# \[HELP\] - Certificate - Let's encrypt - Reverse proxy

**URL:** <https://community.traefik.io/t/help-certificate-lets-encrypt-reverse-proxy/25847>\
**Category:** Traefik v3 (latest)\
**Tags:** letsencrypt-acme\
**Created:** [January 4, 2025, 11:08am UTC](https://community.traefik.io/t/help-certificate-lets-encrypt-reverse-proxy/25847 "2025-01-04T11:08:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Th3Heavy](https://avatars.discourse-cdn.com/v4/letter/t/47e85d/32.png) [@Th3Heavy](https://community.traefik.io/u/Th3Heavy)\
**Post date:** [January 4, 2025, 11:08am UTC](https://community.traefik.io/t/help-certificate-lets-encrypt-reverse-proxy/25847/1 "2025-01-04T11:08:58Z")

</div>

Hello, I can access the kubernetes services on port 80 from the internet, but to switch to 443 I have to set up the certificates.  
I wonder at what level to put the certificates, is it sufficient on the reverse proxy of the server only, do I also have to put certificates at the level of the kubernetes services.  
At the reverse proxy level should I use let's encrypt (http or dns challenge) because I have a public dns or use the certificate generated by porkbun and deploy it on my server.  
Here is a diagram of my infrastructure.

I tried to enable let's encrypt on my server's traefik revere proxy but I got an error, saying that the certificate is not valid for my kubernetes cluster.

Thank you for your help.

 ![Diagramme sans nom](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/e/e5f1a02f6fc6a4211974ec8395273967ee2563db.jpeg)

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [January 4, 2025, 4:15pm UTC](https://community.traefik.io/t/help-certificate-lets-encrypt-reverse-proxy/25847/2 "2025-01-04T16:15:24Z")

</div>

I think in general in k8s the TLS certs are handled by cert-manager ([guide](https://doc.traefik.io/traefik/user-guides/cert-manager/)), not Traefik directly. But I am not a k8s user.

---

<div class="post-metadata">

**Author:** ![Th3Heavy](https://avatars.discourse-cdn.com/v4/letter/t/47e85d/32.png) [@Th3Heavy](https://community.traefik.io/u/Th3Heavy)\
**Post date:** [January 5, 2025, 11:09am UTC](https://community.traefik.io/t/help-certificate-lets-encrypt-reverse-proxy/25847/3 "2025-01-05T11:09:32Z")

</div>

solution is:

just need to use http and not https for the interne redirection 'kubernetes-traefik-https'  
tls connexion is before

```auto
  services:
    kubernetes-traefik-http:
      loadBalancer:
        passHostHeader: true
        servers:
          - url: "http://kubeserver:31960/"
    kubernetes-traefik-https:
      loadBalancer:
        passHostHeader: true
        servers:
          - url: "http://kubeserver:31960/"

```
