# Unable to access automatically generated certificates from deployment/pod

**URL:** <https://community.traefik.io/t/unable-to-access-automatically-generated-certificates-from-deployment-pod/7839>\
**Category:** Traefik v2\
**Tags:** file, letsencrypt-acme\
**Created:** [September 23, 2020, 6:12pm UTC](https://community.traefik.io/t/unable-to-access-automatically-generated-certificates-from-deployment-pod/7839 "2020-09-23T18:12:34Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mamiu](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/mamiu/32/2626_2.png) [@mamiu](https://community.traefik.io/u/mamiu)\
**Post date:** [September 23, 2020, 6:12pm UTC](https://community.traefik.io/t/unable-to-access-automatically-generated-certificates-from-deployment-pod/7839/1 "2020-09-23T18:12:34Z")

</div>

Hi traefik engineers,

I'm using traefik in a kubernetes environment and am trying to pass automatically generated certificates (through let's encrypt and are stored as json in the `acme.json` file) to a deployment or pod as certification files.  
As an example have a look at the kubernetes dashboard application: [https://github.com/kubernetes/dashboard/blob/master/docs/user/installation.md#recommended-setup](https://github.com/kubernetes/dashboard/blob/master/docs/user/installation.md#recommended-setup)  
It's one of the use cases where such a scenario is highly recommended in comparison to transferring the data within the cluster unencrypted. Because it's a security vulnerability once a pod in the cluster has gained access to the network traffic.

I'm not a Kubernetes expert, but in case there's no solution for this purpose yet, maybe a [volume type](https://kubernetes.io/docs/concepts/storage/volumes/#types-of-volumes) CRD which would provide the mounting of certificates in pods from a specified certResolvers and domain.

That's how a simplified pseudo deployment (from the example above) could look like:

```yaml
apiVersion: apps/v1
kind: Deployment
metadata:
  name: kubernetes-dashboard
spec:
  template:
    spec:
      volumes:
        - name: kubernetes-dashboard-certs
          certResolver:
            - name: letsencrypt
              domains:
                - main: "example.com"
      containers:
        - name: kubernetes-dashboard
          image: kubernetesui/dashboard:v2.0.4
          ports:
            - containerPort: 8443
              protocol: TCP
          args:
            - --tls-cert-file=/tls.crt
            - --tls-key-file=/tls.key
          volumeMounts:
            - name: kubernetes-dashboard-certs
              mountPath: /certs

```

Thanks for your help.

Awesome proxy BTW!

---

<div class="post-metadata">

**Author:** ![zespri](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/zespri/32/310_2.png) [@zespri](https://community.traefik.io/u/zespri)\
**Post date:** [September 23, 2020, 11:40pm UTC](https://community.traefik.io/t/unable-to-access-automatically-generated-certificates-from-deployment-pod/7839/2 "2020-09-23T23:40:17Z")

</div>

It is not clear to me what you are trying to achieve. If your goal is to re-use certificate that traefik requested from LE and stored in acme.json you can use a script simialr to [this one](https://github.com/mailserver2/mailserver/blob/master/rootfs/usr/local/bin/dumpcerts.traefik.v2.sh) to get the certificates in `pem` format.

If your goal is to have tls encryption between traefik and a pod, then:

- It's up to you to manage applications within pods with appropriate certificates. If an app within pod answers on http, then there is not much you can do apart from using something like [istio](https://istio.io/) or [consul connect](https://www.consul.io/docs/connect) or [maesh](https://traefik.io/traefik-mesh/). If an app within pod answer on https then it's app specific how the certificate gets installed, so traefik cannot know that
- Currently with kubernetes you have to use [insecureSkipVerify](https://doc.traefik.io/traefik/routing/overview/#insecureskipverify) when using TLS between traefik and a pod. This is because traefik currently calls pods by IP address, and thus certificate checking is not possible. There is a [fix for that](https://github.com/traefik/traefik/issues/4835) but we will not see it until traefik v2.4.
