All Products
Search
Document Center

Container Compute Service:Configure a certificate to access Knative Services over HTTPS

Last Updated:Sep 16, 2026

If you want to use a custom domain name for a Knative Service, we recommend that you configure an HTTPS certificate for the custom domain name to improve the security of data transmission. Knative lets you specify an HTTPS certificate by configuring a DomainMapping, which securely maps a Knative Service to the custom domain name.

Prerequisites

Knative is deployed in your ACS cluster. For more information, see Deploy Knative.

Step 1: Create a Knative Service

  1. Log on to the Container Compute Service (ACS) console. In the left-side navigation pane, click Clusters.

  2. On the Clusters page, click the name of the target cluster. In the left-side navigation pane of the cluster details page, choose Applications > Knative.

  3. On the Services tab of the Knative page, set Namespace to default, and then click Create from Template to create a Knative Service (the helloworld-go Service) from the sample template in the console. Complete the creation as instructed. After the Service is created, its status appears as successful on the Services tab, and its default domain name is helloworld-go.default.example.com. Before you access the Service, you must bind the access domain name to the ingress gateway as a Host.

Step 2: Configure the HTTPS service

The way you configure HTTPS depends on the gateway type:

  • ALB gateway: Certificates are managed centrally by AlbConfig. You enable TLS by using an annotation, without manually handling certificate files.

  • Kourier gateway: You must manually create a certificate Secret, and then bind the Secret to the domain name by using a DomainMapping.

ALB

You can specify a certificate in the AlbConfig and enable TLS access in the Knative Service by using the knative.k8s.alibabacloud/tls: "true" annotation. See the following example.

To enable HTTPS access, add the TLS annotation to the Knative Service and configure a listener on port 443 in the AlbConfig.

  1. Add the knative.k8s.alibabacloud/tls: "true" annotation to the Knative Service YAML.

    apiVersion: serving.knative.dev/v1
    kind: Service
    metadata:
      name: helloworld
      namespace: default
      annotations:
        knative.k8s.alibabacloud/tls: "true"
    spec:
      template:
        spec:
          containers:
          - image: registry-vpc.cn-shenzhen.aliyuncs.com/knative-sample/helloworld-go:73fbdd56  # Replace the region with the region that you actually use.
            env:
            - name: TARGET
              value: "Knative"
  2. Add a listener on port 443 in the AlbConfig (for example, knative-internet) to route HTTPS traffic into the cluster.

    apiVersion: alibabacloud.com/v1
    kind: AlbConfig
    metadata:
      name: knative-internet
    spec:
      config:
      ...
      listeners:
        - port: 443
          # Valid values: HTTP, HTTPS, QUIC
          protocol: HTTPS
      ...
  3. Verify that the Service is accessible over HTTPS.

    # Replace alb-ppcate4ox6******.cn-beijing.alb.aliyuncs.com with your ALB gateway address.
    curl -H "Host: helloworld.knative.top" https://alb-ppcate4ox6******.cn-beijing.alb.aliyuncs.com -k

    Expected output:

    Hello Knative!

Kourier

The Kourier gateway does not provide built-in certificate management. You must first store the TLS certificate in the cluster as a Secret. After the Secret is ready, bind the domain name to the certificate by using a DomainMapping.

1. Create a certificate Secret

The following example uses a self-signed HTTPS certificate generated with OpenSSL. If you already have certificate files in .pem format, you can skip step 1 and start from step 2.

Self-signed certificates are for testing only. In production environments, we recommend that you use certificates issued by a certificate authority (CA).

  1. Create a self-signed certificate by using OpenSSL.

    openssl genrsa -out knativetop-key.pem 4096
    openssl req -subj "/CN=helloworld.knative.top" -sha256 -new -key knativetop-key.pem -out knativetop.csr
    echo subjectAltName = DNS:helloworld.knative.top > extfile.cnf
    openssl x509 -req -days 3650 -sha256 -in knativetop.csr -signkey knativetop-key.pem -out knativetop-cert.pem -extfile extfile.cnf

    Expected output:

    Signature ok
    subject=CN = helloworld.knative.top
    Getting Private key
  2. Base64-encode the knativetop-key.pem and knativetop-cert.pem files created in step 1.

    • Base64-encode knativetop-key.pem.

      cat knativetop-key.pem | base64

      Expected output:

      a25hdGl2ZXRvcC1r******
    • Base64-encode knativetop-cert.pem.

      cat knativetop-cert.pem | base64

      Expected output:

      a25hdGl2ZXRvcC1jZ******==
  3. Create the Secret. The Secret can be used in the TLS configuration of the Knative Service to enable secure access to the domain name helloworld.knative.top.

    kubectl create secret tls secret-tls --key knativetop-key.pem --cert knativetop-cert.pem

    Expected output:

    secret/secret-tls created

2. Create a DomainMapping

In Knative, a DomainMapping is a resource object that maps a domain name to one or more Knative Services. After the Secret is ready, use a DomainMapping to bind the custom domain name to the Knative Service, and reference the previously created Secret to enable TLS encryption.

  1. Create the helloworld.knative.top.yaml file with the following content.

    apiVersion: serving.knative.dev/v1beta1
    kind: DomainMapping
    metadata:
      name: helloworld.knative.top
      namespace: default
    spec:
      ref:
        name: helloworld-go
        kind: Service
        apiVersion: serving.knative.dev/v1
    # The tls block specifies the secret to be used.
      tls:
        secretName: secret-tls
  2. Apply the DomainMapping to the cluster.

    kubectl apply -f helloworld.knative.top.yaml

    Expected output:

    domainmapping.serving.knative.dev/helloworld.knative.top created
  3. Run the following command to verify that the DomainMapping is ready.

    kubectl get domainmapping helloworld.knative.top

    Expected output:

    NAME                          URL                                      READY   REASON
    helloworld.knative.top       https://helloworld.knative.top            True
  4. Verify that the Service is accessible through the custom domain name.

    # 8.141.XX.XX is the Kourier gateway address.
    curl -H "Host: helloworld-go.default.example.com" http://8.141.XX.XX -k

    Expected output:

    Hello Knative!