> Markdown version of [Transport Layer Security](https://vaadin.com/docs/next/tools/azure-cloud/tls). Section index: [llms.txt](https://vaadin.com/docs/next/tools/llms.txt)

# Transport Layer Security (TLS)

> **Important: Ingress NGINX Retirement**
>
> The Kubernetes community has [announced](https://kubernetes.io/blog/2025/11/11/ingress-nginx-retirement/) that the Ingress NGINX controller is being retired, with best-effort maintenance only until March 2026. The [Gateway API](https://gateway-api.sigs.k8s.io/) is the recommended replacement. The instructions below reference NGINX Ingress and may need to be adapted if you’re using the Gateway API.

To help with using `letsencrypt`, there’s an option in the Terraform variables to enable `letsencrypt` and `certmanager` in the cluster.

After `certmanager` is installed, you’ll still need to [create the cluster issuer](https://learn.microsoft.com/en-us/azure/aks/ingress-tls?tabs=azure-cli#create-a-ca-cluster-issuer).

After the cluster issuer is created, the next steps are to configure the ingress to use these certificates. You can follow the same [Microsoft guide](https://learn.microsoft.com/en-us/azure/aks/ingress-tls?tabs=azure-cli#update-your-ingress-routes) for this.

If you plan to use normal certificates, it’s best to follow Microsoft’s tips on how to set up [Secrets Store CSI Driver to Enable NGINX Ingress Controller with TLS](https://learn.microsoft.com/en-us/azure/aks/csi-secrets-store-nginx-tls).
