Help Center/ Cloud Container Engine_Autopilot/ FAQs/ Network Management/ What Can I Do If Requests Fail After an HTTPS Certificate Is Configured for a LoadBalancer Ingress?
Updated on 2026-06-25 GMT+08:00

What Can I Do If Requests Fail After an HTTPS Certificate Is Configured for a LoadBalancer Ingress?

Symptom

When a domain name is specified in the forwarding policy of a LoadBalancer ingress and an HTTPS server certificate is configured, the TLS handshake fails upon accessing the domain name.

Possible Cause

The domain name defined in the LoadBalancer ingress forwarding policy does not match the domain name in the server certificate.

Solution

If the forwarding policy of the LoadBalancer ingress needs to match the domain name, you are advised to configure an SNI certificate for the ingress.

This issue is likely to occur in the following scenarios if an SNI certificate is not configured:

  • When the forwarding policy of a single ingress includes multiple domain names
  • When multiple ingresses share the same load balancer listener