简体   繁体   English

通过 Nginx Ingress 控制器和证书管理器启用 SSL 后 200+ 毫秒创建了 TTFB

[英]TTFB increated by 200+ ms after enabling SSL via Nginx Ingress controller & cert-manager

Right after enabling cert-manager in Ingress Controller by TTFB (time to first byte) increased by 200+ms in most of the regions.在通过 TTFB(到第一个字节的时间)在Ingress Controller 中启用 cert-manager 之后,在大多数区域中增加了 200+ms。 Without SSL, it was <200ms to 80% of the regions.在没有 SSL 的情况下,80% 的区域不到 200 毫秒。 After enabling SSL only 30% have TTFB <200ms启用 SSL 后,只有 30% 的 TTFB <200ms

without SSL没有 SSL 在此处输入图片说明

with SSL使用 SSL 在此处输入图片说明

My Ingress definition:我的入口定义:

apiVersion: extensions/v1beta1
kind: Ingress
metadata:
  name: test-ingress
  annotations:
    kubernetes.io/ingress.class: nginx
    certmanager.k8s.io/cluster-issuer: letsencrypt-prod
    kubernetes.io/tls-acme: "true"
spec:
  rules:
    - host: gce.wpspeedmatters.com
      http:
        paths:
          - path: /
            backend:
              serviceName: wordpress
              servicePort: 80
  tls:
    - secretName: tls-prod-cert
      hosts:
        - gce.wpspeedmatters.com

Switched to TLS 1.3 and I was able to above shave off extra 50-150ms!切换到 TLS 1.3,我能够节省额外的 50-150 毫秒!

I wrote a detailed blog post too: https://wpspeedmatters.com/tls-1-3-in-wordpress/我也写了一篇详细的博客文章: https : //wpspeedmatters.com/tls-1-3-in-wordpress/

With TLS 1.3:使用 TLS 1.3: 在此处输入图片说明

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

相关问题 使用cert-manager istio ingress和LetsEncrypt在kubernetes中配置SSL证书 - Configure SSL certificates in kubernetes with cert-manager istio ingress and LetsEncrypt 带有证书管理器的 Istio Ingress - Istio Ingress with cert-manager 未应用带有证书管理器的入口TLS路由 - Ingress TLS routes with cert-manager not applied AWS上的Kubernetes:使用Nginx-ingress + cert-manager保留客户端IP - Kubernetes on AWS: Preserving Client IP with nginx-ingress + cert-manager 带有证书管理器和自签名 ClusterIssuer 的 Kubernetes TLS Ingress 路由不起作用 - Kubernetes TLS Ingress route with cert-manager and SelfSigned ClusterIssuer not working 在 Kubernetes 和 nginx 入口上使用客户端证书身份验证时,如何修复 cert-manager 对 Let's Encrypt ACME 挑战的响应? - How to fix cert-manager responses to Let's Encrypt ACME challenges when using client certificate authentication on Kubernetes with nginx ingress? Cert-Manager 为 AKS 提供自己的 SSL 证书 - Cert-Manager provide own SSL Certificate for AKS kubernetes - Nginx,证书管理器,安装的秘密文件更新问题 - kubernetes - Nginx, cert-manager, mounted secret file renewal issue 如何通过证书管理器在 Kubernetes 中正确设置 TLS? - How to setup TLS correctly in Kubernetes via cert-manager? 带有 nginx 入口和证书管理器的 ArgoCD 无法正常工作 - ArgoCD with nginx ingress and cert manager not working
 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM