```
### 先将阿里申请的证书 生成密钥
kubectl --kubeconfig=/root/lcnc-ack-prod create secret tls aaa.ulises.com-ingress-secret --cert=8579111_bmw.ulises.cn.pem --key=8579111_bmw.ulises.cn.key

### 服务创建
kubectl --kubeconfig=/root/lcnc-ack-prod get secret aaa.ulises.com-ingress-secret -o yaml > bmw.ulises.com-ingress-secret.yaml

[root@POC ingress-test]# cat test-deployment-service.yaml
apiVersion: apps/v1
kind: Deployment
metadata:
  name: test-web1
  labels:
    app: test-web1
spec:
  replicas: 1
  selector:
    matchLabels:
      app: test-web1
  template:
    metadata:
      labels:
        app: test-web1
    spec:
      containers:
      - name: test-web1
        imagePullPolicy: IfNotPresent
        image: registry.cn-hangzhou.aliyuncs.com/yilong/ingress-test:web1
        ports:
        - containerPort: 8080
---
apiVersion: v1
kind: Service
metadata:
  name: web1-service
spec:
  type: ClusterIP
  selector:
    app: test-web1
  ports:
    - port: 8080
      targetPort: 8080


### 修改ingress配置或者在阿里云ACK配置
[root@POC ingress-test]# cat test-ingress.yaml
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: test-ingress
  namespace: default
spec:
  tls:
  - hosts:
      - aaa.ulises.cn
    secretName: aaa.ulises.com-ingress-secret
  rules:
  - host: bmw.ulises.cn
    http:
      paths:
      - path: /foo
        backend:
          service:
            name: web1-service
            port:
              number: 8080
        pathType: ImplementationSpecific
      - path: /bar
        backend:
          service:
            name: web1-service
            port:
              number: 8080
        pathType: ImplementationSpecific

```