A cert-manager style Certificate custom resource produces a TLS Secret. How should an application Ingress typically consume that output?
Select an answer to reveal the explanation.
Short Explanation
The Certificate CR is the work order; the TLS Secret is the finished badge the Ingress pins on. Point Ingress tls at that Secret name. Do not bake the CR into the image.
Full Explanation
Operators such as cert-manager reconcile Certificate CRs into Kubernetes Secrets containing TLS material. Ingress objects reference those Secrets under spec.tls for HTTPS. Mounting CR YAML as config, baking CRs into images, or expecting kube-proxy to terminate TLS from Certificate annotations are incorrect consumption patterns.