TLS termination at the Ingress Controller and by default unencrypted from there to the service endpoint?
I found this useful: http://blog.wercker.com/troubleshooting-ingress-kubernetes
Interesting discussion here: https://github.com/kubernetes/ingress/issues/257
It seems like a lot of overhead before even starting to process a request!