Post by @jorijn
No, you'll lose the k3s LB. It's not very economical to have one LB per service, as most cloud providers charge you for IPs/LBs. For HTTP(s) traffic you'll want to read up on an Ingress Controller. It's a reverse proxy deployment that looks for "Ingress" resources on your cluster, and it will configure the reverse proxy / vhost so you can expose that service/deployment through the Ingress Controller.
The Ingress Controller will handle TLS. It'll look somewhat like World -> Cloud LB -> (Service ->) Ingress Controller -> Service -> Pods.
https://kubernetes.io/docs/concepts/services-networking/ingress/