n order to have HTTPs service exposed only, you can block traffic on port 80 as mentioned on this link:
What you can do is block all traffic on port 80 like here:
You can block traffic on :80 through an annotation. You might want to do this if all your clients are only going to hit the loadbalancer through https and you don't want to waste the extra GCE forwarding rule, eg:
# This assumes tls-secret exists.
# To generate it run the make in this directory.
- secretName: tls-secret