From 2bcce4894fbf61ae205af2fe0bc2e06536481450 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Sun, 4 Oct 2026 15:07:08 +1100 Subject: [PATCH] Drop git.unkin.net from k8s gitea gateway and routes (#518) git.unkin.net is served by the VM haproxy during the forge migration. Claiming it on the k8s gitea Gateway/HTTPRoutes competes with that path, so the k8s gitea serves only its admin name until cutover. - remove git.unkin.net from the gitea HTTPRoute and redirect route hostnames - remove the http-primary/https-primary listeners and their parentRefs - set the gateway cert common-name to git.k8s.syd1.au.unkin.net Reviewed-on: https://git.unkin.net/unkin/argocd-apps/pulls/518 Co-authored-by: unkin-agent Co-committed-by: unkin-agent --- apps/base/gitea/gateway.yaml | 34 +++------------------------------- apps/base/gitea/httproute.yaml | 10 ---------- 2 files changed, 3 insertions(+), 41 deletions(-) diff --git a/apps/base/gitea/gateway.yaml b/apps/base/gitea/gateway.yaml index 1e4d675..26a7407 100644 --- a/apps/base/gitea/gateway.yaml +++ b/apps/base/gitea/gateway.yaml @@ -1,11 +1,6 @@ --- -# HTTPS front for the k8s Gitea, served on two names: -# git.unkin.net — canonical/production (apex, bind-operator zone; -# DNS flip is the gated cutover step, see the doc) -# git.k8s.syd1.au.unkin.net — admin/backup route (external-dns k8s.syd1 zone), -# same dual-name pattern as identity.unkin.net. -# The cert-manager Certificate (vault-issuer) takes CN git.unkin.net and gets a -# DNS SAN for each TLS listener hostname automatically. +# HTTPS front for the k8s Gitea on git.k8s.syd1.au.unkin.net (external-dns +# k8s.syd1 zone). git.unkin.net stays on the VM haproxy until cutover. apiVersion: gateway.networking.k8s.io/v1 kind: Gateway metadata: @@ -17,36 +12,13 @@ metadata: traefik.io/instance: internal annotations: cert-manager.io/cluster-issuer: vault-issuer - cert-manager.io/common-name: git.unkin.net + cert-manager.io/common-name: git.k8s.syd1.au.unkin.net cert-manager.io/private-key-size: "4096" - # Only the k8s admin route is published by external-dns (it owns just the - # k8s.syd1.au.unkin.net zone). git.unkin.net lives in the apex zone and is - # flipped at cutover — NOT managed here. external-dns.alpha.kubernetes.io/hostname: git.k8s.syd1.au.unkin.net external-dns.alpha.kubernetes.io/target: 198.18.200.4 spec: gatewayClassName: traefik-internal listeners: - - name: http-primary - port: 80 - protocol: HTTP - hostname: git.unkin.net - allowedRoutes: - namespaces: - from: Same - - name: https-primary - port: 443 - protocol: HTTPS - hostname: git.unkin.net - allowedRoutes: - namespaces: - from: Same - tls: - mode: Terminate - certificateRefs: - - group: "" - kind: Secret - name: gitea-tls - name: http-admin port: 80 protocol: HTTP diff --git a/apps/base/gitea/httproute.yaml b/apps/base/gitea/httproute.yaml index 62b6202..20e90a7 100644 --- a/apps/base/gitea/httproute.yaml +++ b/apps/base/gitea/httproute.yaml @@ -9,13 +9,8 @@ metadata: app.kubernetes.io/instance: gitea spec: hostnames: - - git.unkin.net - git.k8s.syd1.au.unkin.net parentRefs: - - group: gateway.networking.k8s.io - kind: Gateway - name: gitea - sectionName: http-primary - group: gateway.networking.k8s.io kind: Gateway name: gitea @@ -41,13 +36,8 @@ metadata: app.kubernetes.io/instance: gitea spec: hostnames: - - git.unkin.net - git.k8s.syd1.au.unkin.net parentRefs: - - group: gateway.networking.k8s.io - kind: Gateway - name: gitea - sectionName: https-primary - group: gateway.networking.k8s.io kind: Gateway name: gitea