logging: expose vlselect on internal traefik (#525)

Querying the VLCluster from outside the cluster (CLI tools, puppet VMs) needs a resolvable TLS endpoint for vlselect, mirroring the existing logs-ingest endpoint for vlinsert.

- add `vlselect` Gateway on `traefik-internal` with vault-issuer TLS and external-dns for `vlselect.k8s.syd1.au.unkin.net`
- add HTTP->HTTPS redirect route and HTTPS route to `vlselect-logs:9471`, unauthenticated

Reviewed-on: #525
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #525.
This commit is contained in:
2026-10-05 14:08:33 +11:00
committed by BenVincent
parent d1825bb655
commit 9b857bef64
2 changed files with 95 additions and 0 deletions
+40
View File
@@ -39,3 +39,43 @@ spec:
- group: ""
kind: Secret
name: logs-ingest-tls
---
# Unauthenticated LogsQL query endpoint fronting the VLCluster vlselect service.
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
name: vlselect
namespace: logging
labels:
app.kubernetes.io/name: victorialogs
app.kubernetes.io/component: query
traefik.io/instance: internal
annotations:
cert-manager.io/cluster-issuer: vault-issuer
cert-manager.io/common-name: vlselect.k8s.syd1.au.unkin.net
cert-manager.io/private-key-size: "4096"
external-dns.alpha.kubernetes.io/hostname: vlselect.k8s.syd1.au.unkin.net
external-dns.alpha.kubernetes.io/target: 198.18.200.4
spec:
gatewayClassName: traefik-internal
listeners:
- name: http
port: 80
protocol: HTTP
hostname: vlselect.k8s.syd1.au.unkin.net
allowedRoutes:
namespaces:
from: Same
- name: https
port: 443
protocol: HTTPS
hostname: vlselect.k8s.syd1.au.unkin.net
allowedRoutes:
namespaces:
from: Same
tls:
mode: Terminate
certificateRefs:
- group: ""
kind: Secret
name: vlselect-tls
+55
View File
@@ -53,3 +53,58 @@ spec:
- path:
type: PathPrefix
value: /
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: vlselect-http-redirect
namespace: logging
labels:
app.kubernetes.io/name: victorialogs
app.kubernetes.io/component: query
spec:
hostnames:
- vlselect.k8s.syd1.au.unkin.net
parentRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: vlselect
sectionName: http
rules:
- filters:
- type: RequestRedirect
requestRedirect:
scheme: https
statusCode: 301
matches:
- path:
type: PathPrefix
value: /
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: vlselect
namespace: logging
labels:
app.kubernetes.io/name: victorialogs
app.kubernetes.io/component: query
spec:
hostnames:
- vlselect.k8s.syd1.au.unkin.net
parentRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: vlselect
sectionName: https
rules:
- backendRefs:
- group: ""
kind: Service
name: vlselect-logs
port: 9471
weight: 1
matches:
- path:
type: PathPrefix
value: /