Set traefik-external externalTrafficPolicy to Local (#519)

With the default Cluster external policy, kube-proxy SNATs inbound traffic to the traefik-external LoadBalancer, hiding real client IPs from traefik and adding a cross-node hop. Local preserves source IPs. Internal policy stays Cluster so in-cluster callers on nodes without a traefik-external pod still reach it.

- Set `externalTrafficPolicy: Local` on the traefik-external Service
- Set `internalTrafficPolicy: Cluster` explicitly

Reviewed-on: #519
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #519.
This commit is contained in:
2026-10-04 15:26:23 +11:00
committed by BenVincent
parent 2bcce4894f
commit af61ac5e92
@@ -59,6 +59,8 @@ service:
spec:
type: LoadBalancer
loadBalancerIP: "198.18.199.0"
externalTrafficPolicy: Local
internalTrafficPolicy: Cluster
additionalServices: {}
autoscaling: