From af61ac5e927958c5cdee91a324d6041f4752fb0f Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Sun, 4 Oct 2026 15:26:23 +1100 Subject: [PATCH] Set traefik-external externalTrafficPolicy to Local (#519) With the default Cluster external policy, kube-proxy SNATs inbound traffic to the traefik-external LoadBalancer, hiding real client IPs from traefik and adding a cross-node hop. Local preserves source IPs. Internal policy stays Cluster so in-cluster callers on nodes without a traefik-external pod still reach it. - Set `externalTrafficPolicy: Local` on the traefik-external Service - Set `internalTrafficPolicy: Cluster` explicitly Reviewed-on: https://git.unkin.net/unkin/argocd-apps/pulls/519 Co-authored-by: unkin-agent Co-committed-by: unkin-agent --- apps/overlays/au-syd1/traefik-system/values-external.yaml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/apps/overlays/au-syd1/traefik-system/values-external.yaml b/apps/overlays/au-syd1/traefik-system/values-external.yaml index 42cab53..1152ae2 100644 --- a/apps/overlays/au-syd1/traefik-system/values-external.yaml +++ b/apps/overlays/au-syd1/traefik-system/values-external.yaml @@ -59,6 +59,8 @@ service: spec: type: LoadBalancer loadBalancerIP: "198.18.199.0" + externalTrafficPolicy: Local + internalTrafficPolicy: Cluster additionalServices: {} autoscaling: