Serve grafana.unkin.net from traefik-external (#522)

grafana.unkin.net still routes through the puppet haproxy edge to the old grafana VMs; the k8s grafana should serve it directly like identity and vlogs.

- add grafana-external Gateway (traefik-external, *.unkin.net wildcard) with redirect + main HTTPRoutes
- reflect wildcard-unkin-net-tls into grafana
- set grafana root_url to https://grafana.unkin.net
- add grafana A record -> 198.18.199.0 in the bind-operator unkin.net zone
- drop grafana.unkin.net from the k8s haproxy routes and config

Requires terraform-authentik grafana redirect URI PR applied first, and the puppet halb vrrp_cnames grafana.unkin.net CNAME removed.

Reviewed-on: #522
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #522.
This commit is contained in:
2026-10-05 00:38:21 +11:00
committed by BenVincent
parent 115cdd492f
commit d9cc24dbdb
9 changed files with 107 additions and 23 deletions
@@ -0,0 +1,15 @@
---
apiVersion: bind.unkin.net/v1alpha1
kind: DNSRecord
metadata:
name: grafana-dns-internal
namespace: bind-internal
spec:
zoneRef: unkin-net
name: grafana
type: A
ttl: 600
values:
# traefik-EXTERNAL (DMZ) gateway VIP; the grafana-external Gateway serves
# grafana.unkin.net there.
- 198.18.199.0
@@ -9,6 +9,7 @@ resources:
# record itself.
# - git.yaml
- ghp.yaml
- grafana.yaml
- identity.yaml
- lb1.yaml
- logviewer.yaml