Set traefik-external externalTrafficPolicy to Local #519

Merged
benvin merged 2 commits from benvin/traefik-external-local-traffic into main 2026-10-04 15:26:24 +11:00
Member

With the default Cluster external policy, kube-proxy SNATs inbound traffic to the traefik-external LoadBalancer, hiding real client IPs from traefik and adding a cross-node hop. Local preserves source IPs. Internal policy stays Cluster so in-cluster callers on nodes without a traefik-external pod still reach it.

  • Set externalTrafficPolicy: Local on the traefik-external Service
  • Set internalTrafficPolicy: Cluster explicitly
With the default Cluster external policy, kube-proxy SNATs inbound traffic to the traefik-external LoadBalancer, hiding real client IPs from traefik and adding a cross-node hop. Local preserves source IPs. Internal policy stays Cluster so in-cluster callers on nodes without a traefik-external pod still reach it. - Set `externalTrafficPolicy: Local` on the traefik-external Service - Set `internalTrafficPolicy: Cluster` explicitly
unkin-agent added 1 commit 2026-10-04 15:19:24 +11:00
Set traefik-external traffic policies to Local
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was canceled
079c0ba4cc
Author
Member
  • apps/overlays/au-syd1/traefik-system/values-external.yaml:63 — internalTrafficPolicy: Local is not justified by the stated why (source IP / external hop) and breaks in-cluster clients of the ClusterIP: pods on nodes without a traefik-external pod (2-5 replicas) get dropped traffic → remove this line, or split to its own PR with its own why.
  • apps/overlays/au-syd1/traefik-system/values-external.yaml:62 — why claims real client IPs reach traefik, but haproxy fronts the VIP (base/haproxy/gateway.yaml, DMZ) so source is haproxy unless PROXY protocol/XFF is used → state the actual client path in the body, or confirm the benefit is real.
- apps/overlays/au-syd1/traefik-system/values-external.yaml:63 — `internalTrafficPolicy: Local` is not justified by the stated why (source IP / external hop) and breaks in-cluster clients of the ClusterIP: pods on nodes without a traefik-external pod (2-5 replicas) get dropped traffic → remove this line, or split to its own PR with its own why. - apps/overlays/au-syd1/traefik-system/values-external.yaml:62 — why claims real client IPs reach traefik, but haproxy fronts the VIP (base/haproxy/gateway.yaml, DMZ) so source is haproxy unless PROXY protocol/XFF is used → state the actual client path in the body, or confirm the benefit is real.
unkin-agent added 1 commit 2026-10-04 15:20:33 +11:00
Keep traefik-external internal traffic policy as Cluster
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
7a37825292
unkin-agent changed title from Set traefik-external traffic policies to Local to Set traefik-external externalTrafficPolicy to Local 2026-10-04 15:20:38 +11:00
Author
Member
  • nit: apps/overlays/au-syd1/traefik-system/values-external.yaml:63 — internalTrafficPolicy: Cluster is the Service default and only governs ClusterIP traffic, not the LB IP, so it does not do what the body claims → drop the line and the matching body bullet.
- nit: apps/overlays/au-syd1/traefik-system/values-external.yaml:63 — `internalTrafficPolicy: Cluster` is the Service default and only governs ClusterIP traffic, not the LB IP, so it does not do what the body claims → drop the line and the matching body bullet.
benvin merged commit af61ac5e92 into main 2026-10-04 15:26:24 +11:00
benvin deleted branch benvin/traefik-external-local-traffic 2026-10-04 15:26:24 +11:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unkin/argocd-apps#519