Serve grafana.unkin.net from traefik-external #522

Merged
benvin merged 1 commits from benvin/grafana-external into main 2026-10-05 00:38:22 +11:00
Member

grafana.unkin.net still routes through the puppet haproxy edge to the old grafana VMs; the k8s grafana should serve it directly like identity and vlogs.

  • add grafana-external Gateway (traefik-external, *.unkin.net wildcard) with redirect + main HTTPRoutes
  • reflect wildcard-unkin-net-tls into grafana
  • set grafana root_url to https://grafana.unkin.net
  • add grafana A record -> 198.18.199.0 in the bind-operator unkin.net zone
  • drop grafana.unkin.net from the k8s haproxy routes and config

Requires terraform-authentik grafana redirect URI PR applied first, and the puppet halb vrrp_cnames grafana.unkin.net CNAME removed.

grafana.unkin.net still routes through the puppet haproxy edge to the old grafana VMs; the k8s grafana should serve it directly like identity and vlogs. - add grafana-external Gateway (traefik-external, *.unkin.net wildcard) with redirect + main HTTPRoutes - reflect wildcard-unkin-net-tls into grafana - set grafana root_url to https://grafana.unkin.net - add grafana A record -> 198.18.199.0 in the bind-operator unkin.net zone - drop grafana.unkin.net from the k8s haproxy routes and config Requires terraform-authentik grafana redirect URI PR applied first, and the puppet halb vrrp_cnames grafana.unkin.net CNAME removed.
unkin-agent added 1 commit 2026-10-05 00:31:28 +11:00
Serve grafana.unkin.net from traefik-external
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
e5be6ab5a2
Add a grafana-external Gateway and routes on the *.unkin.net wildcard, point the A record at the external VIP, set root_url to grafana.unkin.net and drop grafana from the haproxy edge.
Author
Member
  • apps/base/grafana/grafana.yaml:46 — root_url now https://grafana.unkin.net while the internal grafana.k8s.syd1.au.unkin.net Gateway/route is kept; Grafana-generated redirects and any OAuth callback on the k8s host will bounce to the public name → confirm that is intended (or state it in the body); otherwise leave root_url as is.
- apps/base/grafana/grafana.yaml:46 — root_url now https://grafana.unkin.net while the internal grafana.k8s.syd1.au.unkin.net Gateway/route is kept; Grafana-generated redirects and any OAuth callback on the k8s host will bounce to the public name → confirm that is intended (or state it in the body); otherwise leave root_url as is.
benvin merged commit d9cc24dbdb into main 2026-10-05 00:38:22 +11:00
benvin deleted branch benvin/grafana-external 2026-10-05 00:38:22 +11:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unkin/argocd-apps#522