ghp: serve at ghp.unkin.net (gateway + cert + httproute + DNS) #360
@@ -88,3 +88,17 @@ spec:
|
|||||||
ttl: 600
|
ttl: 600
|
||||||
values:
|
values:
|
||||||
- 103.216.191.185
|
- 103.216.191.185
|
||||||
|
---
|
||||||
|
apiVersion: bind.unkin.net/v1alpha1
|
||||||
|
kind: DNSRecord
|
||||||
|
metadata:
|
||||||
|
name: ghp-dns-internal
|
||||||
|
namespace: bind-internal
|
||||||
|
spec:
|
||||||
|
zoneRef: unkin-net
|
||||||
|
name: ghp
|
||||||
|
type: A
|
||||||
|
ttl: 600
|
||||||
|
values:
|
||||||
|
# traefik-internal gateway VIP; the ghp Gateway serves ghp.unkin.net there.
|
||||||
|
- 198.18.200.4
|
||||||
|
|||||||
@@ -11,8 +11,8 @@ data:
|
|||||||
GHP_SERVER_HTTP_LISTEN: ":8080"
|
GHP_SERVER_HTTP_LISTEN: ":8080"
|
||||||
GHP_METRICS_LISTEN: ":9136"
|
GHP_METRICS_LISTEN: ":9136"
|
||||||
GHP_METRICS_ENABLED: "true"
|
GHP_METRICS_ENABLED: "true"
|
||||||
GHP_SERVER_BASE_URL: https://ghp.k8s.syd1.au.unkin.net
|
GHP_SERVER_BASE_URL: https://ghp.unkin.net
|
||||||
GHP_SERVER_MANAGEMENT_HOST: ghp.k8s.syd1.au.unkin.net
|
GHP_SERVER_MANAGEMENT_HOST: ghp.unkin.net
|
||||||
# private_key key from the ghp-github-app Secret, mounted as a file.
|
# private_key key from the ghp-github-app Secret, mounted as a file.
|
||||||
GHP_GITHUB_PRIVATE_KEY_FILE: /etc/ghp/github-app/private_key
|
GHP_GITHUB_PRIVATE_KEY_FILE: /etc/ghp/github-app/private_key
|
||||||
# cert-manager Certificate ghp-tls, mounted from the ghp-tls Secret.
|
# cert-manager Certificate ghp-tls, mounted from the ghp-tls Secret.
|
||||||
|
|||||||
+43
-13
@@ -1,8 +1,12 @@
|
|||||||
---
|
---
|
||||||
# Management UI ingress for ghp.k8s.syd1.au.unkin.net via the internal Traefik.
|
# HTTPS front for ghp, served on two names via the internal Traefik:
|
||||||
# TLS is terminated with the ghp-tls Secret produced by the cert-manager
|
# ghp.unkin.net — canonical/primary (apex, bind-operator zone)
|
||||||
# Certificate (which also carries the GitHub SANs); no cert-manager annotation
|
# ghp.k8s.syd1.au.unkin.net — admin/internal route (external-dns k8s.syd1 zone)
|
||||||
# here so the two never fight over the same Secret.
|
# The cert-manager annotations below make cert-manager mint the ghp-gateway-tls
|
||||||
|
# Secret with CN ghp.unkin.net and a DNS SAN for each TLS listener hostname
|
||||||
|
# automatically. This is a SEPARATE Secret from ghp-tls (certificate.yaml), which
|
||||||
|
# carries the GitHub impersonation SANs and is mounted by ghp itself — the two
|
||||||
|
# never share a Secret, so cert-manager does not fight over either.
|
||||||
apiVersion: gateway.networking.k8s.io/v1
|
apiVersion: gateway.networking.k8s.io/v1
|
||||||
kind: Gateway
|
kind: Gateway
|
||||||
metadata:
|
metadata:
|
||||||
@@ -10,6 +14,12 @@ metadata:
|
|||||||
traefik.io/instance: internal
|
traefik.io/instance: internal
|
||||||
annotations:
|
annotations:
|
||||||
argocd.argoproj.io/sync-wave: "2"
|
argocd.argoproj.io/sync-wave: "2"
|
||||||
|
cert-manager.io/cluster-issuer: vault-issuer
|
||||||
|
cert-manager.io/common-name: ghp.unkin.net
|
||||||
|
cert-manager.io/private-key-size: "4096"
|
||||||
|
# Only the k8s admin route is published by external-dns (it owns just the
|
||||||
|
# k8s.syd1.au.unkin.net zone). ghp.unkin.net lives in the apex zone and is
|
||||||
|
# served by the bind-operator DNSRecord — NOT managed here.
|
||||||
external-dns.alpha.kubernetes.io/hostname: ghp.k8s.syd1.au.unkin.net
|
external-dns.alpha.kubernetes.io/hostname: ghp.k8s.syd1.au.unkin.net
|
||||||
external-dns.alpha.kubernetes.io/target: 198.18.200.4
|
external-dns.alpha.kubernetes.io/target: 198.18.200.4
|
||||||
name: ghp
|
name: ghp
|
||||||
@@ -17,23 +27,43 @@ metadata:
|
|||||||
spec:
|
spec:
|
||||||
gatewayClassName: traefik-internal
|
gatewayClassName: traefik-internal
|
||||||
listeners:
|
listeners:
|
||||||
- allowedRoutes:
|
- name: http-primary
|
||||||
namespaces:
|
|
||||||
from: Same
|
|
||||||
hostname: ghp.k8s.syd1.au.unkin.net
|
|
||||||
name: http
|
|
||||||
port: 80
|
port: 80
|
||||||
protocol: HTTP
|
protocol: HTTP
|
||||||
- allowedRoutes:
|
hostname: ghp.unkin.net
|
||||||
|
allowedRoutes:
|
||||||
namespaces:
|
namespaces:
|
||||||
from: Same
|
from: Same
|
||||||
hostname: ghp.k8s.syd1.au.unkin.net
|
- name: https-primary
|
||||||
name: https
|
|
||||||
port: 443
|
port: 443
|
||||||
protocol: HTTPS
|
protocol: HTTPS
|
||||||
|
hostname: ghp.unkin.net
|
||||||
|
allowedRoutes:
|
||||||
|
namespaces:
|
||||||
|
from: Same
|
||||||
tls:
|
tls:
|
||||||
|
mode: Terminate
|
||||||
certificateRefs:
|
certificateRefs:
|
||||||
- group: ""
|
- group: ""
|
||||||
kind: Secret
|
kind: Secret
|
||||||
name: ghp-tls
|
name: ghp-gateway-tls
|
||||||
|
- name: http-admin
|
||||||
|
port: 80
|
||||||
|
protocol: HTTP
|
||||||
|
hostname: ghp.k8s.syd1.au.unkin.net
|
||||||
|
allowedRoutes:
|
||||||
|
namespaces:
|
||||||
|
from: Same
|
||||||
|
- name: https-admin
|
||||||
|
port: 443
|
||||||
|
protocol: HTTPS
|
||||||
|
hostname: ghp.k8s.syd1.au.unkin.net
|
||||||
|
allowedRoutes:
|
||||||
|
namespaces:
|
||||||
|
from: Same
|
||||||
|
tls:
|
||||||
mode: Terminate
|
mode: Terminate
|
||||||
|
certificateRefs:
|
||||||
|
- group: ""
|
||||||
|
kind: Secret
|
||||||
|
name: ghp-gateway-tls
|
||||||
|
|||||||
@@ -8,16 +8,25 @@ metadata:
|
|||||||
argocd.argoproj.io/sync-wave: "2"
|
argocd.argoproj.io/sync-wave: "2"
|
||||||
spec:
|
spec:
|
||||||
hostnames:
|
hostnames:
|
||||||
|
- ghp.unkin.net
|
||||||
- ghp.k8s.syd1.au.unkin.net
|
- ghp.k8s.syd1.au.unkin.net
|
||||||
parentRefs:
|
parentRefs:
|
||||||
- group: gateway.networking.k8s.io
|
- group: gateway.networking.k8s.io
|
||||||
kind: Gateway
|
kind: Gateway
|
||||||
name: ghp
|
name: ghp
|
||||||
sectionName: http
|
sectionName: http-primary
|
||||||
- group: gateway.networking.k8s.io
|
- group: gateway.networking.k8s.io
|
||||||
kind: Gateway
|
kind: Gateway
|
||||||
name: ghp
|
name: ghp
|
||||||
sectionName: https
|
sectionName: http-admin
|
||||||
|
- group: gateway.networking.k8s.io
|
||||||
|
kind: Gateway
|
||||||
|
name: ghp
|
||||||
|
sectionName: https-primary
|
||||||
|
- group: gateway.networking.k8s.io
|
||||||
|
kind: Gateway
|
||||||
|
name: ghp
|
||||||
|
sectionName: https-admin
|
||||||
rules:
|
rules:
|
||||||
- backendRefs:
|
- backendRefs:
|
||||||
- group: ""
|
- group: ""
|
||||||
|
|||||||
Reference in New Issue
Block a user