ghp: serve at ghp.unkin.net (gateway + cert + httproute + DNS) #360

Merged
benvin merged 1 commits from benvin/ghp-unkin-net into main 2026-08-13 22:48:24 +10:00
4 changed files with 70 additions and 17 deletions
@@ -88,3 +88,17 @@ spec:
ttl: 600 ttl: 600
values: values:
- 103.216.191.185 - 103.216.191.185
---
apiVersion: bind.unkin.net/v1alpha1
kind: DNSRecord
metadata:
name: ghp-dns-internal
namespace: bind-internal
spec:
zoneRef: unkin-net
name: ghp
type: A
ttl: 600
values:
# traefik-internal gateway VIP; the ghp Gateway serves ghp.unkin.net there.
- 198.18.200.4
+2 -2
View File
@@ -11,8 +11,8 @@ data:
GHP_SERVER_HTTP_LISTEN: ":8080" GHP_SERVER_HTTP_LISTEN: ":8080"
GHP_METRICS_LISTEN: ":9136" GHP_METRICS_LISTEN: ":9136"
GHP_METRICS_ENABLED: "true" GHP_METRICS_ENABLED: "true"
GHP_SERVER_BASE_URL: https://ghp.k8s.syd1.au.unkin.net GHP_SERVER_BASE_URL: https://ghp.unkin.net
GHP_SERVER_MANAGEMENT_HOST: ghp.k8s.syd1.au.unkin.net GHP_SERVER_MANAGEMENT_HOST: ghp.unkin.net
# private_key key from the ghp-github-app Secret, mounted as a file. # private_key key from the ghp-github-app Secret, mounted as a file.
GHP_GITHUB_PRIVATE_KEY_FILE: /etc/ghp/github-app/private_key GHP_GITHUB_PRIVATE_KEY_FILE: /etc/ghp/github-app/private_key
# cert-manager Certificate ghp-tls, mounted from the ghp-tls Secret. # cert-manager Certificate ghp-tls, mounted from the ghp-tls Secret.
+43 -13
View File
@@ -1,8 +1,12 @@
--- ---
# Management UI ingress for ghp.k8s.syd1.au.unkin.net via the internal Traefik. # HTTPS front for ghp, served on two names via the internal Traefik:
# TLS is terminated with the ghp-tls Secret produced by the cert-manager # ghp.unkin.net — canonical/primary (apex, bind-operator zone)
# Certificate (which also carries the GitHub SANs); no cert-manager annotation # ghp.k8s.syd1.au.unkin.net — admin/internal route (external-dns k8s.syd1 zone)
# here so the two never fight over the same Secret. # The cert-manager annotations below make cert-manager mint the ghp-gateway-tls
# Secret with CN ghp.unkin.net and a DNS SAN for each TLS listener hostname
# automatically. This is a SEPARATE Secret from ghp-tls (certificate.yaml), which
# carries the GitHub impersonation SANs and is mounted by ghp itself — the two
# never share a Secret, so cert-manager does not fight over either.
apiVersion: gateway.networking.k8s.io/v1 apiVersion: gateway.networking.k8s.io/v1
kind: Gateway kind: Gateway
metadata: metadata:
@@ -10,6 +14,12 @@ metadata:
traefik.io/instance: internal traefik.io/instance: internal
annotations: annotations:
argocd.argoproj.io/sync-wave: "2" argocd.argoproj.io/sync-wave: "2"
cert-manager.io/cluster-issuer: vault-issuer
cert-manager.io/common-name: ghp.unkin.net
cert-manager.io/private-key-size: "4096"
# Only the k8s admin route is published by external-dns (it owns just the
# k8s.syd1.au.unkin.net zone). ghp.unkin.net lives in the apex zone and is
# served by the bind-operator DNSRecord — NOT managed here.
external-dns.alpha.kubernetes.io/hostname: ghp.k8s.syd1.au.unkin.net external-dns.alpha.kubernetes.io/hostname: ghp.k8s.syd1.au.unkin.net
external-dns.alpha.kubernetes.io/target: 198.18.200.4 external-dns.alpha.kubernetes.io/target: 198.18.200.4
name: ghp name: ghp
@@ -17,23 +27,43 @@ metadata:
spec: spec:
gatewayClassName: traefik-internal gatewayClassName: traefik-internal
listeners: listeners:
- allowedRoutes: - name: http-primary
namespaces:
from: Same
hostname: ghp.k8s.syd1.au.unkin.net
name: http
port: 80 port: 80
protocol: HTTP protocol: HTTP
- allowedRoutes: hostname: ghp.unkin.net
allowedRoutes:
namespaces: namespaces:
from: Same from: Same
hostname: ghp.k8s.syd1.au.unkin.net - name: https-primary
name: https
port: 443 port: 443
protocol: HTTPS protocol: HTTPS
hostname: ghp.unkin.net
allowedRoutes:
namespaces:
from: Same
tls: tls:
mode: Terminate
certificateRefs: certificateRefs:
- group: "" - group: ""
kind: Secret kind: Secret
name: ghp-tls name: ghp-gateway-tls
- name: http-admin
port: 80
protocol: HTTP
hostname: ghp.k8s.syd1.au.unkin.net
allowedRoutes:
namespaces:
from: Same
- name: https-admin
port: 443
protocol: HTTPS
hostname: ghp.k8s.syd1.au.unkin.net
allowedRoutes:
namespaces:
from: Same
tls:
mode: Terminate mode: Terminate
certificateRefs:
- group: ""
kind: Secret
name: ghp-gateway-tls
+11 -2
View File
@@ -8,16 +8,25 @@ metadata:
argocd.argoproj.io/sync-wave: "2" argocd.argoproj.io/sync-wave: "2"
spec: spec:
hostnames: hostnames:
- ghp.unkin.net
- ghp.k8s.syd1.au.unkin.net - ghp.k8s.syd1.au.unkin.net
parentRefs: parentRefs:
- group: gateway.networking.k8s.io - group: gateway.networking.k8s.io
kind: Gateway kind: Gateway
name: ghp name: ghp
sectionName: http sectionName: http-primary
- group: gateway.networking.k8s.io - group: gateway.networking.k8s.io
kind: Gateway kind: Gateway
name: ghp name: ghp
sectionName: https sectionName: http-admin
- group: gateway.networking.k8s.io
kind: Gateway
name: ghp
sectionName: https-primary
- group: gateway.networking.k8s.io
kind: Gateway
name: ghp
sectionName: https-admin
rules: rules:
- backendRefs: - backendRefs:
- group: "" - group: ""