--- # External (DMZ) front for the haproxy edge on the traefik-external LB VIP # 198.18.199.0. The :443 listener is TLS Passthrough: haproxy owns the three # wildcard certs and terminates behind Traefik, so there are no certificateRefs # here. Listener hostnames are deliberately unset and the routes carry the # explicit hostname list instead; allowedRoutes Same keeps other namespaces off # these listeners. apiVersion: gateway.networking.k8s.io/v1 kind: Gateway metadata: name: haproxy namespace: haproxy labels: traefik.io/instance: external spec: gatewayClassName: traefik-external listeners: - name: http port: 80 protocol: HTTP allowedRoutes: namespaces: from: Same - name: https-passthrough port: 443 protocol: TLS tls: mode: Passthrough allowedRoutes: namespaces: from: Same