--- apiVersion: gateway.networking.k8s.io/v1 kind: Gateway metadata: name: grafana namespace: grafana labels: app.kubernetes.io/name: grafana app.kubernetes.io/instance: grafana traefik.io/instance: internal annotations: cert-manager.io/cluster-issuer: vault-issuer cert-manager.io/common-name: grafana.k8s.syd1.au.unkin.net cert-manager.io/private-key-size: "4096" external-dns.alpha.kubernetes.io/hostname: grafana.k8s.syd1.au.unkin.net external-dns.alpha.kubernetes.io/target: 198.18.200.4 spec: gatewayClassName: traefik-internal listeners: - name: http port: 80 protocol: HTTP hostname: grafana.k8s.syd1.au.unkin.net allowedRoutes: namespaces: from: Same - name: https port: 443 protocol: HTTPS hostname: grafana.k8s.syd1.au.unkin.net allowedRoutes: namespaces: from: Same tls: mode: Terminate certificateRefs: - group: "" kind: Secret name: grafana-tls --- # Public grafana.unkin.net via the external Traefik; TLS uses the reflected # Let's Encrypt *.unkin.net wildcard, DNS lives in the bind-operator zone. apiVersion: gateway.networking.k8s.io/v1 kind: Gateway metadata: labels: traefik.io/instance: external name: grafana-external namespace: grafana spec: gatewayClassName: traefik-external listeners: - allowedRoutes: namespaces: from: Same hostname: grafana.unkin.net name: http port: 80 protocol: HTTP - allowedRoutes: namespaces: from: Same hostname: grafana.unkin.net name: https port: 443 protocol: HTTPS tls: certificateRefs: - group: "" kind: Secret name: wildcard-unkin-net-tls mode: Terminate