Files
argocd-apps/apps/base/gitea/httproute.yaml
T
unkinben 34c2994cd3
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
Disable SSH; serve git.unkin.net + git.k8s.syd1 admin route
Per the forge design: drop git-over-ssh (HTTPS clones only, estate norm) and
serve the new instance on both the canonical git.unkin.net and a
git.k8s.syd1.au.unkin.net admin/backup route (same dual-name pattern as
identity). Only the k8s admin name goes live now (external-dns); the
git.unkin.net DNS flip stays the gated final cutover step.

- values: DISABLE_SSH + START_SSH_SERVER false; DOMAIN/ROOT_URL/SSH_DOMAIN ->
  git.unkin.net; drop the SSH LoadBalancer service
- overlay: $patch-delete the chart's leftover gitea-ssh Service
- gateway/httproute: listeners + routes for git.unkin.net and
  git.k8s.syd1.au.unkin.net; cert CN git.unkin.net (both as SANs); external-dns
  publishes only git.k8s.syd1.au.unkin.net -> 198.18.200.4
- bind-internal: prepared (commented) git-dns-internal DNSRecord as the gated
  apex cutover step
- docs: SSH removed, dual hostnames, git.unkin.net flip as the final step

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
2026-07-31 20:01:46 +10:00

66 lines
1.4 KiB
YAML

---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: gitea-http-redirect
namespace: gitea
labels:
app.kubernetes.io/name: gitea
app.kubernetes.io/instance: gitea
spec:
hostnames:
- git.unkin.net
- git.k8s.syd1.au.unkin.net
parentRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: gitea
sectionName: http-primary
- group: gateway.networking.k8s.io
kind: Gateway
name: gitea
sectionName: http-admin
rules:
- filters:
- type: RequestRedirect
requestRedirect:
scheme: https
statusCode: 301
matches:
- path:
type: PathPrefix
value: /
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: gitea
namespace: gitea
labels:
app.kubernetes.io/name: gitea
app.kubernetes.io/instance: gitea
spec:
hostnames:
- git.unkin.net
- git.k8s.syd1.au.unkin.net
parentRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: gitea
sectionName: https-primary
- group: gateway.networking.k8s.io
kind: Gateway
name: gitea
sectionName: https-admin
rules:
- backendRefs:
- group: ""
kind: Service
name: gitea-http
port: 3000
weight: 1
matches:
- path:
type: PathPrefix
value: /