426a399f31
Stalwart was only ever a test deployment. The daemon is dead on all three backend VMs and nothing public depends on it — `unkin.net` MX points at Google — so the edge is proxying mail to nowhere and the tcp frontends make `defaults` emit 20 spurious HTTP-mode warnings. - Drop the `fe_smtp`, `fe_submission`, `fe_imap` and `fe_imaps` frontends. - Drop the five `be_stalwart_*` backends and their map entries in `fe_http.map`/`fe_https.map`. - Drop the now-unused 25/143/587/993 Service and container ports. `haproxy -c` on the rendered config: exit 0, 0 warnings (was 20), 0 alerts. Reviewed-on: #491 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
28 lines
599 B
YAML
28 lines
599 B
YAML
---
|
|
apiVersion: v1
|
|
kind: Service
|
|
metadata:
|
|
name: haproxy
|
|
namespace: haproxy
|
|
annotations:
|
|
purelb.io/service-group: dmz
|
|
purelb.io/addresses: 198.18.199.1
|
|
spec:
|
|
type: LoadBalancer
|
|
loadBalancerIP: "198.18.199.1"
|
|
# Source IP must survive for X-Real-IP.
|
|
externalTrafficPolicy: Local
|
|
# Pins a client to one replica, standing in for the dropped stick-table peers.
|
|
sessionAffinity: ClientIP
|
|
selector:
|
|
app: haproxy
|
|
ports:
|
|
- name: http
|
|
port: 80
|
|
protocol: TCP
|
|
targetPort: http
|
|
- name: https
|
|
port: 443
|
|
protocol: TCP
|
|
targetPort: https
|