d83735b3e3
A ClusterIP is only reachable via kubectl port-forward, which needs a create grant on pods/portforward that the read-only operator context does not have; laptops reach the cache over wireguard. - Publish the Service as a LoadBalancer on 198.18.200.11 in the common pool - Set externalTrafficPolicy Local so the client IP survives to the nginx allow rules, matching the bind LoadBalancers