Files
argocd-apps/apps/base/vlogs/httproute.yaml
T
unkin-agent e6e882abfc Give vlogs its own namespace (#507)
The Vault KV layout is kubernetes/namespace/<ns>/<sa>/<secret>, so vlogs and logviewer both running as SA default in the shared logging namespace would collide on one oauth-credentials entry. Splitting vlogs out resolves it without widening any Vault policy.

- Move apps/base/logging/vlogs to apps/base/vlogs, namespace vlogs
- Add namespace.yaml and a vlogs-scoped VaultAuth (role default)
- Point the VaultStaticSecret at kubernetes/namespace/vlogs/default/oauth-credentials
- Add the au-syd1 overlay, platform ApplicationSet path and project destination
- Move the wildcard-unkin-net-tls reflection from logging to vlogs; vlogs was its only consumer there

Secret is already seeded at the new Vault path.

Reviewed-on: #507
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-28 22:55:28 +10:00

62 lines
1.3 KiB
YAML

---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: vlogs-http-redirect
namespace: vlogs
spec:
hostnames:
- vlogs.unkin.net
parentRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: vlogs-external
sectionName: http
rules:
- filters:
- type: RequestRedirect
requestRedirect:
scheme: https
statusCode: 301
matches:
- path:
type: PathPrefix
value: /
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: vlogs
namespace: vlogs
spec:
hostnames:
- vlogs.unkin.net
parentRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: vlogs-external
sectionName: https
rules:
# Exact / outranks the PathPrefix catch-all; target needs the trailing slash
- filters:
- type: RequestRedirect
requestRedirect:
path:
type: ReplaceFullPath
replaceFullPath: /select/vmui/
statusCode: 302
matches:
- path:
type: Exact
value: /
- backendRefs:
- group: ""
kind: Service
name: vlogs-oauth2
port: 80
weight: 1
matches:
- path:
type: PathPrefix
value: /