# Exhaustive Traefik IngressRouteTCP reference (traefik.io/v1alpha1). # Routes raw TCP: SSH, databases, or TLS-passthrough where Traefik never # decrypts. Two TLS modes exist - termination (Traefik holds the cert) and # passthrough (backend holds the cert) - and they are mutually exclusive. apiVersion: traefik.io/v1alpha1 kind: IngressRouteTCP metadata: name: app-ssh namespace: example labels: app: app spec: entryPoints: - ssh routes: # Plain TCP (SSH here): no TLS block at all, bytes flow as-is. - match: HostSNI(`*`) # HostSNI matches the TLS Server Name Indication. `*` accepts anything # (required for non-TLS protocols like SSH that send no SNI). # With TLS + a real hostname: HostSNI(`db.example.com`). # middlewares: TCP middleware chain (IP allowlist, rate limit...). # middlewares: # - name: ssh-allowlist # priority: same semantics as HTTP - higher wins. # priority: 10 services: - name: app-service port: 2222 # weight: share of connections across backends. # weight: 1 # terminationDelay: linger after backend close to drain in-flight # data. Default 100ms; raise for slow protocols. terminationDelay: 100 # proxyProtocol: PROXY header toward the backend (v1/v2) so it # learns real client IPs. # proxyProtocol: # version: 2 # TLS termination: Traefik decrypts with its own cert, forwards plaintext. # - match: HostSNI(`db.example.com`) # services: # - name: app-service # port: 5432 # tls: enable TLS handling on this route. Omit entirely for plain TCP. # tls: # Either termination... # secretName: app-tcp-tls # options: # name: modern-tls # domains: # - main: db.example.com # ...or passthrough (Traefik never sees plaintext; needs SNI routing): # passthrough: true