# Exhaustive Traefik IngressRoute reference (traefik.io/v1alpha1, HTTP). # Routes are evaluated top to bottom by priority, then by rule length: the # first matching route handles the request. Keep specific rules above the # catch-all. apiVersion: traefik.io/v1alpha1 kind: IngressRoute metadata: name: app-prod namespace: example labels: app: app annotations: description: "exhaustive traefik http route example" spec: # entryPoints: static entrypoints the route listens on (ports Traefik was # started with: web=:80, websecure=:443, plus any custom ones). entryPoints: - websecure routes: # Rule 1: API subtree with middleware chain and weighted backends. - match: Host(`app.example.com`) && PathPrefix(`/api`) # kind: Rule (match traffic) or the same match used for redirections. kind: Rule # priority: explicit precedence. Higher wins regardless of position. # Default is the rule length in characters - explicit numbers beat # clever ordering. priority: 100 # middlewares: request pipeline, in order (auth, headers, rate limit, # redirect, strip prefix...). Same-namespace by name; cross-namespace # as name@namespace (never across providers without the suffix). middlewares: - name: app-auth - name: security-headers services: - name: app-service # port: Service port number or name. port: 80 # scheme: http (default), https (TLS backend), h2c (cleartext # HTTP/2, e.g. gRPC without TLS). scheme: http # weight: traffic share for canary/blue-green splits. weight: 90 # serversTransport: ServersTransport CRD with TLS/forwarding # tuning for this backend (rootCAs, insecureSkipVerify...). # serversTransport: app-transport # responseForwarding: # flushInterval: 100ms # passHostHeader: forward the original Host header (default true). # passHostHeader: true # proxyProtocol: speak PROXY protocol to the backend so it sees # real client IPs. Version v1 or v2; backend must understand it. # proxyProtocol: # version: 2 - name: app-canary-service port: 80 weight: 10 # Rule 2: multiple hosts, regex path, external backend by URL. - match: (Host(`app.example.com`) || Host(`www.example.com`)) && PathRegexp(`^/files/.*$`) kind: Rule priority: 50 services: # servers: bypass the Service and address backends directly. # Only one of name/port (cluster Service) or servers (explicit # URLs) may be set. - name: app-service port: 80 # Catch-all rule: everything not matched above. - match: Host(`app.example.com`) kind: Rule priority: 1 services: - name: app-service port: 80 # tls: terminate TLS on this route. Omit the whole block for plain HTTP. tls: # secretName: TLS Secret (tls.crt/tls.key) in THIS namespace. secretName: app-prod-tls # options: TLSOption CRD (minVersion, cipherSuites, sniStrict...). # options: # name: modern-tls # certResolver: ACME resolver name (letsencrypt-style) that issues the # certificate on demand. Use EITHER certResolver OR secretName, not both: # resolver for auto-issued certs, secretName for pre-made ones. # certResolver: letsencrypt # store: custom TLSStore for the certificate. Default store otherwise. # store: # name: default # domains: certificates to request/serve (main + SANs). With secretName # this documents intent; with certResolver it drives issuance. domains: - main: app.example.com sans: - www.example.com