34 lines
1.5 KiB
Markdown
34 lines
1.5 KiB
Markdown
# Traefik
|
|
|
|
Ingress for HTTP, gRPC, TCP, and UDP services, with public and internal TLS.
|
|
|
|
Kubernetes uses the Helm settings in `k8s/traefik-values.yaml`. The deploy
|
|
library applies supporting resources in this directory but does not install or
|
|
upgrade the Traefik chart. Bootstrap the chart and CRDs separately.
|
|
|
|
The LoadBalancer address is set to `192.168.80.2`. Change it for another network.
|
|
Entrypoints include web traffic, Gitea SSH, NetBird STUN, and other lab protocols.
|
|
Public certificates come from cert-manager; internal certificates use the lab CA.
|
|
The file provider reads `traefik-dynamic` through an additional volume and flags.
|
|
|
|
## API access
|
|
|
|
The committed chart values enable `api.insecure` and expose TCP 8080 through the
|
|
LoadBalancer for Homarr integration. That listener has no Traefik authentication.
|
|
Its reachability depends on external network controls. Review those controls
|
|
before deploying these values outside the trusted network.
|
|
|
|
The normal dashboard IngressRoute is a separate path; protecting that route does
|
|
not protect the direct port 8080 listener.
|
|
|
|
## Compose alternative
|
|
|
|
Compose mounts static and dynamic config, certificates, ACME state, and the
|
|
Docker socket. It needs the external `proxy` network. Local file-server routing
|
|
and TLS files have `.example` templates; copy only the ones needed for the host.
|
|
|
|
Keep ACME state and private keys with backups. Changing ingress values can affect
|
|
every service at once, so inspect routes and entrypoints after an upgrade.
|
|
|
|
See the [repository README](../README.md) for deployment selection.
|