Files
homelab/templates/gateway.yaml
T
forust 18c633c242
ci / lint-prettier (push) Skipped
ci / lint-ruff (push) Skipped
ci / lint-yaml (push) Skipped
ci / lint-dockerfiles (push) Skipped
ci / validate (push) Skipped
renovate-ci / validate-renovate (push) Skipped
renovate-ci / validate-renovate (pull_request) Skipped
ci / lint-compose (pull_request) Successful in 12s
ci / lint-actionlint (pull_request) Successful in 6s
ci / lint-shellcheck (pull_request) Successful in 13s
ci / lint-prettier (pull_request) Successful in 21s
ci / lint-ruff (pull_request) Successful in 7s
ci / lint-yaml (pull_request) Successful in 12s
ci / lint-dockerfiles (pull_request) Successful in 7s
ci / validate (pull_request) Successful in 7s
ci / build (pull_request) Skipped
feat(monitoring): add VictoriaMetrics trial stack
2026-10-06 17:45:44 +02:00

101 lines
3.7 KiB
YAML

# Exhaustive Gateway reference (gateway.networking.k8s.io/v1).
# A Gateway is the entry door: it owns listener ports/protocols/hostnames and
# delegates actual routing to Route objects (HTTPRoute, TCPRoute, ...), which
# attach via parentRefs. One Gateway usually fronts many Routes.
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
name: example
namespace: example
labels:
app: example
annotations:
description: "exhaustive gateway example"
spec:
# gatewayClassName: which controller implements this Gateway
# (kubectl get gatewayclass). The controller only touches Gateways naming
# its own class; anything else stays Ignored.
gatewayClassName: example-class
# addresses: VIPs/hostnames to request for the Gateway. Most controllers
# (including cloud LBs) allocate and fill status.addresses automatically;
# setting this pins a static IP. Omit for auto-assignment.
# addresses:
# - type: IPAddress
# value: 203.0.113.10
# - type: Hostname
# value: lb.example.com
# infrastructure: controller-specific settings for the provisioned data
# plane (labels/annotations propagated to it). RARE - most setups never
# need it.
# infrastructure:
# labels:
# environment: prod
# annotations:
# example.com/keep: "true"
listeners:
# Each listener = one port + protocol + optional hostname + TLS + which
# Routes may attach. Listener names are referenced by Route parentRefs
# via sectionName.
- name: http
# port: 1-65535. Must be free on the data plane (controllers often
# require 80/443 to match their own entrypoints, otherwise the
# listener is marked Invalid/Conflicted).
port: 80
# protocol: HTTP, HTTPS, TLS, TCP, UDP.
protocol: HTTP
# hostname: restrict this listener to one DNS name. Omit to accept all
# (Routes then narrow via their own hostnames). Listener hostname and
# Route hostnames must intersect or the Route is rejected.
hostname: app.example.com
# allowedRoutes: which Routes may bind here.
allowedRoutes:
namespaces:
# from: Same (only this namespace), All (any namespace), or
# Selector (namespaces matching the selector below).
from: Same
# selector: used only with from: Selector.
# selector:
# matchLabels:
# shared-gateway-access: "true"
# kinds: restrict by Route kind. Default allows whatever the
# listener protocol supports (HTTPRoute on HTTP, etc.).
kinds:
- kind: HTTPRoute
- name: https
port: 443
protocol: HTTPS
hostname: app.example.com
# tls: termination settings for HTTPS/TLS listeners.
tls:
# mode: Terminate (decrypt here, default) or Passthrough (forward
# encrypted bytes to the backend - the backend holds the key).
mode: Terminate
# certificateRefs: TLS Secrets (or other kinds) in the SAME namespace
# (cross-namespace needs a ReferenceGrant). SNI picks among them.
certificateRefs:
- name: app-prod-tls
# kind/group default to Secret / core. Other kinds (e.g. a
# cert-manager Certificate via a plugin) set kind + group.
kind: Secret
group: ""
# options: controller-specific TLS knobs, referenced by name
# (cipher suites, min version). RARE.
# options:
# name: tls-options
- name: tcp
port: 2222
protocol: TCP
allowedRoutes:
namespaces:
from: Same
kinds:
- kind: TCPRoute
- name: udp
port: 3478
protocol: UDP
allowedRoutes:
namespaces:
from: Same
kinds:
- kind: UDPRoute