Files
homelab/templates/ingressroute-tcp.yaml
T
forust 18c633c242
ci / lint-prettier (push) Skipped
ci / lint-ruff (push) Skipped
ci / lint-yaml (push) Skipped
ci / lint-dockerfiles (push) Skipped
ci / validate (push) Skipped
renovate-ci / validate-renovate (push) Skipped
renovate-ci / validate-renovate (pull_request) Skipped
ci / lint-compose (pull_request) Successful in 12s
ci / lint-actionlint (pull_request) Successful in 6s
ci / lint-shellcheck (pull_request) Successful in 13s
ci / lint-prettier (pull_request) Successful in 21s
ci / lint-ruff (pull_request) Successful in 7s
ci / lint-yaml (pull_request) Successful in 12s
ci / lint-dockerfiles (pull_request) Successful in 7s
ci / validate (pull_request) Successful in 7s
ci / build (pull_request) Skipped
feat(monitoring): add VictoriaMetrics trial stack
2026-10-06 17:45:44 +02:00

53 lines
1.9 KiB
YAML

# Exhaustive Traefik IngressRouteTCP reference (traefik.io/v1alpha1).
# Routes raw TCP: SSH, databases, or TLS-passthrough where Traefik never
# decrypts. Two TLS modes exist - termination (Traefik holds the cert) and
# passthrough (backend holds the cert) - and they are mutually exclusive.
apiVersion: traefik.io/v1alpha1
kind: IngressRouteTCP
metadata:
name: app-ssh
namespace: example
labels:
app: app
spec:
entryPoints:
- ssh
routes:
# Plain TCP (SSH here): no TLS block at all, bytes flow as-is.
- match: HostSNI(`*`)
# HostSNI matches the TLS Server Name Indication. `*` accepts anything
# (required for non-TLS protocols like SSH that send no SNI).
# With TLS + a real hostname: HostSNI(`db.example.com`).
# middlewares: TCP middleware chain (IP allowlist, rate limit...).
# middlewares:
# - name: ssh-allowlist
# priority: same semantics as HTTP - higher wins.
# priority: 10
services:
- name: app-service
port: 2222
# weight: share of connections across backends.
# weight: 1
# terminationDelay: linger after backend close to drain in-flight
# data. Default 100ms; raise for slow protocols.
terminationDelay: 100
# proxyProtocol: PROXY header toward the backend (v1/v2) so it
# learns real client IPs.
# proxyProtocol:
# version: 2
# TLS termination: Traefik decrypts with its own cert, forwards plaintext.
# - match: HostSNI(`db.example.com`)
# services:
# - name: app-service
# port: 5432
# tls: enable TLS handling on this route. Omit entirely for plain TCP.
# tls:
# Either termination...
# secretName: app-tcp-tls
# options:
# name: modern-tls
# domains:
# - main: db.example.com
# ...or passthrough (Traefik never sees plaintext; needs SNI routing):
# passthrough: true