ci / lint-prettier (push) Skipped
ci / lint-ruff (push) Skipped
ci / lint-yaml (push) Skipped
ci / lint-dockerfiles (push) Skipped
ci / validate (push) Skipped
renovate-ci / validate-renovate (push) Skipped
renovate-ci / validate-renovate (pull_request) Skipped
ci / lint-compose (pull_request) Successful in 12s
ci / lint-actionlint (pull_request) Successful in 6s
ci / lint-shellcheck (pull_request) Successful in 13s
ci / lint-prettier (pull_request) Successful in 21s
ci / lint-ruff (pull_request) Successful in 7s
ci / lint-yaml (pull_request) Successful in 12s
ci / lint-dockerfiles (pull_request) Successful in 7s
ci / validate (pull_request) Successful in 7s
ci / build (pull_request) Skipped
53 lines
1.9 KiB
YAML
53 lines
1.9 KiB
YAML
# Exhaustive Traefik IngressRouteTCP reference (traefik.io/v1alpha1).
|
|
# Routes raw TCP: SSH, databases, or TLS-passthrough where Traefik never
|
|
# decrypts. Two TLS modes exist - termination (Traefik holds the cert) and
|
|
# passthrough (backend holds the cert) - and they are mutually exclusive.
|
|
apiVersion: traefik.io/v1alpha1
|
|
kind: IngressRouteTCP
|
|
metadata:
|
|
name: app-ssh
|
|
namespace: example
|
|
labels:
|
|
app: app
|
|
spec:
|
|
entryPoints:
|
|
- ssh
|
|
routes:
|
|
# Plain TCP (SSH here): no TLS block at all, bytes flow as-is.
|
|
- match: HostSNI(`*`)
|
|
# HostSNI matches the TLS Server Name Indication. `*` accepts anything
|
|
# (required for non-TLS protocols like SSH that send no SNI).
|
|
# With TLS + a real hostname: HostSNI(`db.example.com`).
|
|
# middlewares: TCP middleware chain (IP allowlist, rate limit...).
|
|
# middlewares:
|
|
# - name: ssh-allowlist
|
|
# priority: same semantics as HTTP - higher wins.
|
|
# priority: 10
|
|
services:
|
|
- name: app-service
|
|
port: 2222
|
|
# weight: share of connections across backends.
|
|
# weight: 1
|
|
# terminationDelay: linger after backend close to drain in-flight
|
|
# data. Default 100ms; raise for slow protocols.
|
|
terminationDelay: 100
|
|
# proxyProtocol: PROXY header toward the backend (v1/v2) so it
|
|
# learns real client IPs.
|
|
# proxyProtocol:
|
|
# version: 2
|
|
# TLS termination: Traefik decrypts with its own cert, forwards plaintext.
|
|
# - match: HostSNI(`db.example.com`)
|
|
# services:
|
|
# - name: app-service
|
|
# port: 5432
|
|
# tls: enable TLS handling on this route. Omit entirely for plain TCP.
|
|
# tls:
|
|
# Either termination...
|
|
# secretName: app-tcp-tls
|
|
# options:
|
|
# name: modern-tls
|
|
# domains:
|
|
# - main: db.example.com
|
|
# ...or passthrough (Traefik never sees plaintext; needs SNI routing):
|
|
# passthrough: true
|