ci / lint-prettier (push) Skipped
ci / lint-ruff (push) Skipped
ci / lint-yaml (push) Skipped
ci / lint-dockerfiles (push) Skipped
ci / validate (push) Skipped
renovate-ci / validate-renovate (push) Skipped
renovate-ci / validate-renovate (pull_request) Skipped
ci / lint-compose (pull_request) Successful in 12s
ci / lint-actionlint (pull_request) Successful in 6s
ci / lint-shellcheck (pull_request) Successful in 13s
ci / lint-prettier (pull_request) Successful in 21s
ci / lint-ruff (pull_request) Successful in 7s
ci / lint-yaml (pull_request) Successful in 12s
ci / lint-dockerfiles (pull_request) Successful in 7s
ci / validate (pull_request) Successful in 7s
ci / build (pull_request) Skipped
94 lines
3.7 KiB
YAML
94 lines
3.7 KiB
YAML
# Exhaustive Traefik IngressRoute reference (traefik.io/v1alpha1, HTTP).
|
|
# Routes are evaluated top to bottom by priority, then by rule length: the
|
|
# first matching route handles the request. Keep specific rules above the
|
|
# catch-all.
|
|
apiVersion: traefik.io/v1alpha1
|
|
kind: IngressRoute
|
|
metadata:
|
|
name: app-prod
|
|
namespace: example
|
|
labels:
|
|
app: app
|
|
annotations:
|
|
description: "exhaustive traefik http route example"
|
|
spec:
|
|
# entryPoints: static entrypoints the route listens on (ports Traefik was
|
|
# started with: web=:80, websecure=:443, plus any custom ones).
|
|
entryPoints:
|
|
- websecure
|
|
routes:
|
|
# Rule 1: API subtree with middleware chain and weighted backends.
|
|
- match: Host(`app.example.com`) && PathPrefix(`/api`)
|
|
# kind: Rule (match traffic) or the same match used for redirections.
|
|
kind: Rule
|
|
# priority: explicit precedence. Higher wins regardless of position.
|
|
# Default is the rule length in characters - explicit numbers beat
|
|
# clever ordering.
|
|
priority: 100
|
|
# middlewares: request pipeline, in order (auth, headers, rate limit,
|
|
# redirect, strip prefix...). Same-namespace by name; cross-namespace
|
|
# as name@namespace (never across providers without the suffix).
|
|
middlewares:
|
|
- name: app-auth
|
|
- name: security-headers
|
|
services:
|
|
- name: app-service
|
|
# port: Service port number or name.
|
|
port: 80
|
|
# scheme: http (default), https (TLS backend), h2c (cleartext
|
|
# HTTP/2, e.g. gRPC without TLS).
|
|
scheme: http
|
|
# weight: traffic share for canary/blue-green splits.
|
|
weight: 90
|
|
# serversTransport: ServersTransport CRD with TLS/forwarding
|
|
# tuning for this backend (rootCAs, insecureSkipVerify...).
|
|
# serversTransport: app-transport
|
|
# responseForwarding:
|
|
# flushInterval: 100ms
|
|
# passHostHeader: forward the original Host header (default true).
|
|
# passHostHeader: true
|
|
# proxyProtocol: speak PROXY protocol to the backend so it sees
|
|
# real client IPs. Version v1 or v2; backend must understand it.
|
|
# proxyProtocol:
|
|
# version: 2
|
|
- name: app-canary-service
|
|
port: 80
|
|
weight: 10
|
|
# Rule 2: multiple hosts, regex path, external backend by URL.
|
|
- match: (Host(`app.example.com`) || Host(`www.example.com`)) && PathRegexp(`^/files/.*$`)
|
|
kind: Rule
|
|
priority: 50
|
|
services:
|
|
# servers: bypass the Service and address backends directly.
|
|
# Only one of name/port (cluster Service) or servers (explicit
|
|
# URLs) may be set.
|
|
- name: app-service
|
|
port: 80
|
|
# Catch-all rule: everything not matched above.
|
|
- match: Host(`app.example.com`)
|
|
kind: Rule
|
|
priority: 1
|
|
services:
|
|
- name: app-service
|
|
port: 80
|
|
# tls: terminate TLS on this route. Omit the whole block for plain HTTP.
|
|
tls:
|
|
# secretName: TLS Secret (tls.crt/tls.key) in THIS namespace.
|
|
secretName: app-prod-tls
|
|
# options: TLSOption CRD (minVersion, cipherSuites, sniStrict...).
|
|
# options:
|
|
# name: modern-tls
|
|
# certResolver: ACME resolver name (letsencrypt-style) that issues the
|
|
# certificate on demand. Use EITHER certResolver OR secretName, not both:
|
|
# resolver for auto-issued certs, secretName for pre-made ones.
|
|
# certResolver: letsencrypt
|
|
# store: custom TLSStore for the certificate. Default store otherwise.
|
|
# store:
|
|
# name: default
|
|
# domains: certificates to request/serve (main + SANs). With secretName
|
|
# this documents intent; with certResolver it drives issuance.
|
|
domains:
|
|
- main: app.example.com
|
|
sans:
|
|
- www.example.com
|