Files
homelab/templates/ingressroute.yaml
T
forust 18c633c242
ci / lint-prettier (push) Skipped
ci / lint-ruff (push) Skipped
ci / lint-yaml (push) Skipped
ci / lint-dockerfiles (push) Skipped
ci / validate (push) Skipped
renovate-ci / validate-renovate (push) Skipped
renovate-ci / validate-renovate (pull_request) Skipped
ci / lint-compose (pull_request) Successful in 12s
ci / lint-actionlint (pull_request) Successful in 6s
ci / lint-shellcheck (pull_request) Successful in 13s
ci / lint-prettier (pull_request) Successful in 21s
ci / lint-ruff (pull_request) Successful in 7s
ci / lint-yaml (pull_request) Successful in 12s
ci / lint-dockerfiles (pull_request) Successful in 7s
ci / validate (pull_request) Successful in 7s
ci / build (pull_request) Skipped
feat(monitoring): add VictoriaMetrics trial stack
2026-10-06 17:45:44 +02:00

94 lines
3.7 KiB
YAML

# Exhaustive Traefik IngressRoute reference (traefik.io/v1alpha1, HTTP).
# Routes are evaluated top to bottom by priority, then by rule length: the
# first matching route handles the request. Keep specific rules above the
# catch-all.
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: app-prod
namespace: example
labels:
app: app
annotations:
description: "exhaustive traefik http route example"
spec:
# entryPoints: static entrypoints the route listens on (ports Traefik was
# started with: web=:80, websecure=:443, plus any custom ones).
entryPoints:
- websecure
routes:
# Rule 1: API subtree with middleware chain and weighted backends.
- match: Host(`app.example.com`) && PathPrefix(`/api`)
# kind: Rule (match traffic) or the same match used for redirections.
kind: Rule
# priority: explicit precedence. Higher wins regardless of position.
# Default is the rule length in characters - explicit numbers beat
# clever ordering.
priority: 100
# middlewares: request pipeline, in order (auth, headers, rate limit,
# redirect, strip prefix...). Same-namespace by name; cross-namespace
# as name@namespace (never across providers without the suffix).
middlewares:
- name: app-auth
- name: security-headers
services:
- name: app-service
# port: Service port number or name.
port: 80
# scheme: http (default), https (TLS backend), h2c (cleartext
# HTTP/2, e.g. gRPC without TLS).
scheme: http
# weight: traffic share for canary/blue-green splits.
weight: 90
# serversTransport: ServersTransport CRD with TLS/forwarding
# tuning for this backend (rootCAs, insecureSkipVerify...).
# serversTransport: app-transport
# responseForwarding:
# flushInterval: 100ms
# passHostHeader: forward the original Host header (default true).
# passHostHeader: true
# proxyProtocol: speak PROXY protocol to the backend so it sees
# real client IPs. Version v1 or v2; backend must understand it.
# proxyProtocol:
# version: 2
- name: app-canary-service
port: 80
weight: 10
# Rule 2: multiple hosts, regex path, external backend by URL.
- match: (Host(`app.example.com`) || Host(`www.example.com`)) && PathRegexp(`^/files/.*$`)
kind: Rule
priority: 50
services:
# servers: bypass the Service and address backends directly.
# Only one of name/port (cluster Service) or servers (explicit
# URLs) may be set.
- name: app-service
port: 80
# Catch-all rule: everything not matched above.
- match: Host(`app.example.com`)
kind: Rule
priority: 1
services:
- name: app-service
port: 80
# tls: terminate TLS on this route. Omit the whole block for plain HTTP.
tls:
# secretName: TLS Secret (tls.crt/tls.key) in THIS namespace.
secretName: app-prod-tls
# options: TLSOption CRD (minVersion, cipherSuites, sniStrict...).
# options:
# name: modern-tls
# certResolver: ACME resolver name (letsencrypt-style) that issues the
# certificate on demand. Use EITHER certResolver OR secretName, not both:
# resolver for auto-issued certs, secretName for pre-made ones.
# certResolver: letsencrypt
# store: custom TLSStore for the certificate. Default store otherwise.
# store:
# name: default
# domains: certificates to request/serve (main + SANs). With secretName
# this documents intent; with certResolver it drives issuance.
domains:
- main: app.example.com
sans:
- www.example.com