cluster

Infrastructure files for Nordgedanken and Midnightthoughts.
git clone git://archive.git.mtrnord.blog/MTRNord/cluster.git
Log | Files | Refs | README

commit c0979790aa50a81e1dad2ba4eea7691602fed0e0
parent 55fd824d82f5389e673530d4dbff6856ab558d7d
Author: MTRNord <MTRNord@users.noreply.github.com>
Date:   Sun,  3 Aug 2025 16:30:34 +0200

Install envoy on new cluster

Diffstat:
Mapps/base/envoy-gateway/release.yaml | 24------------------------
Mapps/talos_cluster/envoy-gateway/gateway_settings.yaml | 1141+++++++++++++++++++++++++++++++++++++++----------------------------------------
2 files changed, 564 insertions(+), 601 deletions(-)

diff --git a/apps/base/envoy-gateway/release.yaml b/apps/base/envoy-gateway/release.yaml @@ -130,30 +130,6 @@ spec: load-balancer.hetzner.cloud/uses-proxyprotocol: "false" # no wildcards due to Envoy bug: https://github.com/envoyproxy/gateway/issues/2675#issuecomment-1960449002 listeners: - - name: https-mas-midnightthoughts - protocol: HTTPS - hostname: "mas.matrix.midnightthoughts.space" - port: 443 - allowedRoutes: - namespaces: - from: "All" - tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: mas.matrix.midnightthoughts.space-tls - - name: https-matrix-midnightthoughts - protocol: HTTPS - hostname: "matrix.midnightthoughts.space" - port: 443 - allowedRoutes: - namespaces: - from: "All" - tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: matrix.midnightthoughts.space-tls - name: https-draupnir-midnightthoughts protocol: HTTPS hostname: "draupnir.midnightthoughts.space" diff --git a/apps/talos_cluster/envoy-gateway/gateway_settings.yaml b/apps/talos_cluster/envoy-gateway/gateway_settings.yaml @@ -1,4 +1,3 @@ ---- apiVersion: gateway.envoyproxy.io/v1alpha1 kind: EnvoyProxy metadata: @@ -44,47 +43,47 @@ spec: load-balancer.hetzner.cloud/use-private-ip: "true" load-balancer.hetzner.cloud/uses-proxyprotocol: "true" # no wildcards due to Envoy bug: https://github.com/envoyproxy/gateway/issues/2675#issuecomment-1960449002 - listeners: [] - # - name: smtp - # protocol: TCP - # port: 25 - # allowedRoutes: - # kinds: - # - kind: TCPRoute - # namespaces: - # from: All - # - name: submissions - # protocol: TCP - # port: 465 - # allowedRoutes: - # kinds: - # - kind: TCPRoute - # namespaces: - # from: All - # - name: submission - # protocol: TCP - # port: 587 - # allowedRoutes: - # kinds: - # - kind: TCPRoute - # namespaces: - # from: All - # - name: imap - # protocol: TCP - # port: 143 - # allowedRoutes: - # kinds: - # - kind: TCPRoute - # namespaces: - # from: All - # - name: imaps - # protocol: TCP - # port: 993 - # allowedRoutes: - # kinds: - # - kind: TCPRoute - # namespaces: - # from: All + listeners: + - name: smtp + protocol: TCP + port: 25 + allowedRoutes: + kinds: + - kind: TCPRoute + namespaces: + from: All + - name: submissions + protocol: TCP + port: 465 + allowedRoutes: + kinds: + - kind: TCPRoute + namespaces: + from: All + - name: submission + protocol: TCP + port: 587 + allowedRoutes: + kinds: + - kind: TCPRoute + namespaces: + from: All + - name: imap + protocol: TCP + port: 143 + allowedRoutes: + kinds: + - kind: TCPRoute + namespaces: + from: All + - name: imaps + protocol: TCP + port: 993 + allowedRoutes: + kinds: + - kind: TCPRoute + namespaces: + from: All --- apiVersion: gateway.networking.k8s.io/v1 kind: Gateway @@ -103,541 +102,529 @@ spec: load-balancer.hetzner.cloud/use-private-ip: "true" load-balancer.hetzner.cloud/uses-proxyprotocol: "true" # no wildcards due to Envoy bug: https://github.com/envoyproxy/gateway/issues/2675#issuecomment-1960449002 - listeners: [] - # - name: https-mas-midnightthoughts - # protocol: HTTPS - # hostname: "mas.matrix.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: mas.matrix.midnightthoughts.space-tls - # - name: https-matrix-midnightthoughts - # protocol: HTTPS - # hostname: "matrix.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: matrix.midnightthoughts.space-tls - # - name: https-draupnir-midnightthoughts - # protocol: HTTPS - # hostname: "draupnir.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: draupnir.midnightthoughts.space-tls - # - name: https-matrix-draupnir-midnightthoughts - # protocol: HTTPS - # hostname: "matrix.draupnir.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: matrix.draupnir.midnightthoughts.space-tls - # - name: https-docuseal-midnightthoughts - # protocol: HTTPS - # hostname: "docuseal.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: docuseal.midnightthoughts.space-tls - # - name: https-midnightthoughts-neoboard - # protocol: HTTPS - # hostname: "miro-export.neoboard.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: miro-export.neoboard.midnightthoughts.space-tls - # - name: https-midnightthoughts-certs - # protocol: HTTPS - # hostname: "certs.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: certs.midnightthoughts.space-tls - # - name: https-midnightthoughts-capacitor - # protocol: HTTPS - # hostname: "ui.k8s.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: ui.k8s.midnightthoughts.space-tls - # - name: https-midnightthoughts-auth - # protocol: HTTPS - # hostname: "auth.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: auth.midnightthoughts.space-tls - # - name: https-midnightthoughts-ldap - # protocol: HTTPS - # hostname: "ldap.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: ldap.midnightthoughts.space-tls - # - name: https-midnightthoughts-status-webhook - # protocol: HTTPS - # hostname: "webhook.status.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: webhook.status.midnightthoughts.space-tls - # - name: https-midnightthoughts-budget - # protocol: HTTPS - # hostname: "budget.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: budget.midnightthoughts.space-tls - # - name: https-midnightthoughts-bugzilla - # protocol: HTTPS - # hostname: "bugzilla.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: bugzilla.midnightthoughts.space-tls - # - name: https-midnightthoughts-root - # protocol: HTTPS - # hostname: "midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: midnightthoughts.space-tls - # - name: https-midnightthoughts-status - # protocol: HTTPS - # hostname: "status.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: status.midnightthoughts.space-tls - # - name: https-midnightthoughts-webhook-kubernetes - # protocol: HTTPS - # hostname: "webhook.kubernetes.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: webhook.kubernetes.midnightthoughts.space-tls - # - name: https-midnightthoughts-rspamd - # protocol: HTTPS - # hostname: "rspamd.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: rspamd.midnightthoughts.space-tls - # - name: https-midnightthoughts-grafana - # protocol: HTTPS - # hostname: "grafana.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: grafana.midnightthoughts.space-tls - # - name: https-midnightthoughts-osticket - # protocol: HTTPS - # hostname: "osticket.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: osticket.midnightthoughts.space-tls - # - name: https-midnightthoughts-vault - # protocol: HTTPS - # hostname: "vault.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: vault.midnightthoughts.space-tls - # - name: https-midnightthoughts-rook - # protocol: HTTPS - # hostname: "rook.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: rook.midnightthoughts.space-tls - # - name: https-midnightthoughts-jenkins - # protocol: HTTPS - # hostname: "jenkins.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: jenkins.midnightthoughts.space-tls - # - name: https-midnightthoughts-gerrit - # protocol: HTTPS - # hostname: "gerrit.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: gerrit.midnightthoughts.space-tls - # - name: https-midnightthoughts-uptime - # protocol: HTTPS - # hostname: "uptime.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: uptime.midnightthoughts.space-tls - # - name: https-midnightthoughts-element-changes - # protocol: HTTPS - # hostname: "element-changes.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: element-changes.midnightthoughts.space - # - name: https-midnightthoughts-dav - # protocol: HTTPS - # hostname: "dav.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: dav.midnightthoughts.space - # - name: https-midnightthoughts-plane - # protocol: HTTPS - # hostname: "plane.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: plane.midnightthoughts.space - # - name: https-midnightthoughts-irc - # protocol: HTTPS - # hostname: "irc.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: irc.midnightthoughts.space - # - name: https-midnightthoughts-rspamd-matrix - # protocol: HTTPS - # hostname: "rspamd.matrix.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: rspamd.matrix.midnightthoughts.space - # - name: https-midnightthoughts-collabora - # protocol: HTTPS - # hostname: "collabora.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: collabora.midnightthoughts.space - # - name: https-nordgedanken-root - # protocol: HTTPS - # hostname: "nordgedanken.dev" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: nordgedanken.dev-tls - # - name: https-nordgedanken - # protocol: HTTPS - # hostname: "*.nordgedanken.dev" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: nordgedanken.dev-tls - # - name: https-mtrnord-blog-root - # protocol: HTTPS - # hostname: "mtrnord.blog" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: mtrnord.blog-tls - # - name: https-mtrnord-blog-matrix - # protocol: HTTPS - # hostname: "matrix.mtrnord.blog" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: matrix.mtrnord.blog-tls - # - name: https-mtrnord-blog-hubzilla - # protocol: HTTPS - # hostname: "hub.mtrnord.blog" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: hub.mtrnord.blog-tls - # - name: https-mtrnord-blog-mastodon - # protocol: HTTPS - # hostname: "mastodon.mtrnord.blog" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: mastodon.mtrnord.blog-tls - # - name: https-api-connectivity-tester-mtrnord-blog - # protocol: HTTPS - # hostname: "api.connectivity-tester.mtrnord.blog" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: api.connectivity-tester.mtrnord.blog-tls - # - name: https-stage-connectivity-tester-mtrnord-blog - # protocol: HTTPS - # hostname: "stage.connectivity-tester.mtrnord.blog" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: stage.connectivity-tester.mtrnord.blog-tls - # - name: https-connectivity-tester-mtrnord-blog - # protocol: HTTPS - # hostname: "connectivity-tester.mtrnord.blog" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: connectivity-tester.mtrnord.blog-tls - # - name: https-federationtester-mtrnord-blog - # protocol: HTTPS - # hostname: "federationtester.mtrnord.blog" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: federationtester.mtrnord.blog-tls - # - name: https-notify-mtrnord-blog - # protocol: HTTPS - # hostname: "notify.mtrnord.blog" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: notify.mtrnord.blog-tls - # - name: https-rss-mtrnord-blog - # protocol: HTTPS - # hostname: "rss.mtrnord.blog" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: rss.mtrnord.blog-tls - # - name: http - # protocol: HTTP - # port: 80 - # allowedRoutes: - # namespaces: - # from: "All" - # - name: ldap - # protocol: TCP - # port: 389 - # allowedRoutes: - # kinds: - # - kind: TCPRoute - # namespaces: - # from: All - # - name: gerrit-ssh - # protocol: TCP - # port: 29418 - # allowedRoutes: - # kinds: - # - kind: TCPRoute - # namespaces: - # from: All - # - name: ircs - # protocol: TCP - # port: 6697 - # allowedRoutes: - # kinds: - # - kind: TCPRoute - # namespaces: - # from: All + listeners: + - name: https-talos-midnightthoughts + protocol: HTTPS + hostname: "talos.midnightthoughts.space" + port: 443 + allowedRoutes: + namespaces: + from: "All" + tls: + mode: Terminate + certificateRefs: + - kind: Secret + name: talos.midnightthoughts.space-tls + # - name: https-draupnir-midnightthoughts + # protocol: HTTPS + # hostname: "draupnir.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: draupnir.midnightthoughts.space-tls + # - name: https-matrix-draupnir-midnightthoughts + # protocol: HTTPS + # hostname: "matrix.draupnir.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: matrix.draupnir.midnightthoughts.space-tls + # - name: https-docuseal-midnightthoughts + # protocol: HTTPS + # hostname: "docuseal.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: docuseal.midnightthoughts.space-tls + # - name: https-midnightthoughts-neoboard + # protocol: HTTPS + # hostname: "miro-export.neoboard.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: miro-export.neoboard.midnightthoughts.space-tls + # - name: https-midnightthoughts-certs + # protocol: HTTPS + # hostname: "certs.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: certs.midnightthoughts.space-tls + # - name: https-midnightthoughts-capacitor + # protocol: HTTPS + # hostname: "ui.k8s.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: ui.k8s.midnightthoughts.space-tls + # - name: https-midnightthoughts-auth + # protocol: HTTPS + # hostname: "auth.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: auth.midnightthoughts.space-tls + # - name: https-midnightthoughts-ldap + # protocol: HTTPS + # hostname: "ldap.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: ldap.midnightthoughts.space-tls + # - name: https-midnightthoughts-status-webhook + # protocol: HTTPS + # hostname: "webhook.status.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: webhook.status.midnightthoughts.space-tls + # - name: https-midnightthoughts-budget + # protocol: HTTPS + # hostname: "budget.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: budget.midnightthoughts.space-tls + # - name: https-midnightthoughts-bugzilla + # protocol: HTTPS + # hostname: "bugzilla.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: bugzilla.midnightthoughts.space-tls + # - name: https-midnightthoughts-root + # protocol: HTTPS + # hostname: "midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: midnightthoughts.space-tls + # - name: https-midnightthoughts-status + # protocol: HTTPS + # hostname: "status.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: status.midnightthoughts.space-tls + # - name: https-midnightthoughts-webhook-kubernetes + # protocol: HTTPS + # hostname: "webhook.kubernetes.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: webhook.kubernetes.midnightthoughts.space-tls + # - name: https-midnightthoughts-rspamd + # protocol: HTTPS + # hostname: "rspamd.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: rspamd.midnightthoughts.space-tls + # - name: https-midnightthoughts-grafana + # protocol: HTTPS + # hostname: "grafana.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: grafana.midnightthoughts.space-tls + # - name: https-midnightthoughts-osticket + # protocol: HTTPS + # hostname: "osticket.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: osticket.midnightthoughts.space-tls + # - name: https-midnightthoughts-vault + # protocol: HTTPS + # hostname: "vault.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: vault.midnightthoughts.space-tls + # - name: https-midnightthoughts-rook + # protocol: HTTPS + # hostname: "rook.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: rook.midnightthoughts.space-tls + # - name: https-midnightthoughts-jenkins + # protocol: HTTPS + # hostname: "jenkins.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: jenkins.midnightthoughts.space-tls + # - name: https-midnightthoughts-gerrit + # protocol: HTTPS + # hostname: "gerrit.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: gerrit.midnightthoughts.space-tls + # - name: https-midnightthoughts-uptime + # protocol: HTTPS + # hostname: "uptime.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: uptime.midnightthoughts.space-tls + # - name: https-midnightthoughts-element-changes + # protocol: HTTPS + # hostname: "element-changes.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: element-changes.midnightthoughts.space + # - name: https-midnightthoughts-dav + # protocol: HTTPS + # hostname: "dav.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: dav.midnightthoughts.space + # - name: https-midnightthoughts-plane + # protocol: HTTPS + # hostname: "plane.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: plane.midnightthoughts.space + # - name: https-midnightthoughts-irc + # protocol: HTTPS + # hostname: "irc.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: irc.midnightthoughts.space + # - name: https-midnightthoughts-rspamd-matrix + # protocol: HTTPS + # hostname: "rspamd.matrix.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: rspamd.matrix.midnightthoughts.space + # - name: https-midnightthoughts-collabora + # protocol: HTTPS + # hostname: "collabora.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: collabora.midnightthoughts.space + # - name: https-nordgedanken-root + # protocol: HTTPS + # hostname: "nordgedanken.dev" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: nordgedanken.dev-tls + # - name: https-nordgedanken + # protocol: HTTPS + # hostname: "*.nordgedanken.dev" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: nordgedanken.dev-tls + # - name: https-mtrnord-blog-root + # protocol: HTTPS + # hostname: "mtrnord.blog" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: mtrnord.blog-tls + # - name: https-mtrnord-blog-matrix + # protocol: HTTPS + # hostname: "matrix.mtrnord.blog" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: matrix.mtrnord.blog-tls + # - name: https-mtrnord-blog-hubzilla + # protocol: HTTPS + # hostname: "hub.mtrnord.blog" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: hub.mtrnord.blog-tls + # - name: https-mtrnord-blog-mastodon + # protocol: HTTPS + # hostname: "mastodon.mtrnord.blog" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: mastodon.mtrnord.blog-tls + # - name: https-api-connectivity-tester-mtrnord-blog + # protocol: HTTPS + # hostname: "api.connectivity-tester.mtrnord.blog" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: api.connectivity-tester.mtrnord.blog-tls + # - name: https-stage-connectivity-tester-mtrnord-blog + # protocol: HTTPS + # hostname: "stage.connectivity-tester.mtrnord.blog" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: stage.connectivity-tester.mtrnord.blog-tls + # - name: https-connectivity-tester-mtrnord-blog + # protocol: HTTPS + # hostname: "connectivity-tester.mtrnord.blog" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: connectivity-tester.mtrnord.blog-tls + # - name: https-federationtester-mtrnord-blog + # protocol: HTTPS + # hostname: "federationtester.mtrnord.blog" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: federationtester.mtrnord.blog-tls + # - name: https-notify-mtrnord-blog + # protocol: HTTPS + # hostname: "notify.mtrnord.blog" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: notify.mtrnord.blog-tls + # - name: https-rss-mtrnord-blog + # protocol: HTTPS + # hostname: "rss.mtrnord.blog" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: rss.mtrnord.blog-tls + # - name: http + # protocol: HTTP + # port: 80 + # allowedRoutes: + # namespaces: + # from: "All" + # - name: ldap + # protocol: TCP + # port: 389 + # allowedRoutes: + # kinds: + # - kind: TCPRoute + # namespaces: + # from: All + # - name: gerrit-ssh + # protocol: TCP + # port: 29418 + # allowedRoutes: + # kinds: + # - kind: TCPRoute + # namespaces: + # from: All + # - name: ircs + # protocol: TCP + # port: 6697 + # allowedRoutes: + # kinds: + # - kind: TCPRoute + # namespaces: + # from: All --- apiVersion: gateway.envoyproxy.io/v1alpha1 kind: ClientTrafficPolicy