# PoC: homepages prod hosts via Gateway API. # Runs alongside k8s/ingress.yaml - delete the prod IngressRoutes only after verification. # There are no local .internal hosts here, they stay on the local IngressRoute. # No per-route security middlewares: L3 enforcement moved to the host # firewall bouncer, so HTTPRoutes stay clean. --- apiVersion: gateway.networking.k8s.io/v1 kind: HTTPRoute metadata: name: homepages-http-redirect namespace: homepages spec: parentRefs: - name: homepages kind: Gateway sectionName: http hostnames: - forust.xyz - www.forust.xyz - xdfnx.cfd rules: - filters: - type: RequestRedirect requestRedirect: scheme: https statusCode: 301 --- apiVersion: gateway.networking.k8s.io/v1 kind: HTTPRoute metadata: name: forust-homepage-https namespace: homepages spec: parentRefs: - name: homepages kind: Gateway sectionName: https hostnames: - forust.xyz - www.forust.xyz rules: - matches: - path: type: PathPrefix value: / backendRefs: - name: forust-homepage-service port: 80 --- apiVersion: gateway.networking.k8s.io/v1 kind: HTTPRoute metadata: name: xdfnx-homepage-https namespace: homepages spec: parentRefs: - name: homepages kind: Gateway sectionName: https hostnames: - xdfnx.cfd rules: - matches: - path: type: PathPrefix value: / backendRefs: - name: xdfnx-homepage-service port: 80