apiVersion: traefik.io/v1alpha1 kind: IngressRoute metadata: name: gitea-prod namespace: gitea spec: entryPoints: - websecure routes: - match: Host(`gitea.forust.xyz`) kind: Rule middlewares: - name: crowdsec-bouncer namespace: crowdsec services: - name: gitea-service port: 3000 # Registry route: NO crowdsec-bouncer. # A deploy burst (runner Action API polls, `docker manifest inspect` per # own image, containerd pulls, smoke probes) fires hundreds of parallel # registry calls, and a ban on the runner breaks every later job. This # route only serves authenticated OCI traffic - registry tokens and # basic-auth are already handled by gitea - and scanners get nothing # useful from /v2, so there is no bruteforce surface to protect here. - match: Host(`gcr.forust.xyz`) && PathPrefix(`/v2`) kind: Rule services: - name: gitea-service port: 3000 tls: secretName: gitea-prod-tls --- apiVersion: traefik.io/v1alpha1 kind: IngressRoute metadata: name: gitea-local namespace: gitea spec: entryPoints: - websecure routes: - match: Host(`gitea.workstation.internal`) || Host(`gitea.gigaforust.internal`) kind: Rule services: - name: gitea-service port: 3000 - match: (Host(`gcr.workstation.internal`) || Host(`gcr.gigaforust.internal`)) && PathPrefix(`/v2`) kind: Rule services: - name: gitea-service port: 3000 tls: secretName: internal-wildcard-tls --- apiVersion: traefik.io/v1alpha1 kind: IngressRouteTCP metadata: name: gitea-ssh namespace: gitea spec: entryPoints: - ssh routes: - match: HostSNI(`*`) services: - name: gitea-service port: 2221