apiVersion: traefik.io/v1alpha1 kind: IngressRoute metadata: name: netbird-prod namespace: netbird spec: entryPoints: - websecure routes: # NO crowdsec-bouncer on the API routes. These are the mesh client's own # endpoints: gRPC-gateway management calls plus signal/relay long-polling, # authenticated by NetBird's token rather than by a login form. A ban here # is self-defeating - the client needs the mesh to reach anything else, so # CrowdSec banning it locks the peer out of the network it needs to # function. It also backfires: a banned peer keeps retrying, every retry # is another 403, and LePresidente/http-generic-403-bf turns five 403s in # ten seconds into a 4h ban, so one 403 loop kept re-arming the ban. # netbird-local below has always been exempt; this makes prod match. - match: Host(`nb.forust.xyz`) && (PathPrefix(`/signalexchange.SignalExchange/`) || PathPrefix(`/management.ManagementService/`) || PathPrefix(`/management.ProxyService/`)) kind: Rule priority: 100 services: - name: netbird-server-service port: 80 scheme: h2c - match: Host(`nb.forust.xyz`) && (PathPrefix(`/relay`) || PathPrefix(`/ws-proxy/`) || PathPrefix(`/api`) || PathPrefix(`/oauth2`)) kind: Rule priority: 100 services: - name: netbird-server-service port: 80 - match: Host(`nb.forust.xyz`) kind: Rule priority: 1 middlewares: - name: crowdsec-bouncer namespace: crowdsec services: - name: netbird-dashboard-service port: 80 tls: secretName: netbird-prod-tls --- apiVersion: traefik.io/v1alpha1 kind: IngressRoute metadata: name: netbird-local namespace: netbird spec: entryPoints: - websecure routes: - match: (Host(`netbird.workstation.internal`) || Host(`netbird.gigaforust.internal`)) && (PathPrefix(`/signalexchange.SignalExchange/`) || PathPrefix(`/management.ManagementService/`) || PathPrefix(`/management.ProxyService/`)) kind: Rule priority: 100 services: - name: netbird-server-service port: 80 scheme: h2c - match: (Host(`netbird.workstation.internal`) || Host(`netbird.gigaforust.internal`)) && (PathPrefix(`/relay`) || PathPrefix(`/ws-proxy/`) || PathPrefix(`/api`) || PathPrefix(`/oauth2`)) kind: Rule priority: 100 services: - name: netbird-server-service port: 80 - match: Host(`netbird.workstation.internal`) || Host(`netbird.gigaforust.internal`) kind: Rule priority: 1 services: - name: netbird-dashboard-service port: 80 tls: secretName: internal-wildcard-tls --- apiVersion: traefik.io/v1alpha1 kind: IngressRouteUDP metadata: name: netbird-stun namespace: netbird spec: entryPoints: - netbird-stun routes: - services: - name: netbird-server-service port: 3478