apiVersion: traefik.io/v1alpha1 kind: IngressRoute metadata: name: gitea-prod namespace: gitea spec: entryPoints: - websecure routes: - match: Host(`gitea.forust.xyz`) kind: Rule middlewares: - name: crowdsec-bouncer namespace: crowdsec services: - name: gitea-service port: 3000 # Registry route: NO crowdsec-bouncer. # The bouncer plugin does a blocking `GET /v1/decisions` to the LAPI on # *every* request. A deploy burst (runner Action API polls, `docker # manifest inspect` per own image, containerd pulls, smoke probes) fires # hundreds of parallel registry calls; LAPI saturation pushed the lookup # past the plugin timeout, and the bouncer fail-closed with 403 - which # containerd surfaces as ErrImagePull/ImagePullBackOff on the next pod. # This route only serves authenticated OCI traffic (registry tokens, # basic-auth already handled by gitea) and scanners get nothing useful # from /v2, so there is no bruteforce surface to protect here. - match: Host(`gcr.forust.xyz`) && PathPrefix(`/v2`) kind: Rule services: - name: gitea-service port: 3000 tls: secretName: gitea-prod-tls --- apiVersion: traefik.io/v1alpha1 kind: IngressRoute metadata: name: gitea-local namespace: gitea spec: entryPoints: - websecure routes: - match: Host(`gitea.workstation.internal`) || Host(`gitea.gigaforust.internal`) kind: Rule services: - name: gitea-service port: 3000 - match: (Host(`gcr.workstation.internal`) || Host(`gcr.gigaforust.internal`)) && PathPrefix(`/v2`) kind: Rule services: - name: gitea-service port: 3000 tls: secretName: internal-wildcard-tls --- apiVersion: traefik.io/v1alpha1 kind: IngressRouteTCP metadata: name: gitea-ssh namespace: gitea spec: entryPoints: - ssh routes: - match: HostSNI(`*`) services: - name: gitea-service port: 2221