Files
homelab/traefik/k8s/traefik-values.yaml
forust 0859479c0f
ci / lint-compose (push) Successful in 9s
ci / lint-actionlint (push) Successful in 4s
ci / lint-shellcheck (push) Successful in 7s
ci / lint-prettier (push) Successful in 12s
ci / lint-ruff (push) Successful in 6s
ci / lint-yaml (push) Successful in 9s
ci / lint-dockerfiles (push) Successful in 5s
ci / validate (push) Successful in 5s
renovate-ci / validate-renovate (push) Successful in 7s
ci / build (push) Failing after 14m22s
feat(ingress): replace traefik crowdsec plugin with firewall bouncer
Move L3 enforcement to the host firewall-bouncer (systemd, nftables): drop the Traefik plugin, its secrets volume and the crowdsec Middleware, remove bouncer refs from all IngressRoutes. Disable the http-generic-bf scenario (403-burst bans hurt legit automation under L3 enforcement). Add a Gateway API PoC for homepages prod and CrowdSec PrometheusRule alerts.
2026-09-30 20:14:25 +02:00

184 lines
4.2 KiB
YAML

# Auto-generated by forust | See https://github.com/traefik/traefik-helm-chart/blob/master/values.yaml
hostNetwork: false
image:
registry: docker.io/library
repository: traefik
tag: v3.7.13
securityContext:
capabilities:
add:
- NET_BIND_SERVICE
podSecurityContext: ~
service:
enabled: true
type: LoadBalancer
annotations:
metallb.io/loadBalancerIPs: "192.168.80.2"
spec:
externalTrafficPolicy: Local
api:
dashboard: true
insecure: true
updateStrategy:
type: Recreate
deployment:
enabled: true
additionalVolumes:
- name: plugins
persistentVolumeClaim:
claimName: traefik-plugins
additionalVolumeMounts:
- name: plugins
mountPath: /plugins-storage
# BestEffort (no requests) meant kubelet squeezed traefik first under node
# pressure, down to /ping timeouts and liveness restarts. Burstable instead.
resources:
requests:
cpu: "200m"
memory: "256Mi"
limits:
cpu: "1000m"
memory: "1Gi"
# Single replica is the whole ingress: a SIGKILL here takes every public
# service down. Budgets are sized for HDD stalls on a loaded node, not for a
# healthy disk — same treatment as immich postgres and metallb speaker.
readinessProbe:
failureThreshold: 6
initialDelaySeconds: 10
periodSeconds: 10
successThreshold: 1
timeoutSeconds: 5
livenessProbe:
failureThreshold: 6
initialDelaySeconds: 30
periodSeconds: 30
successThreshold: 1
timeoutSeconds: 5
providers:
kubernetesIngress:
enabled: true
kubernetesCRD:
enabled: true
kubernetesGateway:
enabled: true
file:
enabled: false
# Entrypoints
ports:
web:
port: 80
http:
aliasHeadersStrategy: delete
redirections:
entryPoint:
to: websecure
scheme: https
permanent: true
websecure:
port: 443
http:
aliasHeadersStrategy: delete
tls:
enabled: true
traefik:
port: 8080
exposedPort: 8080
protocol: TCP
expose:
default: false
http:
aliasHeadersStrategy: delete
ssh:
port: 2221
exposedPort: 2221
protocol: TCP
expose:
default: true
http:
aliasHeadersStrategy: delete
minecraft-tcp:
port: 25565
exposedPort: 25565
protocol: TCP
expose:
default: true
http:
aliasHeadersStrategy: delete
minecraft-udp:
port: 19132
exposedPort: 19132
protocol: UDP
expose:
default: true
netbird-stun:
port: 3478
exposedPort: 3478
protocol: UDP
expose:
default: true
checkmk-agent:
port: 8000
protocol: TCP
expose:
default: true
http:
aliasHeadersStrategy: delete
metrics:
port: 9100
exposedPort: 9100
protocol: TCP
expose:
default: false
http:
aliasHeadersStrategy: delete
metrics:
prometheus:
enabled: true
entryPoint: metrics
serviceMonitor:
enabled: true
additionalLabels:
release: prometheus-stack
namespace: prometheus
ingressRoute:
dashboard:
enabled: false
persistence:
enabled: true
size: 100Mi
path: /data
# No certificatesResolvers: public TLS comes from cert-manager.
# No plugins: L3 enforcement moved to the host firewall bouncer,
# nothing runs in the request path anymore.
volumes:
- name: traefik-dynamic
mountPath: /etc/traefik/dynamic
type: configMap
additionalArguments:
- "--providers.file.directory=/etc/traefik/dynamic"
- "--providers.file.watch=true"
- "--providers.kubernetesCRD.allowCrossNamespace=true"
- "--providers.kubernetesCRD.safeNaming=false"
- "--entryPoints.websecure.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22,192.168.1.1,192.168.1.0/24,192.168.88.0/24,192.168.88.1"
- "--entryPoints.web.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22,192.168.1.1,192.168.1.0/24,192.168.88.0/24,192.168.88.1"
log:
level: INFO
accessLog:
enabled: true
format: common