Files
homelab/vpn/xui/k8s/ingress.yaml
forust bc1e69ebe0
ci / lint-prettier (push) Successful in 2s
ci / lint-ruff (push) Successful in 0s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 1s
ci / build (push) Skipped
ci / deploy-userbot-panel (push) Skipped
feat(tls): internal CA wildcard for *.internal routes
Selfsigned root (10y) + internal-ca issuer; per-namespace
internal-wildcard-tls certs referenced by all -local routers.
Root public cert committed for client trust stores.
2026-09-23 14:45:05 +02:00

87 lines
2.0 KiB
YAML

apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: xui-local
namespace: xui
spec:
entryPoints:
- websecure
routes:
- match: Host(`xui.workstation.internal`) || Host(`xui.gigaforust.internal`)
kind: Rule
services:
- name: xui-service
port: 30379
tls:
secretName: internal-wildcard-tls
---
# Public panel access (optional).
# Realistic, but intentionally disabled: the panel has its own login,
# security-chain adds Authentik in front of it.
# To enable: uncomment and add Public Hostname `xui.forust.xyz`
# in the Cloudflare tunnel (same as other *.forust.xyz hosts).
# ---
# apiVersion: traefik.io/v1alpha1
# kind: IngressRoute
# metadata:
# name: xui-prod
# namespace: xui
# spec:
# entryPoints:
# - websecure
# routes:
# - match: Host(`xui.forust.xyz`)
# kind: Rule
# middlewares:
# - name: security-chain@file
# services:
# - name: xui-service
# port: 30379
# tls:
# certResolver: letsencrypt
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: xray-prod
namespace: xui
spec:
entryPoints:
- websecure
routes:
- match: Host(`xray.forust.xyz`) && PathPrefix(`/pzzfpz6oi281f0u8`)
kind: Rule
services:
- name: xui-service
port: 2096
- match: Host(`xray.forust.xyz`)
kind: Rule
services:
- name: xui-service
port: 10000
tls:
secretName: xray-prod-tls
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: xray-local
namespace: xui
spec:
entryPoints:
- websecure
routes:
- match: (Host(`xray.workstation.internal`) || Host(`xray.gigaforust.internal`)) && PathPrefix(`/pzzfpz6oi281f0u8`)
kind: Rule
services:
- name: xui-service
port: 2096
- match: Host(`xray.workstation.internal`) || Host(`xray.gigaforust.internal`)
kind: Rule
services:
- name: xui-service
port: 10000
tls:
secretName: internal-wildcard-tls