maintenance: issue sentinel-only certificate for metis

This commit is contained in:
Brad Stein 2026-03-31 17:01:23 -03:00
parent 554c339365
commit c5a0e60fd3
3 changed files with 16 additions and 13 deletions

View File

@ -35,6 +35,7 @@ resources:
- node-image-sweeper-daemonset.yaml - node-image-sweeper-daemonset.yaml
- image-sweeper-cronjob.yaml - image-sweeper-cronjob.yaml
- metis-service.yaml - metis-service.yaml
- metis-certificate.yaml
- metis-ingress.yaml - metis-ingress.yaml
images: images:
- name: registry.bstein.dev/bstein/ariadne - name: registry.bstein.dev/bstein/ariadne

View File

@ -0,0 +1,13 @@
# services/maintenance/metis-certificate.yaml
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: sentinel-tls
namespace: maintenance
spec:
secretName: sentinel-tls
issuerRef:
kind: ClusterIssuer
name: letsencrypt
dnsNames:
- sentinel.bstein.dev

View File

@ -6,26 +6,15 @@ metadata:
namespace: maintenance namespace: maintenance
annotations: annotations:
kubernetes.io/ingress.class: traefik kubernetes.io/ingress.class: traefik
cert-manager.io/cluster-issuer: letsencrypt
traefik.ingress.kubernetes.io/router.entrypoints: websecure traefik.ingress.kubernetes.io/router.entrypoints: websecure
traefik.ingress.kubernetes.io/router.tls: "true" traefik.ingress.kubernetes.io/router.tls: "true"
traefik.ingress.kubernetes.io/router.middlewares: sso-oauth2-proxy-errors@kubernetescrd,sso-oauth2-proxy-forward-auth@kubernetescrd traefik.ingress.kubernetes.io/router.middlewares: sso-oauth2-proxy-errors@kubernetescrd,sso-oauth2-proxy-forward-auth@kubernetescrd
spec: spec:
ingressClassName: traefik ingressClassName: traefik
tls: tls:
- hosts: ["metis.bstein.dev", "sentinel.bstein.dev"] - hosts: ["sentinel.bstein.dev"]
secretName: metis-tls secretName: sentinel-tls
rules: rules:
- host: metis.bstein.dev
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: metis
port:
number: 80
- host: sentinel.bstein.dev - host: sentinel.bstein.dev
http: http:
paths: paths: