# services/vaultwarden/ingress.yaml apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: vaultwarden-ingress namespace: vaultwarden annotations: traefik.ingress.kubernetes.io/router.entrypoints: websecure traefik.ingress.kubernetes.io/router.tls: "true" traefik.ingress.kubernetes.io/router.tls.certresolver: letsencrypt-prod cert-manager.io/cluster-issuer: letsencrypt-prod spec: ingressClassName: traefik rules: - host: vault.bstein.dev http: paths: - path: / pathType: Prefix backend: service: name: vaultwarden-service port: number: 80 tls: - hosts: - vault.bstein.dev secretName: vaultwarden-tls