# services/maintenance/metis-ingress.yaml apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: metis namespace: maintenance annotations: kubernetes.io/ingress.class: traefik cert-manager.io/cluster-issuer: letsencrypt traefik.ingress.kubernetes.io/router.entrypoints: websecure traefik.ingress.kubernetes.io/router.tls: "true" traefik.ingress.kubernetes.io/router.middlewares: sso-oauth2-proxy-forward-auth@kubernetescrd spec: ingressClassName: traefik tls: - hosts: ["metis.bstein.dev", "sentinel.bstein.dev"] secretName: metis-tls rules: - host: metis.bstein.dev http: paths: - path: / pathType: Prefix backend: service: name: metis port: number: 80 - host: sentinel.bstein.dev http: paths: - path: / pathType: Prefix backend: service: name: metis port: number: 80