traefik: add private ingress with preserved client addresses

This commit is contained in:
jenkins 2026-09-28 17:10:12 -05:00
parent 0274335dfe
commit 4bd487b8b3
4 changed files with 45 additions and 0 deletions

View File

@ -5,3 +5,4 @@ resources:
- namespace.yaml
- helmrelease.yaml
- ippool.yaml
- lan-ai-pool.yaml

View File

@ -0,0 +1,19 @@
# infrastructure/metallb/lan-ai-pool.yaml
apiVersion: metallb.io/v1beta1
kind: IPAddressPool
metadata:
name: lan-ai-pool
namespace: metallb-system
spec:
addresses:
- 192.168.22.50/32
autoAssign: false
---
apiVersion: metallb.io/v1beta1
kind: L2Advertisement
metadata:
name: lan-ai-adv
namespace: metallb-system
spec:
ipAddressPools:
- lan-ai-pool

View File

@ -14,3 +14,4 @@ resources:
- clusterrolebinding.yaml
- service.yaml
- traefik-service-lb.yaml
- traefik-service-lan.yaml

View File

@ -0,0 +1,24 @@
# infrastructure/traefik/traefik-service-lan.yaml
apiVersion: v1
kind: Service
metadata:
name: traefik-lan
namespace: traefik
annotations:
metallb.universe.tf/address-pool: lan-ai-pool
spec:
type: LoadBalancer
loadBalancerClass: metallb
loadBalancerIP: 192.168.22.50
# The shared public Service masks source addresses. Keep the LAN path
# separate so ingress allowlists see the actual client, not a node IP.
externalTrafficPolicy: Local
loadBalancerSourceRanges:
- 192.168.22.0/24
ports:
- name: websecure
port: 443
targetPort: websecure
protocol: TCP
selector:
app: traefik