traefik: add private ingress with preserved client addresses
This commit is contained in:
parent
0274335dfe
commit
4bd487b8b3
@ -5,3 +5,4 @@ resources:
|
||||
- namespace.yaml
|
||||
- helmrelease.yaml
|
||||
- ippool.yaml
|
||||
- lan-ai-pool.yaml
|
||||
|
||||
19
infrastructure/metallb/lan-ai-pool.yaml
Normal file
19
infrastructure/metallb/lan-ai-pool.yaml
Normal file
@ -0,0 +1,19 @@
|
||||
# infrastructure/metallb/lan-ai-pool.yaml
|
||||
apiVersion: metallb.io/v1beta1
|
||||
kind: IPAddressPool
|
||||
metadata:
|
||||
name: lan-ai-pool
|
||||
namespace: metallb-system
|
||||
spec:
|
||||
addresses:
|
||||
- 192.168.22.50/32
|
||||
autoAssign: false
|
||||
---
|
||||
apiVersion: metallb.io/v1beta1
|
||||
kind: L2Advertisement
|
||||
metadata:
|
||||
name: lan-ai-adv
|
||||
namespace: metallb-system
|
||||
spec:
|
||||
ipAddressPools:
|
||||
- lan-ai-pool
|
||||
@ -14,3 +14,4 @@ resources:
|
||||
- clusterrolebinding.yaml
|
||||
- service.yaml
|
||||
- traefik-service-lb.yaml
|
||||
- traefik-service-lan.yaml
|
||||
|
||||
24
infrastructure/traefik/traefik-service-lan.yaml
Normal file
24
infrastructure/traefik/traefik-service-lan.yaml
Normal file
@ -0,0 +1,24 @@
|
||||
# infrastructure/traefik/traefik-service-lan.yaml
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: traefik-lan
|
||||
namespace: traefik
|
||||
annotations:
|
||||
metallb.universe.tf/address-pool: lan-ai-pool
|
||||
spec:
|
||||
type: LoadBalancer
|
||||
loadBalancerClass: metallb
|
||||
loadBalancerIP: 192.168.22.50
|
||||
# The shared public Service masks source addresses. Keep the LAN path
|
||||
# separate so ingress allowlists see the actual client, not a node IP.
|
||||
externalTrafficPolicy: Local
|
||||
loadBalancerSourceRanges:
|
||||
- 192.168.22.0/24
|
||||
ports:
|
||||
- name: websecure
|
||||
port: 443
|
||||
targetPort: websecure
|
||||
protocol: TCP
|
||||
selector:
|
||||
app: traefik
|
||||
Loading…
x
Reference in New Issue
Block a user