feat(michael): change url (#363)

This commit is contained in:
Antoine Lecompte
2026-07-29 12:09:01 +00:00
committed by GitHub
parent fc8b52fb5f
commit a0c70541d5
6 changed files with 29 additions and 8 deletions
@@ -1,7 +1,8 @@
---
# yaml-language-server: $schema=https://k8s-schemas.home-operations.com/cert-manager.io/certificate_v1.json
# Wildcard + apex for the cluster's APP_DOMAIN — covers web (apex), api., gw.
# (and admin. when it's exposed). cert-manager writes app-domain-tls into this
# Wildcard + apex for the cluster's APP_DOMAIN — covers web (apex), api.
# (and admin. when it's exposed; prod's restic host is two labels down and has
# its own gw-public cert). cert-manager writes app-domain-tls into this
# namespace (envoy-system) for the Gateway(s) to terminate with.
apiVersion: cert-manager.io/v1
kind: Certificate
@@ -0,0 +1,17 @@
---
# yaml-language-server: $schema=https://k8s-schemas.home-operations.com/cert-manager.io/certificate_v1.json
# Cert for the public restic hostname (${GW_HOST}). rest.htz-fsn1. is two
# labels below APP_DOMAIN, so the shared *.APP_DOMAIN wildcard doesn't cover
# it; same DNS-01 pipeline as gw-internal. Lands in envoy-system
# (targetNamespace-forced) beside the Gateway.
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: gw-public
spec:
secretName: gw-public-tls
issuerRef:
name: letsencrypt-production
kind: ClusterIssuer
dnsNames:
- "${GW_HOST}"
@@ -2,8 +2,9 @@
# The michael (restic) Gateway: HTTPS-only, scoped to ${GW_HOST}. Shares the
# `envoy` GatewayClass but attaches its own EnvoyProxy via
# infrastructure.parametersRef (Envoy Gateway creates one proxy fleet per
# Gateway). TLS terminates with the shared wildcard cert (*.APP_DOMAIN covers
# gw.); no :80 listener — restic clients speak HTTPS only.
# Gateway). TLS terminates with the gw-public cert (certificate.yaml — the
# *.APP_DOMAIN wildcard doesn't reach rest.htz-fsn1.); no :80 listener —
# restic clients speak HTTPS only.
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
@@ -27,7 +28,7 @@ spec:
mode: Terminate
certificateRefs:
- kind: Secret
name: app-domain-tls
name: gw-public-tls
# Internal twin (${GW_INT_VIP}): same envoy fleet, NetBird-zone hostname,
# own DNS-01 cert (gw-internal.yaml at the overlay root).
- name: https-internal
@@ -2,6 +2,7 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./certificate.yaml
- ./envoyproxy.yaml
- ./gateway.yaml
- ./policies.yaml
@@ -18,9 +18,10 @@ data:
METRICS_ENV_LABEL: prod
# Per-service ingress hostnames. web (apex; /api routes to yucca-api) on the
# app gateway; gw. (michael, restic) on the dedicated gw-proxy gateway.
# app gateway; rest.htz-fsn1. (michael, restic) on the dedicated gw-proxy
# gateway (own cert — outside the *.APP_DOMAIN wildcard).
APP_DOMAIN: backups.futo.cloud
GW_HOST: gw.backups.futo.cloud
GW_HOST: rest.htz-fsn1.backups.futo.cloud
# Spice RGW (Ceph S3): round-robin DNS across all 48 nodes' fabric VLAN-120
# IPs (prod/global/dns), reached over the FABRIC — the spine routes
@@ -26,7 +26,7 @@ records = {
values = ["69.48.224.5"]
comment = "Yucca prod web/api gateway (tf/deployment/prod/global/dns)"
}
"gw.backups.futo.cloud" = {
"rest.htz-fsn1.backups.futo.cloud" = {
type = "A"
values = ["69.48.224.6"]
comment = "Yucca prod restic gateway - michael (tf/deployment/prod/global/dns)"