mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 13:33:00 +08:00
feat(michael): change url (#363)
This commit is contained in:
@@ -1,7 +1,8 @@
|
||||
---
|
||||
# yaml-language-server: $schema=https://k8s-schemas.home-operations.com/cert-manager.io/certificate_v1.json
|
||||
# Wildcard + apex for the cluster's APP_DOMAIN — covers web (apex), api., gw.
|
||||
# (and admin. when it's exposed). cert-manager writes app-domain-tls into this
|
||||
# Wildcard + apex for the cluster's APP_DOMAIN — covers web (apex), api.
|
||||
# (and admin. when it's exposed; prod's restic host is two labels down and has
|
||||
# its own gw-public cert). cert-manager writes app-domain-tls into this
|
||||
# namespace (envoy-system) for the Gateway(s) to terminate with.
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
|
||||
@@ -0,0 +1,17 @@
|
||||
---
|
||||
# yaml-language-server: $schema=https://k8s-schemas.home-operations.com/cert-manager.io/certificate_v1.json
|
||||
# Cert for the public restic hostname (${GW_HOST}). rest.htz-fsn1. is two
|
||||
# labels below APP_DOMAIN, so the shared *.APP_DOMAIN wildcard doesn't cover
|
||||
# it; same DNS-01 pipeline as gw-internal. Lands in envoy-system
|
||||
# (targetNamespace-forced) beside the Gateway.
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: gw-public
|
||||
spec:
|
||||
secretName: gw-public-tls
|
||||
issuerRef:
|
||||
name: letsencrypt-production
|
||||
kind: ClusterIssuer
|
||||
dnsNames:
|
||||
- "${GW_HOST}"
|
||||
@@ -2,8 +2,9 @@
|
||||
# The michael (restic) Gateway: HTTPS-only, scoped to ${GW_HOST}. Shares the
|
||||
# `envoy` GatewayClass but attaches its own EnvoyProxy via
|
||||
# infrastructure.parametersRef (Envoy Gateway creates one proxy fleet per
|
||||
# Gateway). TLS terminates with the shared wildcard cert (*.APP_DOMAIN covers
|
||||
# gw.); no :80 listener — restic clients speak HTTPS only.
|
||||
# Gateway). TLS terminates with the gw-public cert (certificate.yaml — the
|
||||
# *.APP_DOMAIN wildcard doesn't reach rest.htz-fsn1.); no :80 listener —
|
||||
# restic clients speak HTTPS only.
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: Gateway
|
||||
metadata:
|
||||
@@ -27,7 +28,7 @@ spec:
|
||||
mode: Terminate
|
||||
certificateRefs:
|
||||
- kind: Secret
|
||||
name: app-domain-tls
|
||||
name: gw-public-tls
|
||||
# Internal twin (${GW_INT_VIP}): same envoy fleet, NetBird-zone hostname,
|
||||
# own DNS-01 cert (gw-internal.yaml at the overlay root).
|
||||
- name: https-internal
|
||||
|
||||
@@ -2,6 +2,7 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./certificate.yaml
|
||||
- ./envoyproxy.yaml
|
||||
- ./gateway.yaml
|
||||
- ./policies.yaml
|
||||
|
||||
@@ -18,9 +18,10 @@ data:
|
||||
METRICS_ENV_LABEL: prod
|
||||
|
||||
# Per-service ingress hostnames. web (apex; /api routes to yucca-api) on the
|
||||
# app gateway; gw. (michael, restic) on the dedicated gw-proxy gateway.
|
||||
# app gateway; rest.htz-fsn1. (michael, restic) on the dedicated gw-proxy
|
||||
# gateway (own cert — outside the *.APP_DOMAIN wildcard).
|
||||
APP_DOMAIN: backups.futo.cloud
|
||||
GW_HOST: gw.backups.futo.cloud
|
||||
GW_HOST: rest.htz-fsn1.backups.futo.cloud
|
||||
|
||||
# Spice RGW (Ceph S3): round-robin DNS across all 48 nodes' fabric VLAN-120
|
||||
# IPs (prod/global/dns), reached over the FABRIC — the spine routes
|
||||
|
||||
@@ -26,7 +26,7 @@ records = {
|
||||
values = ["69.48.224.5"]
|
||||
comment = "Yucca prod web/api gateway (tf/deployment/prod/global/dns)"
|
||||
}
|
||||
"gw.backups.futo.cloud" = {
|
||||
"rest.htz-fsn1.backups.futo.cloud" = {
|
||||
type = "A"
|
||||
values = ["69.48.224.6"]
|
||||
comment = "Yucca prod restic gateway - michael (tf/deployment/prod/global/dns)"
|
||||
|
||||
Reference in New Issue
Block a user