- Add initContainer to set proper file permissions (chown 1000:0) - Add fsGroup: 0 for root group permissions - Add ServersTransport for Traefik backend HTTPS with insecureSkipVerify - Add traefik.ingress.kubernetes.io/service.serversscheme annotation
28 lines
690 B
YAML
28 lines
690 B
YAML
apiVersion: networking.k8s.io/v1
|
|
kind: Ingress
|
|
metadata:
|
|
name: crafty-ingress
|
|
namespace: crafty
|
|
annotations:
|
|
cert-manager.io/cluster-issuer: "letsencrypt-prod"
|
|
traefik.ingress.kubernetes.io/router.tls: "true"
|
|
traefik.ingress.kubernetes.io/service.serversscheme: "https"
|
|
traefik.ingress.kubernetes.io/service.serverstransport: "crafty-insecure@kubernetescrd"
|
|
spec:
|
|
ingressClassName: traefik
|
|
tls:
|
|
- hosts:
|
|
- crafty0213.kro.kr
|
|
secretName: crafty-tls
|
|
rules:
|
|
- host: crafty0213.kro.kr
|
|
http:
|
|
paths:
|
|
- path: /
|
|
pathType: Prefix
|
|
backend:
|
|
service:
|
|
name: crafty
|
|
port:
|
|
number: 8443
|