apiVersion: traefik.containo.us/v1alpha1 kind: IngressRoute metadata: name: vault-ingress annotations: cert-manager.io/cluster-issuer: letsencrypt-production spec: entryPoints: - websecure routes: - match: Host(`vault.internal.durp.info`) middlewares: - name: whitelist namespace: traefik kind: Rule services: - name: vault port: 8200 scheme: http tls: secretName: vault-tls --- apiVersion: cert-manager.io/v1 kind: Certificate metadata: name: vault-tls spec: secretName: vault-tls issuerRef: name: letsencrypt-production kind: ClusterIssuer commonName: "vault.internal.durp.info" dnsNames: - "vault.internal.durp.info"