Files
homelab/internalproxy/templates/heimdall.yaml
2023-01-01 18:35:14 -06:00

69 lines
1.7 KiB
YAML

apiVersion: v1
kind: Service
metadata:
name: heimdall
spec:
ports:
- name: app
port: 8443
protocol: TCP
targetPort: 8443
clusterIP: None
type: ClusterIP
---
apiVersion: v1
kind: Endpoints
metadata:
name: heimdall
subsets:
- addresses:
- ip: 192.168.20.253
ports:
- name: app
port: 8443
protocol: TCP
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: heimdall-ingress
annotations:
kubernetes.io/ingress.class: nginx
cert-manager.io/cluster-issuer: letsencrypt-production
nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
nginx.ingress.kubernetes.io/auth-url: |-
http://ak-outpost-authentik-embedded-outpost.authentik.svc.cluster.local:9000/outpost.goauthentik.io/auth/nginx
nginx.ingress.kubernetes.io/auth-signin: |-
https://heimdall.durp.info/outpost.goauthentik.io/start?rd=$escaped_request_uri
nginx.ingress.kubernetes.io/auth-response-headers: |-
Set-Cookie,X-authentik-username,X-authentik-groups,X-authentik-email,X-authentik-name,X-authentik-uid
nginx.ingress.kubernetes.io/auth-snippet: |
proxy_set_header X-Forwarded-Host $http_host;
spec:
rules:
- host: heimdall.durp.info
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: heimdall
port:
number: 8443
- path: /outpost.goauthentik.io
pathType: Prefix
backend:
service:
name: ak-outpost-authentik-embedded-outpost
port:
number: 9000
tls:
- hosts:
- heimdall.durp.info
secretName: heimdall-tls