From d902134a17391f42033a08eea7f9829c7d658490 Mon Sep 17 00:00:00 2001 From: Pragalva Sapkota Date: Sun, 6 Sep 2026 14:12:45 +0545 Subject: [PATCH] feat(gateway): route kuma.lab.pragalva.me to Uptime Kuma Add the hostname to the shared LAN certificate and the HTTP redirect, add an HTTPS route to uptime/uptime-kuma:3001, and grant the cross-namespace reference. cert-manager reissues through Cloudflare DNS-01; the DNS-only A record to 192.168.1.244 is created by hand. Signed-off-by: Pragalva Sapkota --- kubernetes/infra/networking/gateway/README.md | 10 ++++--- .../infra/networking/gateway/certificate.yaml | 1 + .../networking/gateway/reference-grants.yaml | 15 +++++++++++ .../infra/networking/gateway/routes.yaml | 27 +++++++++++++++++++ 4 files changed, 49 insertions(+), 4 deletions(-) diff --git a/kubernetes/infra/networking/gateway/README.md b/kubernetes/infra/networking/gateway/README.md index fa4dbc5..302fbee 100644 --- a/kubernetes/infra/networking/gateway/README.md +++ b/kubernetes/infra/networking/gateway/README.md @@ -1,10 +1,10 @@ # LAN gateway -The Cilium Gateway API terminates public ACME certificates for Grafana and Hubble on the LAN. MetalLB assigns `192.168.1.244` to the generated LoadBalancer Service. DNS-only `A` records for `grafana.lab.pragalva.me` and `hubble.lab.pragalva.me` point to that address. +The Cilium Gateway API terminates public ACME certificates for Grafana, Hubble, and Uptime Kuma on the LAN. MetalLB assigns `192.168.1.244` to the generated LoadBalancer Service. DNS-only `A` records for `grafana.lab.pragalva.me`, `hubble.lab.pragalva.me`, and `kuma.lab.pragalva.me` point to that address. The Gateway uses the `metallb.universe.tf` annotation prefix required by the installed MetalLB `v0.14.5` controller. -The Gateway routes to the existing `kps-grafana` and `hubble-ui` Services through explicit cross-namespace grants. Their LoadBalancer types and direct addresses stay unchanged as the compatibility and rollback path. +The Gateway routes to the `kps-grafana`, `hubble-ui`, and `uptime-kuma` Services through explicit cross-namespace grants. The Grafana and Hubble LoadBalancer types and direct addresses stay unchanged as the compatibility and rollback path. Uptime Kuma is ClusterIP only, so the Gateway is its sole LAN entry; its own README covers the port-forward fallback. ## Verification @@ -12,13 +12,15 @@ The Gateway routes to the existing `kps-grafana` and `hubble-ui` Services throug kubectl -n gateway-system get gateway,httproute,certificate kubectl -n monitoring get referencegrant allow-grafana-route kubectl -n kube-system get referencegrant allow-hubble-route +kubectl -n uptime get referencegrant allow-kuma-route curl -I http://grafana.lab.pragalva.me curl -I https://grafana.lab.pragalva.me curl -I https://hubble.lab.pragalva.me +curl -I https://kuma.lab.pragalva.me ``` -The HTTP request must redirect to HTTPS, both HTTPS requests must validate without `--insecure`, and all route conditions must be `Accepted=True` and `ResolvedRefs=True`. +The HTTP request must redirect to HTTPS, every HTTPS request must validate without `--insecure`, and all route conditions must be `Accepted=True` and `ResolvedRefs=True`. The Uptime Kuma dashboard uses a WebSocket; the browser must show live heartbeat updates through the Gateway, not only the initial page. ## Rollback -Revert the Gateway manifests and `gatewayAPI.enabled` value through Git. Remove the two DNS records after Argo reconciles the revert. Grafana remains reachable at `http://192.168.1.242` and Hubble remains reachable at `http://192.168.1.243` throughout the migration. +Revert the Gateway manifests and `gatewayAPI.enabled` value through Git. Remove the DNS records after Argo reconciles the revert. Grafana remains reachable at `http://192.168.1.242` and Hubble remains reachable at `http://192.168.1.243` throughout the migration. diff --git a/kubernetes/infra/networking/gateway/certificate.yaml b/kubernetes/infra/networking/gateway/certificate.yaml index 1e5394f..493a982 100644 --- a/kubernetes/infra/networking/gateway/certificate.yaml +++ b/kubernetes/infra/networking/gateway/certificate.yaml @@ -13,6 +13,7 @@ spec: dnsNames: - grafana.lab.pragalva.me - hubble.lab.pragalva.me + - kuma.lab.pragalva.me privateKey: algorithm: ECDSA size: 256 diff --git a/kubernetes/infra/networking/gateway/reference-grants.yaml b/kubernetes/infra/networking/gateway/reference-grants.yaml index 77598b0..49d5aee 100644 --- a/kubernetes/infra/networking/gateway/reference-grants.yaml +++ b/kubernetes/infra/networking/gateway/reference-grants.yaml @@ -27,3 +27,18 @@ spec: - group: "" kind: Service name: hubble-ui +--- +apiVersion: gateway.networking.k8s.io/v1beta1 +kind: ReferenceGrant +metadata: + name: allow-kuma-route + namespace: uptime +spec: + from: + - group: gateway.networking.k8s.io + kind: HTTPRoute + namespace: gateway-system + to: + - group: "" + kind: Service + name: uptime-kuma diff --git a/kubernetes/infra/networking/gateway/routes.yaml b/kubernetes/infra/networking/gateway/routes.yaml index 901d1c3..a11a4db 100644 --- a/kubernetes/infra/networking/gateway/routes.yaml +++ b/kubernetes/infra/networking/gateway/routes.yaml @@ -12,6 +12,7 @@ spec: hostnames: - grafana.lab.pragalva.me - hubble.lab.pragalva.me + - kuma.lab.pragalva.me rules: - matches: - path: @@ -74,3 +75,29 @@ spec: - path: type: PathPrefix value: / +--- +apiVersion: gateway.networking.k8s.io/v1 +kind: HTTPRoute +metadata: + name: kuma + namespace: gateway-system +spec: + parentRefs: + - group: gateway.networking.k8s.io + kind: Gateway + name: lan-gateway + sectionName: https + hostnames: + - kuma.lab.pragalva.me + rules: + - backendRefs: + - group: "" + kind: Service + name: uptime-kuma + namespace: uptime + port: 3001 + weight: 1 + matches: + - path: + type: PathPrefix + value: /