Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 6 additions & 4 deletions kubernetes/infra/networking/gateway/README.md
Original file line number Diff line number Diff line change
@@ -1,24 +1,26 @@
# LAN gateway

The Cilium Gateway API terminates public ACME certificates for Grafana and Hubble on the LAN. MetalLB assigns `192.168.1.244` to the generated LoadBalancer Service. DNS-only `A` records for `grafana.lab.pragalva.me` and `hubble.lab.pragalva.me` point to that address.
The Cilium Gateway API terminates public ACME certificates for Grafana, Hubble, and Uptime Kuma on the LAN. MetalLB assigns `192.168.1.244` to the generated LoadBalancer Service. DNS-only `A` records for `grafana.lab.pragalva.me`, `hubble.lab.pragalva.me`, and `kuma.lab.pragalva.me` point to that address.

The Gateway uses the `metallb.universe.tf` annotation prefix required by the installed MetalLB `v0.14.5` controller.

The Gateway routes to the existing `kps-grafana` and `hubble-ui` Services through explicit cross-namespace grants. Their LoadBalancer types and direct addresses stay unchanged as the compatibility and rollback path.
The Gateway routes to the `kps-grafana`, `hubble-ui`, and `uptime-kuma` Services through explicit cross-namespace grants. The Grafana and Hubble LoadBalancer types and direct addresses stay unchanged as the compatibility and rollback path. Uptime Kuma is ClusterIP only, so the Gateway is its sole LAN entry; its own README covers the port-forward fallback.

## Verification

```bash
kubectl -n gateway-system get gateway,httproute,certificate
kubectl -n monitoring get referencegrant allow-grafana-route
kubectl -n kube-system get referencegrant allow-hubble-route
kubectl -n uptime get referencegrant allow-kuma-route
curl -I http://grafana.lab.pragalva.me
curl -I https://grafana.lab.pragalva.me
curl -I https://hubble.lab.pragalva.me
curl -I https://kuma.lab.pragalva.me
```

The HTTP request must redirect to HTTPS, both HTTPS requests must validate without `--insecure`, and all route conditions must be `Accepted=True` and `ResolvedRefs=True`.
The HTTP request must redirect to HTTPS, every HTTPS request must validate without `--insecure`, and all route conditions must be `Accepted=True` and `ResolvedRefs=True`. The Uptime Kuma dashboard uses a WebSocket; the browser must show live heartbeat updates through the Gateway, not only the initial page.

## Rollback

Revert the Gateway manifests and `gatewayAPI.enabled` value through Git. Remove the two DNS records after Argo reconciles the revert. Grafana remains reachable at `http://192.168.1.242` and Hubble remains reachable at `http://192.168.1.243` throughout the migration.
Revert the Gateway manifests and `gatewayAPI.enabled` value through Git. Remove the DNS records after Argo reconciles the revert. Grafana remains reachable at `http://192.168.1.242` and Hubble remains reachable at `http://192.168.1.243` throughout the migration.
1 change: 1 addition & 0 deletions kubernetes/infra/networking/gateway/certificate.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ spec:
dnsNames:
- grafana.lab.pragalva.me
- hubble.lab.pragalva.me
- kuma.lab.pragalva.me
privateKey:
algorithm: ECDSA
size: 256
Expand Down
15 changes: 15 additions & 0 deletions kubernetes/infra/networking/gateway/reference-grants.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -27,3 +27,18 @@ spec:
- group: ""
kind: Service
name: hubble-ui
---
apiVersion: gateway.networking.k8s.io/v1beta1
kind: ReferenceGrant
metadata:
name: allow-kuma-route
namespace: uptime
spec:
from:
- group: gateway.networking.k8s.io
kind: HTTPRoute
namespace: gateway-system
to:
- group: ""
kind: Service
name: uptime-kuma
27 changes: 27 additions & 0 deletions kubernetes/infra/networking/gateway/routes.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@ spec:
hostnames:
- grafana.lab.pragalva.me
- hubble.lab.pragalva.me
- kuma.lab.pragalva.me
rules:
- matches:
- path:
Expand Down Expand Up @@ -74,3 +75,29 @@ spec:
- path:
type: PathPrefix
value: /
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: kuma
namespace: gateway-system
spec:
parentRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: lan-gateway
sectionName: https
hostnames:
- kuma.lab.pragalva.me
rules:
- backendRefs:
- group: ""
kind: Service
name: uptime-kuma
namespace: uptime
port: 3001
weight: 1
matches:
- path:
type: PathPrefix
value: /
Loading