feat(gateway): route kuma.lab.pragalva.me to Uptime Kuma - #76
Merged
Merged
Conversation
Add the hostname to the shared LAN certificate and the HTTP redirect, add an HTTPS route to uptime/uptime-kuma:3001, and grant the cross-namespace reference. cert-manager reissues through Cloudflare DNS-01; the DNS-only A record to 192.168.1.244 is created by hand. Signed-off-by: Pragalva Sapkota <sapkotapragalva@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Recreated after #73 merged; the original stacked PR was closed when its base branch was deleted.
What
kuma.lab.pragalva.meadded to thelan-services-tlsCertificate SANs. cert-manager reissues via the existing Cloudflare DNS-01 ClusterIssuer.kumaon thehttpslistener touptime/uptime-kuma:3001.allow-kuma-routein namespaceuptime, same shape as the Grafana and Hubble grants.Ordering
The ReferenceGrant lives in namespace
uptime, which #73 creates. Merge #73 first or the grant fails to sync until the namespace exists.Manual step
Create a DNS-only
Arecordkuma.lab.pragalva.meto192.168.1.244in Cloudflare, matching the Grafana and Hubble records. No Cloudflare Tunnel hostname is added; this stays LAN and NetBird only.Validation
kubeconform -strictpasses on the gateway directory against the Gateway API catalog schemas.python3 scripts/check-docs.pypasses.After merge
kubectl -n gateway-system get certificate lan-services-tls -o jsonpath='{.status.conditions[?(@.type=="Ready")].status}' kubectl -n gateway-system get httproute kuma curl -I http://kuma.lab.pragalva.me curl -I https://kuma.lab.pragalva.meThen open the dashboard in a browser and confirm heartbeats update live. That proves the WebSocket upgrade passes through Cilium's Envoy.