Skip to content

feat(cloudflared): permit the Uptime Kuma backend for kuma.pragalva.me - #80

Merged
PragalvaXFREZ merged 1 commit into
mainfrom
feat/cloudflared-kuma-route
Sep 6, 2026
Merged

PragalvaXFREZ merged 1 commit into
mainfrom
feat/cloudflared-kuma-route

Conversation

@PragalvaXFREZ

Copy link
Copy Markdown
Owner

What

  • CiliumNetworkPolicy for the connectors gains an egress entry to uptime/uptime-kuma on TCP 3001, matching the Grafana and Hubble backend entries. Gateway hairpin traffic reaches the backend under the connector identity, so the backend must be allowed explicitly.
  • README: hostname table, trust boundary, verification step for Access and the WebSocket.

Kuma's own policy already accepts inbound from the ingress identity (#73), so no change there.

Manual steps in Cloudflare (remotely managed tunnel, as documented)

  1. Zero Trust, Networks, Tunnels, devata, Public Hostname, add kuma.pragalva.me: service HTTPS, URL cilium-gateway-lan-gateway.gateway-system.svc.cluster.local:443, TLS Origin Server Name kuma.lab.pragalva.me, HTTP Host Header kuma.lab.pragalva.me. Cloudflare creates the proxied CNAME.
  2. Zero Trust, Access, Applications, add a self-hosted app for kuma.pragalva.me with an allow policy for the operator email. Kuma's login page and socket must not be on the open internet.

Validation

  • kubeconform -strict and scripts/check-docs.py pass.

Allow connector egress to uptime/uptime-kuma on TCP 3001 so the
remotely managed tunnel route can reach it through the LAN Gateway.
Document the new public hostname and its Access requirement.

Signed-off-by: Pragalva Sapkota <sapkotapragalva@gmail.com>
@PragalvaXFREZ
PragalvaXFREZ merged commit 18bf18f into main Sep 6, 2026
3 checks passed
@PragalvaXFREZ
PragalvaXFREZ deleted the feat/cloudflared-kuma-route branch September 6, 2026 14:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant