123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120 |
- apiVersion: helm.cattle.io/v1
- kind: HelmChartConfig
- metadata:
- name: traefik
- namespace: kube-system
- spec:
- valuesContent: |-
- additionalArguments:
- - "--entrypoints.websecure.proxyProtocol.trustedIPs=127.0.0.1/32,172.16.69.0/24"
- - "--entrypoints.web.http.redirections.entryPoint.to=:443"
- - "--entrypoints.web.http.redirections.entrypoint.scheme=https"
-
- - "--certificatesresolvers.letsencrypt.acme.email=joshbicking@comcast.net"
- - "--certificatesresolvers.letsencrypt.acme.storage=/data/acme.json"
- - "--certificatesresolvers.letsencrypt.acme.dnschallenge.provider=cloudflare"
- - "--certificatesresolvers.letsencrypt.acme.dnschallenge.resolvers=1.1.1.1:53,8.8.8.8:53"
- - "--entrypoints.websecure.http.tls.certResolver=letsencrypt"
-
- - "--entrypoints.websecure.http.tls.domains[0].main=jibby.org"
- - "--entrypoints.websecure.http.tls.domains[0].sans=*.jibby.org"
-
- - "--entrypoints.websecure.http.tls.domains[1].main=lan.jibby.org"
- - "--entrypoints.websecure.http.tls.domains[1].sans=*.lan.jibby.org"
-
- - "--providers.file.directory=/config"
-
-
-
-
- volumes:
- - name: traefik-config
- mountPath: "/config"
- type: configMap
- env:
- - name: CLOUDFLARE_EMAIL
- valueFrom:
- secretKeyRef:
- name: cloudflare-secrets
- key: email
- optional: false
- - name: CLOUDFLARE_API_KEY
- valueFrom:
- secretKeyRef:
- name: cloudflare-secrets
- key: api-key
- optional: false
-
- persistence:
- enabled: true
- storageClass: ceph-block-ssd
- metrics:
- prometheus:
- addServicesLabels: true
- logs:
- access:
- enabled: true
- ingressRoute:
- dashboard:
- enabled: false
-
-
-
-
-
-
-
-
-
-
- podSecurityContext:
- fsGroup: 65532
- deployment:
- initContainers:
-
-
- - name: volume-permissions
- image: busybox:latest
- command: ["sh", "-c", "touch /data/acme.json; chmod -v 600 /data/acme.json"]
- securityContext:
- runAsNonRoot: true
- runAsGroup: 65532
- runAsUser: 65532
- volumeMounts:
- - name: data
- mountPath: /data
-
-
-
- service:
- spec:
-
- externalTrafficPolicy: Local
- providers:
- kubernetesCRD:
-
- allowCrossNamespace: true
-
- affinity:
- nodeAffinity:
- requiredDuringSchedulingIgnoredDuringExecution:
- nodeSelectorTerms:
- - matchExpressions:
- - key: cluster-ingress
- operator: In
- values:
- - "true"
|