All checks were successful
The unified image uses nginx on port 80 as the entrypoint, which reverse-proxies to the Go backend on 127.0.0.1:8080 internally. K8s was exposing 8080 directly, bypassing nginx entirely. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
47 lines
1.4 KiB
YAML
47 lines
1.4 KiB
YAML
# k8s/ingress.yaml
|
|
# ============================================
|
|
# Switchboard Core - Ingress
|
|
# ============================================
|
|
# Path-based routing on a single domain:
|
|
# switchboard.DOMAIN/ → production
|
|
# switchboard.DOMAIN/test/ → test (main branch)
|
|
# switchboard.DOMAIN/dev/ → dev (PR branches)
|
|
#
|
|
# Each environment deploys its own Ingress resource.
|
|
# Traefik merges rules for the same host automatically.
|
|
# Longer path prefixes take priority (Traefik default).
|
|
#
|
|
# BASE_PATH is empty for prod, "/test" or "/dev" for others.
|
|
# Backend handles BASE_PATH via r.Group(cfg.BasePath).
|
|
# Single unified image serves both API and static assets.
|
|
# ============================================
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: Ingress
|
|
metadata:
|
|
name: switchboard${DEPLOY_SUFFIX}
|
|
namespace: ${NAMESPACE}
|
|
annotations:
|
|
cert-manager.io/cluster-issuer: "${CERT_ISSUER}"
|
|
traefik.ingress.kubernetes.io/router.entrypoints: websecure
|
|
labels:
|
|
app: switchboard
|
|
env: ${ENVIRONMENT}
|
|
spec:
|
|
ingressClassName: "traefik"
|
|
tls:
|
|
- hosts:
|
|
- ${DEPLOY_HOST}
|
|
secretName: switchboard-tls
|
|
rules:
|
|
- host: "${DEPLOY_HOST}"
|
|
http:
|
|
paths:
|
|
# All traffic → switchboard (unified image)
|
|
- path: ${BASE_PATH}/
|
|
pathType: Prefix
|
|
backend:
|
|
service:
|
|
name: switchboard${DEPLOY_SUFFIX}
|
|
port:
|
|
number: 80
|