All checks were successful
Co-authored-by: Jeffrey Smith <jasafpro@gmail.com> Co-committed-by: Jeffrey Smith <jasafpro@gmail.com>
47 lines
1.4 KiB
YAML
47 lines
1.4 KiB
YAML
# k8s/ingress.yaml
|
|
# ============================================
|
|
# Armature Core - Ingress
|
|
# ============================================
|
|
# Path-based routing on a single domain:
|
|
# armature.DOMAIN/ → production
|
|
# armature.DOMAIN/test/ → test (main branch)
|
|
# armature.DOMAIN/dev/ → dev (PR branches)
|
|
#
|
|
# Each environment deploys its own Ingress resource.
|
|
# Traefik merges rules for the same host automatically.
|
|
# Longer path prefixes take priority (Traefik default).
|
|
#
|
|
# BASE_PATH is empty for prod, "/test" or "/dev" for others.
|
|
# Backend handles BASE_PATH via r.Group(cfg.BasePath).
|
|
# Single unified image serves both API and static assets.
|
|
# ============================================
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: Ingress
|
|
metadata:
|
|
name: armature${DEPLOY_SUFFIX}
|
|
namespace: ${NAMESPACE}
|
|
annotations:
|
|
cert-manager.io/cluster-issuer: "${CERT_ISSUER}"
|
|
traefik.ingress.kubernetes.io/router.entrypoints: websecure
|
|
labels:
|
|
app: armature
|
|
env: ${ENVIRONMENT}
|
|
spec:
|
|
ingressClassName: "traefik"
|
|
tls:
|
|
- hosts:
|
|
- ${DEPLOY_HOST}
|
|
secretName: armature-tls
|
|
rules:
|
|
- host: "${DEPLOY_HOST}"
|
|
http:
|
|
paths:
|
|
# All traffic → armature (unified image)
|
|
- path: ${BASE_PATH}/
|
|
pathType: Prefix
|
|
backend:
|
|
service:
|
|
name: armature${DEPLOY_SUFFIX}
|
|
port:
|
|
number: 80
|