Compare commits
2 Commits
04b9fdbced
...
330aad6a4c
| Author | SHA1 | Date | |
|---|---|---|---|
|
330aad6a4c
|
|||
| b4919afab0 |
@@ -1,17 +0,0 @@
|
|||||||
apiVersion: "cilium.io/v2alpha1"
|
|
||||||
kind: CiliumL2AnnouncementPolicy
|
|
||||||
metadata:
|
|
||||||
name: node-gateway-l2-policy
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
labels:
|
|
||||||
app.kubernetes.io/name: node-gateway-l2-policy
|
|
||||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
|
||||||
app.kubernetes.io/part-of: {{ .Release.Name }}
|
|
||||||
spec:
|
|
||||||
nodeSelector:
|
|
||||||
matchLabels:
|
|
||||||
kubernetes.io/hostname: talos-ix7-xku
|
|
||||||
interfaces:
|
|
||||||
- enp6s0
|
|
||||||
externalIPs: true
|
|
||||||
loadBalancerIPs: true
|
|
||||||
@@ -11,8 +11,6 @@ spec:
|
|||||||
blocks:
|
blocks:
|
||||||
- start: "10.232.1.21"
|
- start: "10.232.1.21"
|
||||||
stop: "10.232.1.23"
|
stop: "10.232.1.23"
|
||||||
- start: "10.232.1.100"
|
|
||||||
stop: "10.232.1.200"
|
|
||||||
|
|
||||||
---
|
---
|
||||||
apiVersion: cilium.io/v2
|
apiVersion: cilium.io/v2
|
||||||
|
|||||||
@@ -1,46 +1,45 @@
|
|||||||
apiVersion: gateway.networking.k8s.io/v1
|
# apiVersion: gateway.networking.k8s.io/v1
|
||||||
kind: Gateway
|
# kind: Gateway
|
||||||
metadata:
|
# metadata:
|
||||||
name: cilium-tls-gateway
|
# name: cilium-tls-gateway
|
||||||
namespace: {{ .Release.Namespace }}
|
# namespace: {{ .Release.Namespace }}
|
||||||
labels:
|
# labels:
|
||||||
app.kubernetes.io/name: cilium-tls-gateway
|
# app.kubernetes.io/name: cilium-tls-gateway
|
||||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
# app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
app.kubernetes.io/part-of: {{ .Release.Name }}
|
# app.kubernetes.io/part-of: {{ .Release.Name }}
|
||||||
annotations:
|
# annotations:
|
||||||
cert-manager.io/cluster-issuer: letsencrypt-issuer
|
# cert-manager.io/cluster-issuer: letsencrypt-issuer
|
||||||
io.cilium/lb-ipam-ips: "10.232.1.100"
|
# spec:
|
||||||
spec:
|
# addresses:
|
||||||
addresses:
|
# - type: IPAddress
|
||||||
- type: IPAddress
|
# value: 10.232.1.23
|
||||||
value: 10.232.1.100
|
# gatewayClassName: cilium
|
||||||
gatewayClassName: cilium
|
# listeners:
|
||||||
listeners:
|
# - allowedRoutes:
|
||||||
- allowedRoutes:
|
# namespaces:
|
||||||
namespaces:
|
# from: All
|
||||||
from: All
|
# hostname: '*.alexlebens.net'
|
||||||
hostname: '*.alexlebens.net'
|
# name: https
|
||||||
name: https
|
# port: 443
|
||||||
port: 443
|
# protocol: HTTPS
|
||||||
protocol: HTTPS
|
# tls:
|
||||||
tls:
|
# certificateRefs:
|
||||||
certificateRefs:
|
# - group: ''
|
||||||
- group: ''
|
# kind: Secret
|
||||||
kind: Secret
|
# name: https-gateway-cert
|
||||||
name: https-gateway-cert
|
# namespace: kube-system
|
||||||
namespace: kube-system
|
# mode: Terminate
|
||||||
mode: Terminate
|
# - allowedRoutes:
|
||||||
- allowedRoutes:
|
# namespaces:
|
||||||
namespaces:
|
# from: All
|
||||||
from: All
|
# hostname: 'alexlebens.net'
|
||||||
hostname: 'alexlebens.net'
|
# name: https-domain
|
||||||
name: https-domain
|
# port: 443
|
||||||
port: 443
|
# protocol: HTTPS
|
||||||
protocol: HTTPS
|
# tls:
|
||||||
tls:
|
# certificateRefs:
|
||||||
certificateRefs:
|
# - group: ''
|
||||||
- group: ''
|
# kind: Secret
|
||||||
kind: Secret
|
# name: https-gateway-cert
|
||||||
name: https-gateway-cert
|
# namespace: kube-system
|
||||||
namespace: kube-system
|
# mode: Terminate
|
||||||
mode: Terminate
|
|
||||||
|
|||||||
@@ -26,7 +26,7 @@ cilium:
|
|||||||
- SYS_ADMIN
|
- SYS_ADMIN
|
||||||
- SYS_RESOURCE
|
- SYS_RESOURCE
|
||||||
l2announcements:
|
l2announcements:
|
||||||
enabled: true
|
enabled: false
|
||||||
bgpControlPlane:
|
bgpControlPlane:
|
||||||
enabled: false
|
enabled: false
|
||||||
secretsNamespace:
|
secretsNamespace:
|
||||||
@@ -38,7 +38,6 @@ cilium:
|
|||||||
bpf:
|
bpf:
|
||||||
hostLegacyRouting: true
|
hostLegacyRouting: true
|
||||||
devices: end0 enp6s0
|
devices: end0 enp6s0
|
||||||
enableK8sEndpointSlice: true
|
|
||||||
ciliumEndpointSlice:
|
ciliumEndpointSlice:
|
||||||
enabled: true
|
enabled: true
|
||||||
ingressController:
|
ingressController:
|
||||||
|
|||||||
Reference in New Issue
Block a user