Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions charts/core/templates/controller-ingress.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{{- if .Values.controller.enabled }}
{{- if .Values.controller.ingress.enabled }}
{{- if and .Values.controller.ingress.enabled (not (.Values.controller.ingress.traefikIngressRoute)) }}
{{- if (semverCompare ">=1.19-0" (substr 1 -1 .Capabilities.KubeVersion.GitVersion)) }}
apiVersion: networking.k8s.io/v1
kind: Ingress
Expand Down Expand Up @@ -70,7 +70,7 @@ spec:
servicePort: 10443
{{- end }}
{{- end }}
{{- if .Values.controller.federation.mastersvc.ingress.enabled }}
{{- if and .Values.controller.federation.mastersvc.ingress.enabled (not (.Values.controller.federation.mastersvc.ingress.traefikIngressRoute)) }}
{{- if (semverCompare ">=1.19-0" (substr 1 -1 .Capabilities.KubeVersion.GitVersion)) }}
---
apiVersion: networking.k8s.io/v1
Expand Down Expand Up @@ -143,7 +143,7 @@ spec:
servicePort: 11443
{{- end }}
{{- end }}
{{- if .Values.controller.federation.managedsvc.ingress.enabled }}
{{- if and .Values.controller.federation.managedsvc.ingress.enabled (not (.Values.controller.federation.managedsvc.ingress.traefikIngressRoute)) }}
{{- if (semverCompare ">=1.19-0" (substr 1 -1 .Capabilities.KubeVersion.GitVersion)) }}
---
apiVersion: networking.k8s.io/v1
Expand Down
102 changes: 102 additions & 0 deletions charts/core/templates/controller-traefik-ingressroute.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,102 @@
{{- if .Values.controller.enabled }}
---
{{- if and .Values.controller.ingress.enabled .Values.controller.ingress.traefikIngressRoute }}
apiVersion: traefik.containo.us/v1alpha1
kind: IngressRoute
metadata:
name: neuvector-restapi-ingress
namespace: {{ .Release.Namespace }}
{{- with .Values.controller.ingress.annotations }}
annotations:
{{ toYaml . | indent 4 }}
{{- end }}
labels:
chart: {{ template "neuvector.chart" . }}
release: {{ .Release.Name }}
heritage: {{ .Release.Service }}
spec:
entryPoints:
- websecure
routes:
- match: Host(`{{ .Values.controller.ingress.host }}`) && PathPrefix(`{{ .Values.controller.ingress.path }}`)
kind: Rule
services:
- name: neuvector-svc-controller-api
passHostHeader: true
port: 10443
scheme: https
{{- if .Values.controller.ingress.tls }}
tls:
{{- if .Values.controller.ingress.secretName }}
secretName: {{ .Values.controller.ingress.secretName }}
{{- end }}
{{- end }}
{{- end }}
---
{{- if and .Values.controller.federation.mastersvc.ingress.enabled .Values.controller.federation.mastersvc.ingress.traefikIngressRoute }}
apiVersion: traefik.containo.us/v1alpha1
kind: IngressRoute
metadata:
name: neuvector-mastersvc-ingress
namespace: {{ .Release.Namespace }}
{{- with .Values.controller.federation.mastersvc.ingress.annotations }}
annotations:
{{ toYaml . | indent 4 }}
{{- end }}
labels:
chart: {{ template "neuvector.chart" . }}
release: {{ .Release.Name }}
heritage: {{ .Release.Service }}
spec:
entryPoints:
- websecure
routes:
- match: Host(`{{ .Values.controller.federation.mastersvc.ingress.host }}`) && PathPrefix(`{{ .Values.controller.federation.mastersvc.ingress.path }}`)
kind: Rule
services:
- name: neuvector-svc-controller-fed-master
passHostHeader: true
port: 11443
scheme: https
{{- if .Values.controller.federation.mastersvc.ingress.tls }}
tls:
{{- if .Values.controller.federation.mastersvc.ingress.secretName }}
secretName: {{ .Values.controller.federation.mastersvc.ingress.secretName }}
{{- end }}
{{- end }}
{{- end }}
---
{{- if and .Values.controller.federation.managedsvc.ingress.enabled .Values.controller.federation.managedsvc.ingress.traefikIngressRoute }}
apiVersion: traefik.containo.us/v1alpha1
kind: IngressRoute
metadata:
name: neuvector-managedsvc-ingress
namespace: {{ .Release.Namespace }}
{{- with .Values.controller.federation.managedsvc.ingress.annotations }}
annotations:
{{ toYaml . | indent 4 }}
{{- end }}
labels:
chart: {{ template "neuvector.chart" . }}
release: {{ .Release.Name }}
heritage: {{ .Release.Service }}
spec:
entryPoints:
- websecure
routes:
- match: Host(`{{ .Values.controller.federation.managedsvc.ingress.host }}`) && PathPrefix(`{{ .Values.controller.federation.managedsvc.ingress.path }}`)
kind: Rule
services:
- name: neuvector-svc-controller-fed-managed
passHostHeader: true
port: 10443
scheme: https
{{- if .Values.controller.federation.managedsvc.ingress.tls }}
tls:
{{- if .Values.controller.federation.managedsvc.ingress.secretName }}
secretName: {{ .Values.controller.federation.managedsvc.ingress.secretName }}
{{- end }}
{{- end }}
{{- end }}
---
{{- end -}}
4 changes: 2 additions & 2 deletions charts/core/templates/manager-ingress.yaml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
{{- if and .Values.manager.enabled .Values.manager.ingress.enabled -}}
{{- if and .Values.manager.enabled .Values.manager.ingress.enabled (not (.Values.manager.ingress.traefikIngressRoute)) -}}
{{- if (semverCompare ">=1.19-0" (substr 1 -1 .Capabilities.KubeVersion.GitVersion)) }}
apiVersion: networking.k8s.io/v1
kind: Ingress
Expand Down Expand Up @@ -68,4 +68,4 @@ spec:
serviceName: neuvector-service-webui
servicePort: 8443
{{- end }}
{{- end -}}
{{- end -}}
32 changes: 32 additions & 0 deletions charts/core/templates/manager-traefik-ingressroute.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
{{- if and .Values.manager.enabled .Values.manager.ingress.enabled .Values.manager.ingress.traefikIngressRoute -}}
apiVersion: traefik.containo.us/v1alpha1
kind: IngressRoute
metadata:
name: neuvector-webui-ingress
namespace: {{ .Release.Namespace }}
{{- with .Values.manager.ingress.annotations }}
annotations:
{{ toYaml . | indent 4 }}
{{- end }}
labels:
chart: {{ template "neuvector.chart" . }}
release: {{ .Release.Name }}
heritage: {{ .Release.Service }}
spec:
entryPoints:
- websecure
routes:
- match: Host(`{{ .Values.manager.ingress.host }}`) && PathPrefix(`{{ .Values.manager.ingress.path }}`)
kind: Rule
services:
- name: neuvector-service-webui
passHostHeader: true
port: 8443
scheme: https
{{- if .Values.manager.ingress.tls }}
tls:
{{- if .Values.manager.ingress.secretName }}
secretName: {{ .Values.manager.ingress.secretName }}
{{- end }}
{{- end }}
{{- end -}}
2 changes: 1 addition & 1 deletion charts/core/templates/registry-adapter-ingress.yaml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{{- if .Values.cve.adapter.enabled -}}

{{- if .Values.cve.adapter.ingress.enabled }}
{{- if and .Values.cve.adapter.ingress.enabled (not (.Values.cve.adapter.ingress.traefikIngressRoute)) }}
{{- if (semverCompare ">=1.19-0" (substr 1 -1 .Capabilities.KubeVersion.GitVersion)) }}
apiVersion: networking.k8s.io/v1
kind: Ingress
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
{{- if and .Values.cve.adapter.ingress.enabled .Values.cve.adapter.ingress.traefikIngressRoute -}}
apiVersion: traefik.containo.us/v1alpha1
kind: IngressRoute
metadata:
name: neuvector-registry-adapter-ingress
namespace: {{ .Release.Namespace }}
{{- with .Values.cve.adapter.ingress.annotations }}
annotations:
{{ toYaml . | indent 4 }}
{{- end }}
labels:
chart: {{ template "neuvector.chart" . }}
release: {{ .Release.Name }}
heritage: {{ .Release.Service }}
spec:
entryPoints:
- websecure
routes:
- match: Host(`{{ .Values.cve.adapter.ingress.host }}`) && PathPrefix(`{{ .Values.cve.adapter.ingress.path }}`)
kind: Rule
services:
- name: neuvector-service-registry-adapter
passHostHeader: true
port: 9443
scheme: https
{{- if .Values.cve.adapter.ingress.tls }}
tls:
{{- if .Values.cve.adapter.ingress.secretName }}
secretName: {{ .Values.cve.adapter.ingress.secretName }}
{{- end }}
{{- end }}
{{- end -}}
5 changes: 5 additions & 0 deletions charts/core/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -159,6 +159,7 @@ controller:
# Federation Master Ingress
ingress:
enabled: false
traefikIngressRoute: false
host: # MUST be set, if ingress is enabled
ingressClassName: ""
path: "/" # or this could be "/api", but might need "rewrite-target" annotation
Expand Down Expand Up @@ -197,6 +198,7 @@ controller:
# Federation Managed Ingress
ingress:
enabled: false
traefikIngressRoute: false
host: # MUST be set, if ingress is enabled
ingressClassName: ""
path: "/" # or this could be "/api", but might need "rewrite-target" annotation
Expand Down Expand Up @@ -227,6 +229,7 @@ controller:
# -----END PRIVATE KEY-----
ingress:
enabled: false
traefikIngressRoute: false
host: # MUST be set, if ingress is enabled
ingressClassName: ""
path: "/" # or this could be "/api", but might need "rewrite-target" annotation
Expand Down Expand Up @@ -365,6 +368,7 @@ manager:
pemFile: tls.pem
ingress:
enabled: false
traefikIngressRoute: false
host: # MUST be set, if ingress is enabled
ingressClassName: ""
path: "/"
Expand Down Expand Up @@ -465,6 +469,7 @@ cve:
# -----END PRIVATE KEY-----
ingress:
enabled: false
traefikIngressRoute: false
host: # MUST be set, if ingress is enabled
ingressClassName: ""
path: "/"
Expand Down