Traefik

The front door: every inbound HTTP and HTTPS route enters through it via the Gateway API

Decommissioned 2026-09-20

Traefik was the cluster edge proxy from the beginning until 2026-09-20, when every route migrated to the Istio Gateway and the Traefik CRDs were purged. The chart below is kept for reference; nothing deploys it today.

ArgoCD configuration

Excerpt from argocd-apps/values.yaml in the argocd-apps chart, with annotations added for this site:

traefik:
  # true: the Application manifest is rendered by templates/applications/gitlab-apps-template.yaml
  application: true
  # k3s-services: platform layer, fails independently of user-facing apps
  project: k3s-services
  # false: proxy routes are high blast radius; sync after reviewing the diff
  autoSync: false

Chart values

The full traefik/values.yaml from the service's own chart:

traefik:
  providers:
    kubernetesCRD:
      enabled: true
      allowCrossNamespace: true
      allowExternalNameServices: true

    kubernetesIngress:
      enabled: true
      allowExternalNameServices: true
      publishedService:
        enabled: true

    kubernetesGateway:
      enabled: true
      # experimentalChannel requires the Gateway API *Experimental* channel CRDs
      # (experimental-install.yaml) to be installed. We only use HTTPRoutes, which
      # live in the Standard channel, so this stays off. Enabling it with only the
      # standard-install.yaml CRDs prevents the whole gateway provider from serving
      # any route -> every HTTPRoute host 404s (OriginStatus 0).
      experimentalChannel: false

  hostNetwork: true

  rbac:
    enabled: true

  log:
    format: json
    level: "INFO"

  accessLog:
    enabled: true
    format: json

  deployment:
    dnsConfig:
      nameservers:
        - 192.168.1.20
        - 192.168.1.21

  commonLabels:
    app: traefik

  metrics:
    prometheus:
      entryPoint: metrics
      addRoutersLabels: true
      addServicesLabels: true

  additionalArguments:
    - "--serverstransport.forwardingTimeouts.idleConnTimeout=24h"

  ports:
    traefik:
      port: 9000
      expose:
        default: true
      exposedPort: 9000
      protocol: TCP
    web:
      port: 8000
      expose:
        default: true
      exposedPort: 80
      protocol: TCP
    websecure:
      port: 8443
      expose:
        default: true
      exposedPort: 443
      protocol: TCP
      forwardedHeaders:
        trustedIPs:
          - "192.168.1.0/24"
          - "192.168.10.0/24"
    metrics:
      port: 9100
      expose:
        default: true
      exposedPort: 9100
      protocol: TCP
    postgres:
      expose:
        default: true
      port: 5432
      exposedPort: 5432
      protocol: TCP
    torrent-tcp:
      expose:
        default: true
      port: 6881
      exposedPort: 6881
      protocol: TCP
    torrent-udp:
      expose:
        default: true
      port: 6881
      exposedPort: 6881
      protocol: UDP
    kafka:
      expose:
        default: true
      port: 9092
      exposedPort: 9092
      protocol: TCP

  service:
    enabled: true
    single: true
    type: LoadBalancer
    externalIPs:
      - 192.168.1.5

  persistence:
    enabled: false

  api:
    dashboard: true

  ingressRoute:
    dashboard:
      enabled: true
      matchRule: "(Host(`traefik.opi5cluster.co.uk`) && PathPrefix(`/dashboard`)) ||
        (Host(`traefik.opi5cluster.co.uk`) && PathPrefix(`/api`))"
      entryPoints:
        - "websecure"
      tls:
        secretName: opi5cluster-co-uk-domain-secret

  resources:
    requests:
      cpu: 22m
      memory: 127M

  gateway:
    enabled: true
    listeners:
      web:
        port: 8000
        protocol: HTTP
        namespacePolicy:
          from: All

      rustfs:
        port: 8443
        protocol: HTTPS
        hostname: "*.rustfs.opi5cluster.co.uk"
        namespacePolicy:
          from: All
        certificateRefs:
          - name: rustfs-subdomain-secret
            kind: Secret
        mode: Terminate

      websecure:
        port: 8443
        protocol: HTTPS
        hostname: "*.opi5cluster.co.uk"
        namespacePolicy:
          from: All
        certificateRefs:
          - name: opi5cluster-co-uk-domain-secret
            kind: Secret
        mode: Terminate

      postgres:
        port: 5432
        protocol: TCP
        namespacePolicy:
          from: All

      kafka:
        port: 9092
        protocol: TCP
        namespacePolicy:
          from: All

      torrent-tcp:
        port: 6881
        protocol: TCP
        namespacePolicy:
          from: All

      traefik:
        port: 9000
        protocol: HTTP
        namespacePolicy:
          from: All
  • Routes reference the wildcard certificate secret issued by cert-manager.

Trade-offs

Decision. Use Gateway API (Gateway + HTTPRoute) for all routing

Alternative. Classic Ingress resources

Why. Gateway API separates route ownership from the proxy implementation, supports header and weight-based routing, and is where the ecosystem is heading.

Decision. Expose selected services from the cluster through Cloudflare Tunnel

Alternative. Publishing ports on the router

Why. The tunnel is outbound-only, so the cluster has no open inbound ports and TLS terminates at the edge.

Decision. Keep autoSync off for Traefik

Alternative. Auto-syncing routing changes

Why. A bad route change can take every service offline; the diff is reviewed, then synced manually.

← Back to Decommissioned Services · All service groups