Decommissioned 2026-09-20
Traefik was the cluster edge proxy from the beginning until 2026-09-20, when every route migrated to the Istio Gateway and the Traefik CRDs were purged. The chart below is kept for reference; nothing deploys it today.
ArgoCD configuration
Excerpt from argocd-apps/values.yaml in the argocd-apps chart,
with annotations added for this site:
traefik:
# true: the Application manifest is rendered by templates/applications/gitlab-apps-template.yaml
application: true
# k3s-services: platform layer, fails independently of user-facing apps
project: k3s-services
# false: proxy routes are high blast radius; sync after reviewing the diff
autoSync: false
Chart values
The full traefik/values.yaml from the service's
own chart:
traefik:
providers:
kubernetesCRD:
enabled: true
allowCrossNamespace: true
allowExternalNameServices: true
kubernetesIngress:
enabled: true
allowExternalNameServices: true
publishedService:
enabled: true
kubernetesGateway:
enabled: true
# experimentalChannel requires the Gateway API *Experimental* channel CRDs
# (experimental-install.yaml) to be installed. We only use HTTPRoutes, which
# live in the Standard channel, so this stays off. Enabling it with only the
# standard-install.yaml CRDs prevents the whole gateway provider from serving
# any route -> every HTTPRoute host 404s (OriginStatus 0).
experimentalChannel: false
hostNetwork: true
rbac:
enabled: true
log:
format: json
level: "INFO"
accessLog:
enabled: true
format: json
deployment:
dnsConfig:
nameservers:
- 192.168.1.20
- 192.168.1.21
commonLabels:
app: traefik
metrics:
prometheus:
entryPoint: metrics
addRoutersLabels: true
addServicesLabels: true
additionalArguments:
- "--serverstransport.forwardingTimeouts.idleConnTimeout=24h"
ports:
traefik:
port: 9000
expose:
default: true
exposedPort: 9000
protocol: TCP
web:
port: 8000
expose:
default: true
exposedPort: 80
protocol: TCP
websecure:
port: 8443
expose:
default: true
exposedPort: 443
protocol: TCP
forwardedHeaders:
trustedIPs:
- "192.168.1.0/24"
- "192.168.10.0/24"
metrics:
port: 9100
expose:
default: true
exposedPort: 9100
protocol: TCP
postgres:
expose:
default: true
port: 5432
exposedPort: 5432
protocol: TCP
torrent-tcp:
expose:
default: true
port: 6881
exposedPort: 6881
protocol: TCP
torrent-udp:
expose:
default: true
port: 6881
exposedPort: 6881
protocol: UDP
kafka:
expose:
default: true
port: 9092
exposedPort: 9092
protocol: TCP
service:
enabled: true
single: true
type: LoadBalancer
externalIPs:
- 192.168.1.5
persistence:
enabled: false
api:
dashboard: true
ingressRoute:
dashboard:
enabled: true
matchRule: "(Host(`traefik.opi5cluster.co.uk`) && PathPrefix(`/dashboard`)) ||
(Host(`traefik.opi5cluster.co.uk`) && PathPrefix(`/api`))"
entryPoints:
- "websecure"
tls:
secretName: opi5cluster-co-uk-domain-secret
resources:
requests:
cpu: 22m
memory: 127M
gateway:
enabled: true
listeners:
web:
port: 8000
protocol: HTTP
namespacePolicy:
from: All
rustfs:
port: 8443
protocol: HTTPS
hostname: "*.rustfs.opi5cluster.co.uk"
namespacePolicy:
from: All
certificateRefs:
- name: rustfs-subdomain-secret
kind: Secret
mode: Terminate
websecure:
port: 8443
protocol: HTTPS
hostname: "*.opi5cluster.co.uk"
namespacePolicy:
from: All
certificateRefs:
- name: opi5cluster-co-uk-domain-secret
kind: Secret
mode: Terminate
postgres:
port: 5432
protocol: TCP
namespacePolicy:
from: All
kafka:
port: 9092
protocol: TCP
namespacePolicy:
from: All
torrent-tcp:
port: 6881
protocol: TCP
namespacePolicy:
from: All
traefik:
port: 9000
protocol: HTTP
namespacePolicy:
from: All
- Routes reference the wildcard certificate secret issued by cert-manager.
Trade-offs
Decision. Use Gateway API (Gateway + HTTPRoute) for all routing
Alternative. Classic Ingress resources
Why. Gateway API separates route ownership from the proxy implementation, supports header and weight-based routing, and is where the ecosystem is heading.
Decision. Expose selected services from the cluster through Cloudflare Tunnel
Alternative. Publishing ports on the router
Why. The tunnel is outbound-only, so the cluster has no open inbound ports and TLS terminates at the edge.
Decision. Keep autoSync off for Traefik
Alternative. Auto-syncing routing changes
Why. A bad route change can take every service offline; the diff is reviewed, then synced manually.
← Back to Decommissioned Services · All service groups