Expose the postgres cluster outside of the Kubernetes cluster Give myself the option of connecting to postgres from my own machines, so that I can hopefully leverage the improved performance Update some file linting issues in Nix Add necessary gitlab keys so it can be updated properly the next time I deploy to it Add DNS entries for postgres Update the configuraiton of Traefik to expose the appropriate ports
40 lines
929 B
YAML
40 lines
929 B
YAML
apiVersion: traefik.io/v1alpha1
|
|
kind: MiddlewareTCP
|
|
metadata:
|
|
name: local-hosts-only
|
|
namespace: db
|
|
spec:
|
|
ipAllowList:
|
|
sourceRange:
|
|
- 127.0.0.1/32 # Localhost, obviously
|
|
- 10.42.0.0/16 # My internal net
|
|
- 10.211.0.0/16 # Kubernetes IPs
|
|
# Tailscale hosts
|
|
- 100.119.228.115 # chronicles
|
|
- 100.88.91.27 # dns?
|
|
- 100.80.99.48 # exodus
|
|
- 100.88.91.27 # genesis
|
|
- 100.91.131.66 # gitlab
|
|
- 100.68.203.1 # hosea
|
|
- 100.84.183.79 # isaiah
|
|
- 100.102.186.39 # jeremiah
|
|
- 100.90.74.19 # jude
|
|
- 100.115.57.8 # linode
|
|
- 100.65.5.38 # matrix
|
|
- 100.127.55.22 # jellyfin
|
|
---
|
|
apiVersion: traefik.io/v1alpha1
|
|
kind: IngressRouteTCP
|
|
metadata:
|
|
name: ingress-route-postgres
|
|
namespace: db
|
|
spec:
|
|
entryPoints:
|
|
- postgres
|
|
routes:
|
|
- match: HostSNI(`*`)
|
|
priority: 10
|
|
services:
|
|
- name: postgres-rw
|
|
port: 5432
|