# ============================================================================= # Exposition publique # ============================================================================= # Cartographie des domaines : # # xpeditis.com -> frontend (vitrine, pages publiques) # www.xpeditis.com -> frontend # app.xpeditis.com -> frontend (dashboard ; c'est l'origine des cookies) # api.xpeditis.com -> backend NestJS # grafana.xpeditis.com-> Grafana (voir k8s/monitoring/) # # Le certificat est un wildcard *.xpeditis.com + xpeditis.com, obtenu par # cert-manager en DNS-01 Cloudflare (cf. 11-certificate.yaml). # La redirection HTTP -> HTTPS est faite au niveau de l'entrypoint Traefik, # aucun Ingress ne peut l'oublier. --- # --- API : routes d'authentification (limitation stricte) -------------------- # Ingress separe et plus specifique que celui de l'API : Traefik privilegie la # regle au chemin le plus long, cette limite s'applique donc bien en priorite. apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: xpeditis-api-auth namespace: xpeditis-prod annotations: traefik.ingress.kubernetes.io/router.entrypoints: websecure traefik.ingress.kubernetes.io/router.tls: "true" traefik.ingress.kubernetes.io/router.middlewares: xpeditis-prod-auth-chain@kubernetescrd spec: ingressClassName: traefik tls: - hosts: - api.xpeditis.com secretName: xpeditis-wildcard-tls rules: - host: api.xpeditis.com http: paths: - path: /api/v1/auth pathType: Prefix backend: service: name: xpeditis-backend port: name: http --- # --- API : tout le reste ----------------------------------------------------- apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: xpeditis-api namespace: xpeditis-prod annotations: traefik.ingress.kubernetes.io/router.entrypoints: websecure traefik.ingress.kubernetes.io/router.tls: "true" traefik.ingress.kubernetes.io/router.middlewares: xpeditis-prod-public-chain@kubernetescrd spec: ingressClassName: traefik tls: - hosts: - api.xpeditis.com secretName: xpeditis-wildcard-tls rules: - host: api.xpeditis.com http: paths: # Couvre l'API REST, le webhook Stripe et le handshake Socket.IO # (/socket.io/...), Traefik gerant l'upgrade WebSocket nativement. - path: / pathType: Prefix backend: service: name: xpeditis-backend port: name: http --- # --- Frontend ---------------------------------------------------------------- apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: xpeditis-app namespace: xpeditis-prod annotations: traefik.ingress.kubernetes.io/router.entrypoints: websecure traefik.ingress.kubernetes.io/router.tls: "true" traefik.ingress.kubernetes.io/router.middlewares: xpeditis-prod-public-chain@kubernetescrd spec: ingressClassName: traefik tls: - hosts: - xpeditis.com - www.xpeditis.com - app.xpeditis.com secretName: xpeditis-wildcard-tls rules: - host: app.xpeditis.com http: paths: - path: / pathType: Prefix backend: service: name: xpeditis-frontend port: name: http - host: www.xpeditis.com http: paths: - path: / pathType: Prefix backend: service: name: xpeditis-frontend port: name: http - host: xpeditis.com http: paths: - path: / pathType: Prefix backend: service: name: xpeditis-frontend port: name: http