Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018BAUeCFpDkRD6tU5wGsc1C
129 lines
3.9 KiB
YAML
129 lines
3.9 KiB
YAML
# =============================================================================
|
|
# Exposition publique
|
|
# =============================================================================
|
|
# Cartographie des domaines :
|
|
#
|
|
# xpeditis.com -> frontend (vitrine, pages publiques)
|
|
# www.xpeditis.com -> frontend
|
|
# app.xpeditis.com -> frontend (dashboard ; c'est l'origine des cookies)
|
|
# api.xpeditis.com -> backend NestJS
|
|
# grafana.xpeditis.com-> Grafana (voir k8s/monitoring/)
|
|
#
|
|
# Le certificat est un wildcard *.xpeditis.com + xpeditis.com, obtenu par
|
|
# cert-manager en DNS-01 Cloudflare (cf. 11-certificate.yaml).
|
|
# La redirection HTTP -> HTTPS est faite au niveau de l'entrypoint Traefik,
|
|
# aucun Ingress ne peut l'oublier.
|
|
|
|
---
|
|
# --- API : routes d'authentification (limitation stricte) --------------------
|
|
# Ingress separe et plus specifique que celui de l'API : Traefik privilegie la
|
|
# regle au chemin le plus long, cette limite s'applique donc bien en priorite.
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: Ingress
|
|
metadata:
|
|
name: xpeditis-api-auth
|
|
namespace: xpeditis-prod
|
|
annotations:
|
|
traefik.ingress.kubernetes.io/router.entrypoints: websecure
|
|
traefik.ingress.kubernetes.io/router.tls: "true"
|
|
traefik.ingress.kubernetes.io/router.middlewares: xpeditis-prod-auth-chain@kubernetescrd
|
|
spec:
|
|
ingressClassName: traefik
|
|
tls:
|
|
- hosts:
|
|
- api.xpeditis.com
|
|
secretName: xpeditis-wildcard-tls
|
|
rules:
|
|
- host: api.xpeditis.com
|
|
http:
|
|
paths:
|
|
- path: /api/v1/auth
|
|
pathType: Prefix
|
|
backend:
|
|
service:
|
|
name: xpeditis-backend
|
|
port:
|
|
name: http
|
|
|
|
---
|
|
# --- API : tout le reste -----------------------------------------------------
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: Ingress
|
|
metadata:
|
|
name: xpeditis-api
|
|
namespace: xpeditis-prod
|
|
annotations:
|
|
traefik.ingress.kubernetes.io/router.entrypoints: websecure
|
|
traefik.ingress.kubernetes.io/router.tls: "true"
|
|
traefik.ingress.kubernetes.io/router.middlewares: xpeditis-prod-public-chain@kubernetescrd
|
|
spec:
|
|
ingressClassName: traefik
|
|
tls:
|
|
- hosts:
|
|
- api.xpeditis.com
|
|
secretName: xpeditis-wildcard-tls
|
|
rules:
|
|
- host: api.xpeditis.com
|
|
http:
|
|
paths:
|
|
# Couvre l'API REST, le webhook Stripe et le handshake Socket.IO
|
|
# (/socket.io/...), Traefik gerant l'upgrade WebSocket nativement.
|
|
- path: /
|
|
pathType: Prefix
|
|
backend:
|
|
service:
|
|
name: xpeditis-backend
|
|
port:
|
|
name: http
|
|
|
|
---
|
|
# --- Frontend ----------------------------------------------------------------
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: Ingress
|
|
metadata:
|
|
name: xpeditis-app
|
|
namespace: xpeditis-prod
|
|
annotations:
|
|
traefik.ingress.kubernetes.io/router.entrypoints: websecure
|
|
traefik.ingress.kubernetes.io/router.tls: "true"
|
|
traefik.ingress.kubernetes.io/router.middlewares: xpeditis-prod-public-chain@kubernetescrd
|
|
spec:
|
|
ingressClassName: traefik
|
|
tls:
|
|
- hosts:
|
|
- xpeditis.com
|
|
- www.xpeditis.com
|
|
- app.xpeditis.com
|
|
secretName: xpeditis-wildcard-tls
|
|
rules:
|
|
- host: app.xpeditis.com
|
|
http:
|
|
paths:
|
|
- path: /
|
|
pathType: Prefix
|
|
backend:
|
|
service:
|
|
name: xpeditis-frontend
|
|
port:
|
|
name: http
|
|
- host: www.xpeditis.com
|
|
http:
|
|
paths:
|
|
- path: /
|
|
pathType: Prefix
|
|
backend:
|
|
service:
|
|
name: xpeditis-frontend
|
|
port:
|
|
name: http
|
|
- host: xpeditis.com
|
|
http:
|
|
paths:
|
|
- path: /
|
|
pathType: Prefix
|
|
backend:
|
|
service:
|
|
name: xpeditis-frontend
|
|
port:
|
|
name: http
|