[ci skip] Fix HTTPS backend proxying for reverse-proxy services

- Add insecureSkipVerify=true globally for self-signed backend certs
- Name service ports with https- prefix for HTTPS backends so Traefik uses HTTPS
- Add ServersTransport CRD for per-service insecureSkipVerify
- Add serversscheme/serverstransport annotations to reverse-proxy factory
This commit is contained in:
Viktor Barzin 2026-02-07 13:56:24 +00:00
parent 4d0d2a3568
commit d4cf63dce9
No known key found for this signature in database
GPG key ID: 0EB088298288D958
3 changed files with 23 additions and 2 deletions

View file

@ -49,7 +49,7 @@ resource "kubernetes_service" "proxied-service" {
external_name = var.external_name
port {
name = "${var.name}-web"
name = var.backend_protocol == "HTTPS" ? "https-${var.name}" : "${var.name}-web"
port = var.port
protocol = "TCP"
target_port = var.port
@ -70,7 +70,9 @@ resource "kubernetes_ingress_v1" "proxied-ingress" {
var.rybbit_site_id != null ? "${var.namespace}-rybbit-analytics-${var.name}@kubernetescrd" : null,
var.custom_content_security_policy != null ? "${var.namespace}-custom-csp-${var.name}@kubernetescrd" : null,
]))
"traefik.ingress.kubernetes.io/router.entrypoints" = "websecure"
"traefik.ingress.kubernetes.io/router.entrypoints" = "websecure"
"traefik.ingress.kubernetes.io/service.serversscheme" = var.backend_protocol == "HTTPS" ? "https" : null
"traefik.ingress.kubernetes.io/service.serverstransport" = var.backend_protocol == "HTTPS" ? "traefik-insecure-skip-verify@kubernetescrd" : null
}, var.extra_annotations)
}