30 lines
1.4 KiB
Text
30 lines
1.4 KiB
Text
# Add these blocks to the Caddyfile your Podman Caddy container already
|
|
# loads (alongside the existing git.boglabob.com block for Forgejo).
|
|
# Replace the node IPs with your actual k3s node IPs from `tofu output
|
|
# node_ips` (10.20.30.0/24 by default).
|
|
#
|
|
# These IPs are on the private libvirt network the VMs live on (see
|
|
# terraform/variables.tf's network_cidr), only directly routable from the
|
|
# T630 itself — but since Caddy also runs on the T630 (Podman), it reaches
|
|
# them the same way any other process on the host would: no extra network
|
|
# config needed here.
|
|
#
|
|
# podinfo/hello sit behind Traefik's ServiceLB, which listens on port 80 of
|
|
# every k3s node and routes by the Host header — so Caddy just needs to
|
|
# forward the request (Host header included) to any node. Listing all three
|
|
# gives you free load-balancing/failover across nodes.
|
|
#
|
|
# Deliberately NOT here: the Kubernetes Dashboard and the k3s API server.
|
|
# Both grant cluster-admin-level control, and routing either through a
|
|
# public-facing reverse proxy is the exact pattern behind real-world
|
|
# cluster breaches (e.g. Tesla, 2018 — an exposed, unauthenticated
|
|
# Dashboard). Both stay LAN-only / on-demand instead — see docs/SETUP.md
|
|
# steps 12-13.
|
|
|
|
podinfo.boglabob.com {
|
|
reverse_proxy http://10.20.30.11:80 http://10.20.30.12:80 http://10.20.30.13:80
|
|
}
|
|
|
|
hello.boglabob.com {
|
|
reverse_proxy http://10.20.30.11:80 http://10.20.30.12:80 http://10.20.30.13:80
|
|
}
|