Class: Kube::Cluster::Middleware::IngressForService
- Inherits:
-
Kube::Cluster::Middleware
- Object
- Kube::Cluster::Middleware
- Kube::Cluster::Middleware::IngressForService
- Defined in:
- lib/kube/cluster/middleware/ingress_for_service.rb
Overview
Generates an Ingress for every Service whose source resource carries the app.kubernetes.io/expose label.
The label value is the hostname:
.labels = { "app.kubernetes.io/expose": "app.example.com" }
Set to “true” to use the resource name as a hostname placeholder (useful when a later middleware or the manifest class resolves it).
Options:
issuer: — cert-manager ClusterIssuer name (default: "letsencrypt-prod")
ingress_class: — IngressClassName (default: "nginx")
stack do
use Middleware::IngressForService
use Middleware::IngressForService, issuer: "letsencrypt-staging"
end
Constant Summary collapse
- LABEL =
:"app.kubernetes.io/expose"
Constants inherited from Kube::Cluster::Middleware
Instance Method Summary collapse
Methods inherited from Kube::Cluster::Middleware
Constructor Details
This class inherits a constructor from Kube::Cluster::Middleware
Instance Method Details
#call(manifest) ⇒ Object
31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 |
# File 'lib/kube/cluster/middleware/ingress_for_service.rb', line 31 def call(manifest) generated = [] issuer = @opts.fetch(:issuer, "letsencrypt-prod") ingress_class = @opts.fetch(:ingress_class, "nginx") manifest.resources.each do |resource| filter(resource) do next unless resource.kind == "Service" host = resource.label(LABEL) next unless host h = resource.to_h name = h.dig(:metadata, :name) namespace = h.dig(:metadata, :namespace) labels = h.dig(:metadata, :labels) || {} # Find the first port on the service port_name = Array(h.dig(:spec, :ports)).first&.dig(:name) || "http" # Use resource name as hostname fallback if label is just "true" host = "#{name}.local" if host == "true" generated << Kube::Cluster["Ingress"].new { .name = name .namespace = namespace if namespace .labels = labels.reject { |k, _| k == LABEL } .annotations = { "cert-manager.io/cluster-issuer": issuer, "nginx.ingress.kubernetes.io/ssl-redirect": "true", } spec.ingressClassName = ingress_class spec.tls = [ { hosts: [host], secretName: "#{name}-tls" }, ] spec.rules = [ { host: host, http: { paths: [{ path: "/", pathType: "Prefix", backend: { service: { name: name, port: { name: port_name } } }, }], }, }, ] } end end manifest.resources.concat(generated) end |