net-kingdom/sso-mfa/k8s/authelia/ingress.yaml
tegwick 8156525a82
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Add login alias and record CoulombCore DNS inventory
2026-07-28 01:57:22 +02:00

50 lines
1.3 KiB
YAML

# Ingress — Authelia login portal (namespace: sso)
#
# auth.coulomb.social — canonical Authelia OIDC endpoint used by KeyCape.
# login.coulomb.social — user-facing alias for the same login portal.
#
# This hostname MUST be publicly reachable: users' browsers redirect here
# to enter their password. (MFA happens at the KeyCape layer, not here.)
#
# Config points (see CONFIG.md):
# CP-NK-005 auth.coulomb.social
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: authelia
namespace: sso
labels:
app.kubernetes.io/name: authelia
app.kubernetes.io/part-of: net-kingdom-sso-mfa
net-kingdom/component: sso
annotations:
cert-manager.io/cluster-issuer: letsencrypt-prod
spec:
ingressClassName: traefik
rules:
- host: auth.coulomb.social
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: authelia
port:
number: 9091
- host: login.coulomb.social
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: authelia
port:
number: 9091
tls:
- secretName: auth-tls
hosts:
- auth.coulomb.social
- login.coulomb.social