S5 Workloads — Gitea, Zulip, and other application Helm releases
The main Ingress is websecure-only per the forgejo pattern, so port 80 was unrouted for this host and plain http:// returned Traefik's default 404. Adds a redirectScheme Middleware plus a web-entrypoint Ingress, following the reuse-surface pattern. Pins router.priority: "1" on the redirect. cert-manager solves HTTP-01 by creating a solver Ingress on this same host and entrypoint, so a catch-all "/" redirect competes with it directly. Traefik would normally settle that by rule length, but reuse-surface's 2026-07-07 report is exactly a case of a specific rule losing to a catch-all when precedence was left implicit -- and here the symptom would not be a visible 404 but a silently failed renewal ~60 days out, surfacing as an expired certificate on the origin backing an OIDC redirect URI. Verified by probe twice: with a solver-shaped Ingress present the challenge path returns 200 (solver wins) while "/" still redirects; with it absent the redirect correctly catches both. Probe was throwaway and is not committed; the runbook carries the table to recreate it. GET returns 301 and HEAD 308. That split is Traefik's own behaviour on this cluster, not a defect here -- reuse.coulomb.social does the same. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EJbh7o7UWF4tQ5jxygnNGu Assistant: claude-code Assistant-Model: opus Assistant-Process: 2072522@bnt-lap001 Assistant-Session: 46173adf-7302-4ede-99d6-963b61359928 |
||
|---|---|---|
| .claude/rules | ||
| .forgejo/workflows | ||
| .gitea/workflows | ||
| bindings | ||
| charts | ||
| docs | ||
| helm | ||
| manifests | ||
| registry | ||
| tools | ||
| workplans | ||
| .custodian-brief.md | ||
| .repo-classification.yaml | ||
| .sops.yaml | ||
| AGENTS.md | ||
| CLAUDE.md | ||
| INTENT.md | ||
| LICENSE | ||
| Makefile | ||
| SCOPE.md | ||
| STATE.md | ||
| WORK-RECORDS.md | ||