# Kourier stays ClusterIP; public entry needs separate reef admission evidence. # Declared here rather than patched after apply, so a re-run never flips the # live Service to the upstream LoadBalancer type, even briefly. apiVersion: v1 kind: Service metadata: name: kourier namespace: kourier-system spec: type: ClusterIP