Homelab
Public Tier on the Gateway
Moving the Public Tier to Envoy Gateway: an HTTPRoute for the Canary and an frp Lane Retargeted
Overview
The public tier is the riskiest cutover because its traffic arrives through the tunnel, so it moves first while the private services still sit on ingress-nginx. The canary becomes an HTTPRoute on the public listener, the frpc lane that carries the tier home retargets to the Gateway's address, and the by-pod NetworkPolicy rule that enforcement made necessary now selects the Envoy proxy pods. The canary's Ingress and the mirror stub that put the wildcard into frp-tunnel retire last, because the listener holds the certificate now.
Having trouble? See v2.9.0 for reference.
This article isn't ready yet
Check back soon for the full article.