Homelab
Private Tier on the Gateway
Moving the Private Tier to Envoy Gateway: HTTPRoutes for FileBrowser and the Longhorn UI with SecurityPolicy Basic Auth
Overview
The two private services move next. FileBrowser's route carries nothing over from its Ingress, because the body-size annotation it needed under ingress-nginx has no equivalent to port and Envoy imposes no limit, but it does need Envoy's default request timeout lifted so large uploads survive. The Longhorn UI is the spike: its basic auth moves from an Ingress annotation to a SecurityPolicy attached to the route, reading a second key in the same Secret. Both routes land dormant beside their Ingress objects: ingress-nginx keeps serving the private names, and the routes are verified by addressing the Gateway directly from inside the cluster. The record that activates them moves once, later, together with the game lane.
Having trouble? See v2.10.0 for reference.
This article isn't ready yet
Check back soon for the full article.