𝔩𝔢𝔩𝕠𝔭𝔢𝔷
Theme

Homelab

Private Tier on the Gateway

Moving the Private Tier to Envoy Gateway: HTTPRoutes for FileBrowser and the Longhorn UI with SecurityPolicy Basic Auth

Overview

The two private services move next. FileBrowser's route carries nothing over from its Ingress, because the body-size annotation it needed under ingress-nginx has no equivalent to port and Envoy imposes no limit, but it does need Envoy's default request timeout lifted so large uploads survive. The Longhorn UI is the spike: its basic auth moves from an Ingress annotation to a SecurityPolicy attached to the route, reading a second key in the same Secret. Both routes land dormant beside their Ingress objects: ingress-nginx keeps serving the private names, and the routes are verified by addressing the Gateway directly from inside the cluster. The record that activates them moves once, later, together with the game lane.

Having trouble? See v2.10.0 for reference.

This article isn't ready yet

Check back soon for the full article.

Previous
Public Tier on the Gateway