The console will not work from outside without this. WebsocketController hands the browser wss://<node fqdn>:443/api/servers/<uuid>/ws built from Node::getConnectionAddress(), so the browser talks to wings directly and never through the panel. Same for file upload and download, which FileUploadController builds from the same address. Everything else (login, server list, file browsing, power actions, sending console commands) already worked publicly, because those go through the panel API. Adds public listeners for both nodes reusing the existing wings-mc-tls and wings-ark-tls certificates, and a gateway-public parentRef on each route. Extends the wings ClientTrafficPolicy to the two new listeners. Without it the public listeners would negotiate h2 and long-lived consoles would drop: wings only speaks HTTP/1.1, and the idle timeout needs to be 3600s rather than the default. CrowdSec ext_authz already covers every listener on gateway-public, so both nodes are behind the WAF and community blocklist from the moment they are live. Wings itself is JWT-gated and returns 401 unauthenticated.
409 lines
12 KiB
YAML
409 lines
12 KiB
YAML
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
kind: Kustomization
|
|
|
|
# ORPHANED LISTENERS, commented out 2026-08-26. Each of these had a Gateway
|
|
# listener and a TLS cert but ZERO attached routes, because the app is either in
|
|
# deprecated/ (vaultwarden, affine, resume-minio*) or written but never deployed
|
|
# (n8n, wikijs, ollama, openwebui). wiki.jsme.be was one of these on the PUBLIC
|
|
# gateway. Uncomment the pair (certificate + patch) when actually deploying the app.
|
|
|
|
resources:
|
|
- envoy-gateway-namespace.yaml
|
|
- gateway.yaml
|
|
- gateway-public.yaml
|
|
|
|
# CrowdSec ext_authz on the whole public gateway (sectionName scoping is
|
|
# unsupported on EG v1.3.2; envoyproxy-public.yaml is not needed, see its header)
|
|
- crowdsec/gateway-public-securitypolicy.yaml
|
|
|
|
# Policies
|
|
- pelican/pelican-wings-clienttrafficpolicy.yaml
|
|
- minio-aistor/minio-aistor-clienttrafficpolicy.yaml
|
|
- minio-aistor/minio-aistor-console-clienttrafficpolicy.yaml
|
|
|
|
# Certificates
|
|
- authentik/authentik-certificate.yaml
|
|
- argocd/argocd-certificate.yaml
|
|
- bentopdf/bentopdf-certificate.yaml
|
|
- gitea/gitea-certificate.yaml
|
|
- immich/immich-certificate.yaml
|
|
- infisical/infisical-certificate.yaml
|
|
- it-tools/it-tools-certificate.yaml
|
|
- jellyfin/jellyfin-certificate.yaml
|
|
- longhorn/longhorn-certificate.yaml
|
|
- monitoring/monitoring-certificate.yaml
|
|
# - n8n/n8n-certificate.yaml
|
|
- netbootxyz/netbootxyz-certificate.yaml
|
|
- passbolt/passbolt-certificate.yaml
|
|
- proxmox/proxmox-certificate.yaml
|
|
- resume/resume-certificate.yaml
|
|
# - resume/resume-minio-certificate.yaml
|
|
# - resume/resume-minio-webui-certificate.yaml
|
|
- minio-aistor/minio-aistor-api-certificate.yaml
|
|
- minio-aistor/minio-aistor-console-certificate.yaml
|
|
- technitium/technitium-certificate.yaml
|
|
- technitium/technitium-backup-certificate.yaml
|
|
- truenas/truenas-certificate.yaml
|
|
- unifi/unifi-certificate.yaml
|
|
# - wikijs/wikijs-certificate.yaml
|
|
- zipline/zipline-certificate.yaml
|
|
# - vaultwarden/vaultwarden-certificate.yaml
|
|
- databasus/databasus-certificate.yaml
|
|
- excalidraw/excalidraw-certificate.yaml
|
|
- gotify/gotify-certificate.yaml
|
|
- uptime-kuma/uptime-kuma-certificate.yaml
|
|
# - ollama/ollama-certificate.yaml
|
|
# - openwebui/openwebui-certificate.yaml
|
|
- searxng/searxng-certificate.yaml
|
|
# - affine/affine-certificate.yaml
|
|
- pelican/pelican-certificate.yaml
|
|
- pelican/pelican-wings-mc-certificate.yaml
|
|
- pelican/pelican-wings-ark-certificate.yaml
|
|
- outline/outline-certificate.yaml
|
|
# netbox: uncomment together with the patch below once infra/envoy-gateway/netbox/ is committed
|
|
# - netbox/netbox-certificate.yaml
|
|
|
|
patches:
|
|
# Internal gateway patches
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: authentik/authentik-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: argocd/argocd-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: gitea/gitea-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: immich/immich-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: infisical/infisical-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: longhorn/longhorn-gateway-patch.yaml
|
|
# - target:
|
|
# group: gateway.networking.k8s.io
|
|
# version: v1
|
|
# kind: Gateway
|
|
# name: gateway-internal
|
|
# path: n8n/n8n-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: netbootxyz/netbootxyz-gateway-patch.yaml
|
|
# - target:
|
|
# group: gateway.networking.k8s.io
|
|
# version: v1
|
|
# kind: Gateway
|
|
# name: gateway-internal
|
|
# path: resume/resume-minio-gateway-patch.yaml
|
|
# - target:
|
|
# group: gateway.networking.k8s.io
|
|
# version: v1
|
|
# kind: Gateway
|
|
# name: gateway-internal
|
|
# path: resume/resume-minio-webui-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: technitium/technitium-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: technitium/technitium-backup-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: unifi/unifi-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: proxmox/proxmox-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: truenas/truenas-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: monitoring/monitoring-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: bentopdf/bentopdf-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: it-tools/it-tools-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: jellyfin/jellyfin-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: passbolt/passbolt-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: resume/resume-gateway-patch.yaml
|
|
# - target:
|
|
# group: gateway.networking.k8s.io
|
|
# version: v1
|
|
# kind: Gateway
|
|
# name: gateway-internal
|
|
# path: wikijs/wikijs-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: zipline/zipline-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: minio-aistor/minio-aistor-api-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: minio-aistor/minio-aistor-console-gateway-patch.yaml
|
|
# - target:
|
|
# group: gateway.networking.k8s.io
|
|
# version: v1
|
|
# kind: Gateway
|
|
# name: gateway-internal
|
|
# path: vaultwarden/vaultwarden-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: databasus/databasus-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: excalidraw/excalidraw-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: gotify/gotify-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: uptime-kuma/uptime-kuma-gateway-patch.yaml
|
|
# - target:
|
|
# group: gateway.networking.k8s.io
|
|
# version: v1
|
|
# kind: Gateway
|
|
# name: gateway-internal
|
|
# path: ollama/ollama-gateway-patch.yaml
|
|
# - target:
|
|
# group: gateway.networking.k8s.io
|
|
# version: v1
|
|
# kind: Gateway
|
|
# name: gateway-internal
|
|
# path: openwebui/openwebui-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: searxng/searxng-gateway-patch.yaml
|
|
# - target:
|
|
# group: gateway.networking.k8s.io
|
|
# version: v1
|
|
# kind: Gateway
|
|
# name: gateway-internal
|
|
# path: affine/affine-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: pelican/pelican-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: pelican/pelican-wings-mc-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: pelican/pelican-wings-ark-gateway-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-internal
|
|
path: outline/outline-gateway-patch.yaml
|
|
# - target:
|
|
# group: gateway.networking.k8s.io
|
|
# version: v1
|
|
# kind: Gateway
|
|
# name: gateway-internal
|
|
# path: netbox/netbox-gateway-patch.yaml
|
|
|
|
# Public gateway patches
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-public
|
|
path: gitea/gitea-gateway-public-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-public
|
|
path: authentik/authentik-gateway-public-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-public
|
|
path: bentopdf/bentopdf-gateway-public-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-public
|
|
path: it-tools/it-tools-gateway-public-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-public
|
|
path: jellyfin/jellyfin-gateway-public-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-public
|
|
path: immich/immich-gateway-public-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-public
|
|
path: passbolt/passbolt-gateway-public-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-public
|
|
path: resume/resume-gateway-public-patch.yaml
|
|
# - target:
|
|
# group: gateway.networking.k8s.io
|
|
# version: v1
|
|
# kind: Gateway
|
|
# name: gateway-public
|
|
# path: wikijs/wikijs-gateway-public-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-public
|
|
path: zipline/zipline-gateway-public-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-public
|
|
path: excalidraw/excalidraw-gateway-public-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-public
|
|
path: gotify/gotify-gateway-public-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-public
|
|
path: outline/outline-gateway-public-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-public
|
|
path: pelican/pelican-gateway-public-patch.yaml
|
|
# wings must be public for the console websocket and file transfers: the
|
|
# browser talks to the node directly, never through the panel.
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-public
|
|
path: pelican/pelican-wings-mc-gateway-public-patch.yaml
|
|
- target:
|
|
group: gateway.networking.k8s.io
|
|
version: v1
|
|
kind: Gateway
|
|
name: gateway-public
|
|
path: pelican/pelican-wings-ark-gateway-public-patch.yaml
|
|
# Uncomment to expose Grafana publicly — ensure Grafana auth is properly configured first
|
|
# - target:
|
|
# group: gateway.networking.k8s.io
|
|
# version: v1
|
|
# kind: Gateway
|
|
# name: gateway-public
|
|
# path: monitoring/monitoring-grafana-gateway-public-patch.yaml
|