-
Notifications
You must be signed in to change notification settings - Fork 7
/
Copy pathtraefik-v2.tf
42 lines (36 loc) · 988 Bytes
/
traefik-v2.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
# Traefik v2
resource "kubernetes_namespace" "traefik" {
metadata {
name = "traefik"
}
}
resource "helm_release" "traefik" {
name = "traefik"
repository = "https://helm.traefik.io/traefik"
chart = "traefik"
version = var.traefik_helm_chart_version
namespace = kubernetes_namespace.traefik.metadata[0].name
# Permanent HTTP to HTTPS redirect
set {
name = "ports.web.redirectTo.port"
value = "websecure"
}
# Trust private AKS IP range
set {
name = "additionalArguments"
value = "{--entryPoints.websecure.forwardedHeaders.trustedIPs=10.0.0.0/8}"
}
}
data "kubernetes_service" "traefik" {
metadata {
name = helm_release.traefik.name
namespace = helm_release.traefik.namespace
}
}
resource "cloudflare_record" "traefik" {
zone_id = var.cloudflare_schnerring_net_zone_id
name = "k8s"
type = "A"
value = data.kubernetes_service.traefik.status.0.load_balancer.0.ingress.0.ip
proxied = true
}