diff --git a/helm-overrides/gke-toolshed-prd-usc1/argocd-admin-prd/custom-values.yaml b/helm-overrides/gke-toolshed-prd-usc1/argocd-admin-prd/custom-values.yaml index 7889b1c..f4f1ef2 100644 --- a/helm-overrides/gke-toolshed-prd-usc1/argocd-admin-prd/custom-values.yaml +++ b/helm-overrides/gke-toolshed-prd-usc1/argocd-admin-prd/custom-values.yaml @@ -82,6 +82,20 @@ argo-cd: enabled: true ingressClassName: contour hostname: "argocd.35.238.248.203.nip.io" + # The chart supports additional hostnames natively, so the new domain + # is served here rather than from a second Ingress object. + extraHosts: + - name: "argocd.infra.deployshed.com" + path: / + # No TLS yet, deliberately. This chart's ingress.tls is a boolean, not + # a host list: turning it on requests ONE certificate covering + # `hostname` plus every extraHost, and Let's Encrypt cannot issue for + # nip.io — so the request would fail and neither name would be served + # over TLS. There is no extraTls to scope it more narrowly. + # + # This one gets its certificate when nip.io is retired and `hostname` + # itself becomes the deployshed.com name. Until then ArgoCD is HTTP + # only, as it already was. resources: requests: cpu: 50m diff --git a/helm-overrides/gke-toolshed-prd-usc1/gitea/custom-values.yaml b/helm-overrides/gke-toolshed-prd-usc1/gitea/custom-values.yaml index 9136a31..eac2d81 100644 --- a/helm-overrides/gke-toolshed-prd-usc1/gitea/custom-values.yaml +++ b/helm-overrides/gke-toolshed-prd-usc1/gitea/custom-values.yaml @@ -80,12 +80,29 @@ gitea: email: "admin@local.lab" # Contour does not exist yet at bootstrap — the Ingress just sits unused - # until ArgoCD installs it. One host only: no Tailscale on GKE. + # until ArgoCD installs it. + # + # Two hosts while the deployment moves onto its own domain. The nip.io one + # stays until everything that references it has been repointed — ROOT_URL + # below, and any git remote anyone has configured. ingress: enabled: true className: contour + annotations: + # Issues the certificate named in tls below. Only the real domain is + # listed there: Let's Encrypt cannot issue for nip.io, and asking for + # one certificate spanning both names returns nothing for either. + cert-manager.io/cluster-issuer: letsencrypt-prod hosts: - host: gitea.35.238.248.203.nip.io paths: - path: / pathType: Prefix + - host: gitea.infra.deployshed.com + paths: + - path: / + pathType: Prefix + tls: + - secretName: gitea-tls + hosts: + - gitea.infra.deployshed.com diff --git a/helm-overrides/gke-toolshed-prd-usc1/grafana/custom-values.yaml b/helm-overrides/gke-toolshed-prd-usc1/grafana/custom-values.yaml index 7f1e51a..b5aacb1 100644 --- a/helm-overrides/gke-toolshed-prd-usc1/grafana/custom-values.yaml +++ b/helm-overrides/gke-toolshed-prd-usc1/grafana/custom-values.yaml @@ -267,6 +267,16 @@ grafana: ingress: enabled: true ingressClassName: contour + annotations: + # Only the real domain appears in tls below — Let's Encrypt cannot + # issue for nip.io, and one certificate spanning both would fail + # outright rather than covering the half it can serve. + cert-manager.io/cluster-issuer: letsencrypt-prod path: / hosts: - grafana.35.238.248.203.nip.io + - grafana.infra.deployshed.com + tls: + - secretName: grafana-tls + hosts: + - grafana.infra.deployshed.com diff --git a/helm-overrides/gke-toolshed-prd-usc1/jenkins/custom-values.yaml b/helm-overrides/gke-toolshed-prd-usc1/jenkins/custom-values.yaml index 60519a2..2514572 100644 --- a/helm-overrides/gke-toolshed-prd-usc1/jenkins/custom-values.yaml +++ b/helm-overrides/gke-toolshed-prd-usc1/jenkins/custom-values.yaml @@ -59,9 +59,29 @@ jenkins: enabled: true hostName: "jenkins.35.238.248.203.nip.io" ingressClassName: contour - # The homelab also enables secondaryingress, purely to serve its - # Tailscale hostname — this chart's primary ingress supports only one - # host. There is one hostname here, so it stays off. + # This chart's primary ingress supports exactly one hostName — no + # extraHosts like argo-cd. secondaryingress renders a whole second + # Ingress object at the same backend, which is the supported way to get + # a second hostname here. + # + # paths must be set explicitly: the template renders zero routes if left + # at the chart's own default of [], unlike the primary ingress, and the + # hostname would then answer nothing at all. + # + # Being a separate Ingress object is what makes the certificate clean — + # it covers this hostname alone, with no nip.io name to drag in. + secondaryingress: + enabled: true + hostName: "jenkins.infra.deployshed.com" + ingressClassName: contour + paths: + - / + annotations: + cert-manager.io/cluster-issuer: letsencrypt-prod + tls: + - secretName: jenkins-tls + hosts: + - jenkins.infra.deployshed.com agent: resources: diff --git a/helm-overrides/gke-toolshed-prd-usc1/vault/custom-values.yaml b/helm-overrides/gke-toolshed-prd-usc1/vault/custom-values.yaml index 0a75940..23abb60 100644 --- a/helm-overrides/gke-toolshed-prd-usc1/vault/custom-values.yaml +++ b/helm-overrides/gke-toolshed-prd-usc1/vault/custom-values.yaml @@ -83,9 +83,18 @@ vault: ingress: enabled: true ingressClassName: contour + annotations: + # Certificate for the real domain only; nip.io cannot have one. + cert-manager.io/cluster-issuer: letsencrypt-prod hosts: - host: "vault.35.238.248.203.nip.io" paths: [] + - host: "vault.infra.deployshed.com" + paths: [] + tls: + - secretName: vault-tls + hosts: + - vault.infra.deployshed.com ui: enabled: true diff --git a/helm-overrides/gke-toolshed-prd-usc1/victoria-metrics-single/custom-values.yaml b/helm-overrides/gke-toolshed-prd-usc1/victoria-metrics-single/custom-values.yaml index 1329505..f897738 100644 --- a/helm-overrides/gke-toolshed-prd-usc1/victoria-metrics-single/custom-values.yaml +++ b/helm-overrides/gke-toolshed-prd-usc1/victoria-metrics-single/custom-values.yaml @@ -25,7 +25,17 @@ victoria-metrics-single: ingress: enabled: true ingressClassName: contour + annotations: + # Certificate for the real domain only; nip.io cannot have one. + cert-manager.io/cluster-issuer: letsencrypt-prod hosts: - name: vm.35.238.248.203.nip.io path: ["/"] port: http + - name: vm.infra.deployshed.com + path: ["/"] + port: http + tls: + - secretName: vm-tls + hosts: + - vm.infra.deployshed.com