From f703f0b55a7884b6c3142522d2266512081bde40 Mon Sep 17 00:00:00 2001 From: Mukul Sharma Date: Thu, 17 Sep 2026 02:14:30 +0530 Subject: [PATCH] Serve the infra tools on the real domain as well as nip.io MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Each of these now answers on .infra.deployshed.com alongside the nip.io name it already had. Both are kept on purpose: nothing that currently references the old name breaks, and the new one can be proved before anything depends on it. Removing nip.io is a separate step, and a larger one, because Harbor's name is embedded in every running app's image reference. TLS covers the real domain only. Let's Encrypt cannot issue for nip.io — it is not on the public suffix list and every *.nip.io certificate shares one rate limit — so a tls block naming both would request one certificate spanning them and receive nothing for either. Each tls block therefore lists exactly the one new hostname, which is why they are written out rather than derived from the host list beside them. The charts disagree about how to express a second host, so each is done the way its own chart supports: gitea, grafana, vault, victoria-metrics-single take host lists, so the new name joins the existing one on a single Ingress. jenkins' primary ingress accepts exactly one hostName, so the new name goes on secondaryingress — a whole second Ingress object at the same backend. paths must be set explicitly there; left at the chart's default of [] it renders zero routes and the hostname answers nothing. argo-cd takes extraHosts natively, but its ingress.tls is a boolean bound to one fixed secret covering every host at once. Turning it on would request a certificate including nip.io and fail, and there is no extraTls to scope it. So ArgoCD gains the hostname now and its certificate when nip.io goes. Harbor is untouched here. It has no multi-host mechanism at all, so its second hostname needs a standalone Ingress, and its externalURL is what docker clients are handed — both deserve their own change rather than riding along with a hostname tidy-up. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01LEsTefWWifp4ikvhHF5s6N --- .../argocd-admin-prd/custom-values.yaml | 14 ++++++++++ .../gitea/custom-values.yaml | 19 +++++++++++++- .../grafana/custom-values.yaml | 10 +++++++ .../jenkins/custom-values.yaml | 26 ++++++++++++++++--- .../vault/custom-values.yaml | 9 +++++++ .../custom-values.yaml | 10 +++++++ 6 files changed, 84 insertions(+), 4 deletions(-) diff --git a/helm-overrides/gke-toolshed-prd-usc1/argocd-admin-prd/custom-values.yaml b/helm-overrides/gke-toolshed-prd-usc1/argocd-admin-prd/custom-values.yaml index 7889b1c..f4f1ef2 100644 --- a/helm-overrides/gke-toolshed-prd-usc1/argocd-admin-prd/custom-values.yaml +++ b/helm-overrides/gke-toolshed-prd-usc1/argocd-admin-prd/custom-values.yaml @@ -82,6 +82,20 @@ argo-cd: enabled: true ingressClassName: contour hostname: "argocd.35.238.248.203.nip.io" + # The chart supports additional hostnames natively, so the new domain + # is served here rather than from a second Ingress object. + extraHosts: + - name: "argocd.infra.deployshed.com" + path: / + # No TLS yet, deliberately. This chart's ingress.tls is a boolean, not + # a host list: turning it on requests ONE certificate covering + # `hostname` plus every extraHost, and Let's Encrypt cannot issue for + # nip.io — so the request would fail and neither name would be served + # over TLS. There is no extraTls to scope it more narrowly. + # + # This one gets its certificate when nip.io is retired and `hostname` + # itself becomes the deployshed.com name. Until then ArgoCD is HTTP + # only, as it already was. resources: requests: cpu: 50m diff --git a/helm-overrides/gke-toolshed-prd-usc1/gitea/custom-values.yaml b/helm-overrides/gke-toolshed-prd-usc1/gitea/custom-values.yaml index 9136a31..eac2d81 100644 --- a/helm-overrides/gke-toolshed-prd-usc1/gitea/custom-values.yaml +++ b/helm-overrides/gke-toolshed-prd-usc1/gitea/custom-values.yaml @@ -80,12 +80,29 @@ gitea: email: "admin@local.lab" # Contour does not exist yet at bootstrap — the Ingress just sits unused - # until ArgoCD installs it. One host only: no Tailscale on GKE. + # until ArgoCD installs it. + # + # Two hosts while the deployment moves onto its own domain. The nip.io one + # stays until everything that references it has been repointed — ROOT_URL + # below, and any git remote anyone has configured. ingress: enabled: true className: contour + annotations: + # Issues the certificate named in tls below. Only the real domain is + # listed there: Let's Encrypt cannot issue for nip.io, and asking for + # one certificate spanning both names returns nothing for either. + cert-manager.io/cluster-issuer: letsencrypt-prod hosts: - host: gitea.35.238.248.203.nip.io paths: - path: / pathType: Prefix + - host: gitea.infra.deployshed.com + paths: + - path: / + pathType: Prefix + tls: + - secretName: gitea-tls + hosts: + - gitea.infra.deployshed.com diff --git a/helm-overrides/gke-toolshed-prd-usc1/grafana/custom-values.yaml b/helm-overrides/gke-toolshed-prd-usc1/grafana/custom-values.yaml index 7f1e51a..b5aacb1 100644 --- a/helm-overrides/gke-toolshed-prd-usc1/grafana/custom-values.yaml +++ b/helm-overrides/gke-toolshed-prd-usc1/grafana/custom-values.yaml @@ -267,6 +267,16 @@ grafana: ingress: enabled: true ingressClassName: contour + annotations: + # Only the real domain appears in tls below — Let's Encrypt cannot + # issue for nip.io, and one certificate spanning both would fail + # outright rather than covering the half it can serve. + cert-manager.io/cluster-issuer: letsencrypt-prod path: / hosts: - grafana.35.238.248.203.nip.io + - grafana.infra.deployshed.com + tls: + - secretName: grafana-tls + hosts: + - grafana.infra.deployshed.com diff --git a/helm-overrides/gke-toolshed-prd-usc1/jenkins/custom-values.yaml b/helm-overrides/gke-toolshed-prd-usc1/jenkins/custom-values.yaml index 60519a2..2514572 100644 --- a/helm-overrides/gke-toolshed-prd-usc1/jenkins/custom-values.yaml +++ b/helm-overrides/gke-toolshed-prd-usc1/jenkins/custom-values.yaml @@ -59,9 +59,29 @@ jenkins: enabled: true hostName: "jenkins.35.238.248.203.nip.io" ingressClassName: contour - # The homelab also enables secondaryingress, purely to serve its - # Tailscale hostname — this chart's primary ingress supports only one - # host. There is one hostname here, so it stays off. + # This chart's primary ingress supports exactly one hostName — no + # extraHosts like argo-cd. secondaryingress renders a whole second + # Ingress object at the same backend, which is the supported way to get + # a second hostname here. + # + # paths must be set explicitly: the template renders zero routes if left + # at the chart's own default of [], unlike the primary ingress, and the + # hostname would then answer nothing at all. + # + # Being a separate Ingress object is what makes the certificate clean — + # it covers this hostname alone, with no nip.io name to drag in. + secondaryingress: + enabled: true + hostName: "jenkins.infra.deployshed.com" + ingressClassName: contour + paths: + - / + annotations: + cert-manager.io/cluster-issuer: letsencrypt-prod + tls: + - secretName: jenkins-tls + hosts: + - jenkins.infra.deployshed.com agent: resources: diff --git a/helm-overrides/gke-toolshed-prd-usc1/vault/custom-values.yaml b/helm-overrides/gke-toolshed-prd-usc1/vault/custom-values.yaml index 0a75940..23abb60 100644 --- a/helm-overrides/gke-toolshed-prd-usc1/vault/custom-values.yaml +++ b/helm-overrides/gke-toolshed-prd-usc1/vault/custom-values.yaml @@ -83,9 +83,18 @@ vault: ingress: enabled: true ingressClassName: contour + annotations: + # Certificate for the real domain only; nip.io cannot have one. + cert-manager.io/cluster-issuer: letsencrypt-prod hosts: - host: "vault.35.238.248.203.nip.io" paths: [] + - host: "vault.infra.deployshed.com" + paths: [] + tls: + - secretName: vault-tls + hosts: + - vault.infra.deployshed.com ui: enabled: true diff --git a/helm-overrides/gke-toolshed-prd-usc1/victoria-metrics-single/custom-values.yaml b/helm-overrides/gke-toolshed-prd-usc1/victoria-metrics-single/custom-values.yaml index 1329505..f897738 100644 --- a/helm-overrides/gke-toolshed-prd-usc1/victoria-metrics-single/custom-values.yaml +++ b/helm-overrides/gke-toolshed-prd-usc1/victoria-metrics-single/custom-values.yaml @@ -25,7 +25,17 @@ victoria-metrics-single: ingress: enabled: true ingressClassName: contour + annotations: + # Certificate for the real domain only; nip.io cannot have one. + cert-manager.io/cluster-issuer: letsencrypt-prod hosts: - name: vm.35.238.248.203.nip.io path: ["/"] port: http + - name: vm.infra.deployshed.com + path: ["/"] + port: http + tls: + - secretName: vm-tls + hosts: + - vm.infra.deployshed.com