Serve the infra tools on the real domain as well as nip.io

Each of these now answers on <name>.infra.deployshed.com alongside the
nip.io name it already had. Both are kept on purpose: nothing that
currently references the old name breaks, and the new one can be proved
before anything depends on it. Removing nip.io is a separate step, and a
larger one, because Harbor's name is embedded in every running app's image
reference.

TLS covers the real domain only. Let's Encrypt cannot issue for nip.io —
it is not on the public suffix list and every *.nip.io certificate shares
one rate limit — so a tls block naming both would request one certificate
spanning them and receive nothing for either. Each tls block therefore
lists exactly the one new hostname, which is why they are written out
rather than derived from the host list beside them.

The charts disagree about how to express a second host, so each is done
the way its own chart supports:

  gitea, grafana, vault, victoria-metrics-single take host lists, so the
  new name joins the existing one on a single Ingress.

  jenkins' primary ingress accepts exactly one hostName, so the new name
  goes on secondaryingress — a whole second Ingress object at the same
  backend. paths must be set explicitly there; left at the chart's default
  of [] it renders zero routes and the hostname answers nothing.

  argo-cd takes extraHosts natively, but its ingress.tls is a boolean bound
  to one fixed secret covering every host at once. Turning it on would
  request a certificate including nip.io and fail, and there is no extraTls
  to scope it. So ArgoCD gains the hostname now and its certificate when
  nip.io goes.

Harbor is untouched here. It has no multi-host mechanism at all, so its
second hostname needs a standalone Ingress, and its externalURL is what
docker clients are handed — both deserve their own change rather than
riding along with a hostname tidy-up.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LEsTefWWifp4ikvhHF5s6N
This commit is contained in:
Mukul Sharma
2026-09-17 02:14:30 +05:30
co-authored by Claude Opus 5
parent 73ddfd8534
commit f703f0b55a
6 changed files with 84 additions and 4 deletions
@@ -59,9 +59,29 @@ jenkins:
enabled: true
hostName: "jenkins.35.238.248.203.nip.io"
ingressClassName: contour
# The homelab also enables secondaryingress, purely to serve its
# Tailscale hostname — this chart's primary ingress supports only one
# host. There is one hostname here, so it stays off.
# This chart's primary ingress supports exactly one hostName — no
# extraHosts like argo-cd. secondaryingress renders a whole second
# Ingress object at the same backend, which is the supported way to get
# a second hostname here.
#
# paths must be set explicitly: the template renders zero routes if left
# at the chart's own default of [], unlike the primary ingress, and the
# hostname would then answer nothing at all.
#
# Being a separate Ingress object is what makes the certificate clean —
# it covers this hostname alone, with no nip.io name to drag in.
secondaryingress:
enabled: true
hostName: "jenkins.infra.deployshed.com"
ingressClassName: contour
paths:
- /
annotations:
cert-manager.io/cluster-issuer: letsencrypt-prod
tls:
- secretName: jenkins-tls
hosts:
- jenkins.infra.deployshed.com
agent:
resources: