contour: # GKE counterpart of the homelab's contour override (k8s-admin-prd-ase1, # in the homelab devops-infra-helm-charts repo). Same official projectcontour chart (0.7.0, see helm-templates/contour), but # exposed the opposite way. # # The homelab binds Envoy to node ports 80/443 with hostPort, because # VMware bridging over Wi-Fi never made a LoadBalancer IP reachable # (claude.md issue #6). None of that applies here: this is a real cloud # load balancer on the reserved address, and it is the ONE inbound path # into the cluster now that the nodes have no public IPs of their own. contour: replicaCount: 1 # Ingress objects across this cluster say `ingressClassName: contour`, # so the class must be created under exactly that name. The chart's # default is an empty string, which derives a name from the release. ingressClass: name: contour create: true default: true resources: requests: cpu: 50m memory: 64Mi limits: memory: 192Mi envoy: # DaemonSet (the chart default): one Envoy per node, which pairs with # externalTrafficPolicy: Local below — every node the load balancer can # send to is running a proxy that can serve the request locally. kind: daemonset service: type: LoadBalancer # The reserved address from Terraform (module.network's # google_compute_address). Every hostname in this deployment — the # deployshed.com records, including the two wildcards — resolves here, # so this pin is what makes DNS work at all: an unpinned Service takes # a fresh ephemeral IP and every hostname points at nothing. # # More load-bearing now, not less, than when hostnames were # .35.238.248.203.nip.io. Those encoded the address, so a changed # IP produced names that were merely wrong. Real DNS records point here # until somebody edits them in Cloudflare, so a changed IP is an # outage across every hostname at once. # # spec.loadBalancerIP is deprecated upstream (Kubernetes 1.24), and # GKE's replacement is the annotation # networking.gke.io/load-balancer-ip-addresses. That annotation is NOT # a drop-in: it takes the address resource's NAME rather than the # address, and on an external Service it also requires # spec.loadBalancerClass: networking.gke.io/l4-regional-external, # which changes which controller programs the load balancer. GKE still # honours this field, so the deprecated-but-working one is the smaller # change; revisit if a GKE upgrade ever stops honouring it. loadBalancerIP: "35.238.248.203" # Chart default, kept deliberately: preserves the real client IP # instead of replacing it with a node's address. Valid here precisely # because Envoy is a DaemonSet. externalTrafficPolicy: Local resources: requests: cpu: 50m memory: 96Mi limits: memory: 256Mi