apiVersion: traefik.io/v1alpha1 kind: IngressRoute metadata: name: longhorn-infra-ingress annotations: cert-manager.io/cluster-issuer: vault-issuer spec: entryPoints: - websecure routes: - match: Host(`longhorn.infra.durp.info`) && PathPrefix(`/`) kind: Rule middlewares: - name: authentik-proxy-provider namespace: traefik services: - name: infra-cluster port: 443 tls: secretName: longhorn-infra-tls --- apiVersion: cert-manager.io/v1 kind: Certificate metadata: name: longhorn-infra-tls spec: secretName: longhorn-infra-tls issuerRef: name: vault-issuer kind: ClusterIssuer commonName: "longhorn.infra.durp.info" dnsNames: - "longhorn.infra.durp.info"