Ingress & TLS

Every public route in this fleet goes through Traefik, the ingress controller bundled with K3s. There’s no separate Ingress resource and no cert-manager anywhere in this org — Traefik handles routing and requests its own TLS certificates automatically.

How it’s configured

Traefik ships as part of K3s and is tuned with a small configuration overlay rather than a separate install. Two things matter operationally: certificates are requested and renewed automatically (no manual renewal step, ever), and because every application lives in its own namespace (see Namespaces & Apps) while the shared login gate lives in one central namespace, Traefik is explicitly allowed to reference resources across namespace boundaries.

Every protected route ships as two routes, not one

A subtle Traefik behavior — combining the secure and plain-HTTP versions of a route into a single object can silently break the plain-HTTP side, even though it looks correctly configured. The fix, applied everywhere without exception: every protected app gets two separate route objects, one for HTTPS (carrying the login gate) and one that only redirects plain HTTP to HTTPS. Every app in this fleet — the dashboard, this documentation site, and the rest — follows this same shape.

DNS has to exist first

There’s no wildcard DNS record for this domain — every new subdomain is added individually. A new route for a hostname with no matching DNS record will fail to get a certificate, since the certificate authority has to be able to reach it first. See Secrets & DNS for how DNS is managed.