baae9b289a
Traefik has no certificate resolver named 'letsencrypt' configured (this
cluster terminates TLS at Cloudflare and uses Traefik's default cert via
the websecure entrypoint, matching every other neuron-prod IngressRoute).
The invalid certResolver caused Traefik to refuse the router with:
ERR Router uses a nonexistent certificate resolver
certificateResolver=letsencrypt routerName=neuron-prod-dharma-...
so requests to dharma.neurontechnologies.ai/health surfaced as 502 from
Cloudflare even though the dharma pod was healthy on :8765.
20 lines
527 B
YAML
20 lines
527 B
YAML
apiVersion: traefik.io/v1alpha1
|
|
kind: IngressRoute
|
|
metadata:
|
|
name: dharma
|
|
namespace: neuron-prod
|
|
labels:
|
|
app: dharma
|
|
spec:
|
|
entryPoints:
|
|
- websecure
|
|
routes:
|
|
- match: Host(`dharma.neurontechnologies.ai`)
|
|
kind: Rule
|
|
services:
|
|
- name: dharma
|
|
port: 8765
|
|
# TLS terminates at Cloudflare; tunnel reaches Traefik with noTLSVerify.
|
|
# Traefik websecure entrypoint has its own default cert (no resolver
|
|
# configured in this cluster), matching every other neuron-prod IngressRoute.
|