<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Ingress :: Tag :: Ay Docs</title>
    <link>https://ops.docs.72602.space/tags/ingress/index.html</link>
    <description></description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Fri, 07 Jun 2024 15:00:59 +0800</lastBuildDate>
    <atom:link href="https://ops.docs.72602.space/tags/ingress/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>72602</title>
      <link>https://ops.docs.72602.space/csp/72602/index.html</link>
      <pubDate>Thu, 07 Mar 2024 15:00:59 +0800</pubDate>
      <guid>https://ops.docs.72602.space/csp/72602/index.html</guid>
      <description>Scope This section is the single source of truth for 72602 cluster operations.&#xA;Topology Public ECS: 47.110.67.161 (2C4G, cn-hangzhou, zone cn-hangzhou-i) Active ingress domain: 72602.space; legacy .72602.online routes are retired ArgoCD host: argocd.72602.space k3s node: 72602-minipc (192.168.0.25, MiniPC N100 28G+1TB NVMe) SSH reverse tunnel: :10021 (main), :10022 (backup and Mailu loopback) Web tunnel: WireGuard UDP 51820 between ECS and minipc Ingress NodePort: 32080 (HTTP), 32443 (HTTPS) Ingress class: nginx Ingress namespace: basic-components cert-manager issuer: lets-encrypt Storage class: local-path (default, RWO) OS: Ubuntu 26.04 LTS (minipc) k3s version: v1.34.6+k3s1 (installed via install.sh) Traffic Path Web:</description>
    </item>
    <item>
      <title>WireGuard Web Tunnel</title>
      <link>https://ops.docs.72602.space/csp/72602/tunnel/wireguard-web/index.html</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://ops.docs.72602.space/csp/72602/tunnel/wireguard-web/index.html</guid>
      <description>WireGuard Web Tunnel 公网 Web 入口固定由 ECS HAProxy 持有，HAProxy 通过 WireGuard 访问 72602-minipc 的 ingress-nginx NodePort。TLS 仍由 ingress-nginx 和 cert-manager 管理；ECS 不复制证书，不启用 PROXY protocol，也不终止 TLS。&#xA;Internet TCP 80/443 -&gt; ECS HAProxy -&gt; primary: WireGuard 10.77.0.1 &lt;-&gt; 10.77.0.2 over UDP 51820 -&gt; minipc TCP 32080/32443 -&gt; ingress-nginx -&gt; backup: ECS-loopback SSH Web path 127.0.0.1:18080/18443 -&gt; minipc TCP 32080/32443 -&gt; ingress-nginx The WireGuard and SSH Web paths are alternative HAProxy backends, not a serial chain. The SSH Web fallback is an independent ECS-loopback service; its host-local unit and credentials are kept in private host state/ ops-private, not reproduced in this repository.</description>
    </item>
    <item>
      <title>Install Ingress</title>
      <link>https://ops.docs.72602.space/installation/networking/ingress/index.html</link>
      <pubDate>Fri, 07 Jun 2024 15:00:59 +0800</pubDate>
      <guid>https://ops.docs.72602.space/installation/networking/ingress/index.html</guid>
      <description>Installation Install By Helm ArgoCD Preliminary 1. Kubernetes is installed; if not, check 🔗link 2. Helm is installed; if not, check 🔗link 1.get helm repo Details helm repo add ingress-nginx https://kubernetes.github.io/ingress-nginx helm repo update 2.install chart Details helm install ingress-nginx/ingress-nginx --generate-name Using Mirror helm repo add ay-helm-mirror https://aaronyang0628.github.io/helm-chart-mirror/charts &amp;&amp; helm install ay-helm-mirror/ingress-nginx --generate-name --version 4.15.1 for more information, you can check 🔗https://aaronyang0628.github.io/helm-chart-mirror/</description>
    </item>
  </channel>
</rss>