lade...
random avatar

arch - Network

Posts Subscribe

kubernetes is dumb and i can't stop using it

https://floofy.tech/@arch/114236...

kubernetes is dumb and i can't stop using it

27.3.2025 19:25kubernetes is dumb and i can't stop using it
https://floofy.tech/@arch/114236...

Wonder if it’s worth doing the TLS termination on the HAProxy side rather than the cluster side.

https://floofy.tech/@arch/114234...

Wonder if it’s worth doing the TLS termination on the HAProxy side rather than the cluster side.

27.3.2025 14:56Wonder if it’s worth doing the TLS termination on the HAProxy side rather than the cluster side.
https://floofy.tech/@arch/114234...

Hehehe yes

https://floofy.tech/@arch/114234...

Hehehe yes

27.3.2025 10:48Hehehe yes
https://floofy.tech/@arch/114234...

Fellow Kubernetes admins - do you also use wildcards, or just let cert-manager provision a cert per-domain/subdomain?#kubernetes #kubeadmin

https://floofy.tech/@arch/114233...

Fellow Kubernetes admins - do you also use wildcards, or just let cert-manager provision a cert per-domain/subdomain?

27.3.2025 09:25Fellow Kubernetes admins - do you also use wildcards, or just let cert-manager provision a cert per-domain/subdomain?#kubernetes #kubeadmin
https://floofy.tech/@arch/114233...

This is both hilarious and sad (https://projectcontour.io/resources/faq/).I might swap back to per-subdomain certificates anyways, but I...

https://floofy.tech/@arch/114233...

This is both hilarious and sad (projectcontour.io/resources/fa).

I might swap back to per-subdomain certificates anyways, but I really like the idea of having the single wildcard for *.gmem.ca in my cluster.

27.3.2025 09:23This is both hilarious and sad (https://projectcontour.io/resources/faq/).I might swap back to per-subdomain certificates anyways, but I...
https://floofy.tech/@arch/114233...

The Contour commit. Bit hefty, some cleanup to do on the repo, but I need sleep...

https://floofy.tech/@arch/114231...

:sweat2: The Contour commit. Bit hefty, some cleanup to do on the repo, but I need sleep git.gmem.ca/arch/infra/commit/

26.3.2025 23:31 The Contour commit. Bit hefty, some cleanup to do on the repo, but I need sleep...
https://floofy.tech/@arch/114231...

Dangit I restarted Discord and it updated.

https://floofy.tech/@arch/114230...

Dangit I restarted Discord and it updated.

26.3.2025 21:08Dangit I restarted Discord and it updated.
https://floofy.tech/@arch/114230...

k8s-ci-robot and fejta-bot are the worst things to see on a Kubernetes GitHub issue.

https://floofy.tech/@arch/114230...

k8s-ci-robot and fejta-bot are the worst things to see on a Kubernetes GitHub issue.

26.3.2025 19:35k8s-ci-robot and fejta-bot are the worst things to see on a Kubernetes GitHub issue.
https://floofy.tech/@arch/114230...

[starts writing api docs]idk its just like, vibes

https://floofy.tech/@arch/114230...

[starts writing api docs]

idk its just like, vibes

26.3.2025 18:25[starts writing api docs]idk its just like, vibes
https://floofy.tech/@arch/114230...

Anyways, I mildly brute forced it but I’ve swapped to Contour (and Envoy) as my Kubernetes ingress controller. Or rather, my Gatway API...

https://floofy.tech/@arch/114229...

Anyways, I mildly brute forced it but I’ve swapped to Contour (and Envoy) as my Kubernetes ingress controller. Or rather, my Gatway API controller.

26.3.2025 17:47Anyways, I mildly brute forced it but I’ve swapped to Contour (and Envoy) as my Kubernetes ingress controller. Or rather, my Gatway API...
https://floofy.tech/@arch/114229...

oh god oh no contour can produce a graph

https://floofy.tech/@arch/114229...

oh god oh no contour can produce a graph

26.3.2025 17:32oh god oh no contour can produce a graph
https://floofy.tech/@arch/114229...

Me, wondering why one of my self hosted services randomly 503s.The Kubernetes service with a selector that has also selected the Valkey...

https://floofy.tech/@arch/114229...

Me, wondering why one of my self hosted services randomly 503s.

The Kubernetes service with a selector that has also selected the Valkey instance: hehe

26.3.2025 17:18Me, wondering why one of my self hosted services randomly 503s.The Kubernetes service with a selector that has also selected the Valkey...
https://floofy.tech/@arch/114229...

you have observed this posti hope it was enjoyable

https://floofy.tech/@arch/114229...

you have observed this post

i hope it was enjoyable

26.3.2025 17:02you have observed this posti hope it was enjoyable
https://floofy.tech/@arch/114229...

Traefik has also somehow managed to defeat me.How is it proving so hard to just drop in another ingress controller? Having all sorts of...

https://floofy.tech/@arch/114228...

Traefik has also somehow managed to defeat me.

How is it proving so hard to just drop in another ingress controller? Having all sorts of issues :floofWoozy: Both Envoy and Traefik randomly 502 some of my services, or mess up HAProxy for whatever reason. I can't tell if this is because I'm trying to swap to a service NodePort from my ingress-nginx host networking or what.

Uugh. Whatever. I'll put it back down for now. I'm annoyed :P

26.3.2025 11:53Traefik has also somehow managed to defeat me.How is it proving so hard to just drop in another ingress controller? Having all sorts of...
https://floofy.tech/@arch/114228...

Contour/Envoy also randomly 503s requests and I can't figure out why.Blegh. I'm tired. Bed.

https://floofy.tech/@arch/114225...

Contour/Envoy also randomly 503s requests and I can't figure out why.

Blegh. I'm tired. Bed.

25.3.2025 22:33Contour/Envoy also randomly 503s requests and I can't figure out why.Blegh. I'm tired. Bed.
https://floofy.tech/@arch/114225...

I have been defeated by both Istio and Contour tonight. Mildly tempted to poke around Traefik but maybe that'll be a tomorrow thing.I get...

https://floofy.tech/@arch/114225...

I have been defeated by both Istio and Contour tonight. Mildly tempted to poke around Traefik but maybe that'll be a tomorrow thing.

I get why wildcard certs aren't common in Kubernetes clusters, but, like, it should be possible.

25.3.2025 21:35I have been defeated by both Istio and Contour tonight. Mildly tempted to poke around Traefik but maybe that'll be a tomorrow thing.I get...
https://floofy.tech/@arch/114225...

It doesn't error out, it simply doesn't serve a cert.https://paste.gmem.ca/paste/a257ed27-3ad0-4782-a61c-c238b37e2450/raw

https://floofy.tech/@arch/114224...

It doesn't error out, it simply doesn't serve a cert.

paste.gmem.ca/paste/a257ed27-3

25.3.2025 19:00It doesn't error out, it simply doesn't serve a cert.https://paste.gmem.ca/paste/a257ed27-3ad0-4782-a61c-c238b37e2450/raw
https://floofy.tech/@arch/114224...

So what I'm learning:Despite doing everything I can with TLSCertificateDelegation, projectcontour.io/tls-cert-namespace and whatever else, I...

https://floofy.tech/@arch/114224...

So what I'm learning:

Despite doing everything I can with TLSCertificateDelegation, projectcontour.io/tls-cert-namespace and whatever else, I can't get Contour to use my wildcard cert (cert-manager/gmem-ca-wildcard) for my ingresses since the cert SAN doesn't exactly match the tls.hosts entries in my ingress?

:floofTired: Was really hoping to find something drop-in so I could migrate to Gateway API as I needed/wanted. Not super interested in using the HTTProxy CRD :/

25.3.2025 18:57So what I'm learning:Despite doing everything I can with TLSCertificateDelegation, projectcontour.io/tls-cert-namespace and whatever else, I...
https://floofy.tech/@arch/114224...

curl: (35) TLS connect error: error:0A0000C6:SSL routines::packet length too long(╯°□°)╯︵ ┻━┻

https://floofy.tech/@arch/114224...

curl: (35) TLS connect error: error:0A0000C6:SSL routines::packet length too long

(╯°□°)╯︵ ┻━┻

25.3.2025 17:44curl: (35) TLS connect error: error:0A0000C6:SSL routines::packet length too long(╯°□°)╯︵ ┻━┻
https://floofy.tech/@arch/114224...

um, help??

https://floofy.tech/@arch/114222...

um, help??

25.3.2025 10:28um, help??
https://floofy.tech/@arch/114222...
Subscribe
To add news/posts to your profile here, you must add a link to a RSS-Feed to your webfinger. One example how you can do this is to join Fediverse City.
         
Webfan Website Badge
Nutzungsbedingungen   Datenschutzerklärung  Impressum
Webfan | @Web pages | Fediverse Members