Skip to content

Ingress

Kindo’s hosts reach the cluster through your ingress controller and load balancer. You can route them in one of two ways:

  • Your own routing. You create the Ingress objects, load-balancer rules, or gateway routes for each host. Print the hosts, backends, ports, and health checks with kindo ingress manifest.
  • Kindo-managed ingress. Add an ingress: block to install-contract.yaml, and Kindo creates and manages an Ingress object for every host on each install and upgrade.

Kindo-managed ingress puts every host on one load balancer, and OAuth callbacks on integrations-api.<domain> and /webhook on api.<domain> must stay reachable from the internet. An allowlist set in the contract’s ingress.annotations, such as alb.ingress.kubernetes.io/inbound-cidrs, applies to every host and blocks them. If you restrict your load balancer to an allowlist, keep your own routing.

Make this change on its own, in a maintenance window, on an install that is already running its target version.

  1. Back up your current Ingress objects.

    Terminal window
    kubectl get ingress -A -o yaml > ingress-backup.yaml
  2. Add an ingress: block to install-contract.yaml. Set your ingress class, the load-balancer annotations every host shares, and how TLS terminates. For example, with ingress-nginx and cert-manager:

    ingress:
    enabled: true
    className: nginx
    tls:
    mode: cert-manager
    clusterIssuer: <cluster-issuer>

    With an AWS Application Load Balancer and an ACM certificate:

    ingress:
    enabled: true
    className: alb
    annotations:
    alb.ingress.kubernetes.io/group.name: kindo-shared
    alb.ingress.kubernetes.io/scheme: internet-facing
    alb.ingress.kubernetes.io/target-type: ip
    alb.ingress.kubernetes.io/listen-ports: '[{"HTTPS":443}]'
    alb.ingress.kubernetes.io/ssl-redirect: '443'
    tls:
    mode: acm
    acmCertificateArn: <certificate-arn>

    tls.mode is none, acm, cert-manager, or secret (one TLS Secret named secretName in every Kindo namespace).

  3. Preview the hosts. Compare the output with the hosts you serve today:

    Terminal window
    kindo ingress manifest
  4. Remove your current routing for Kindo’s hosts. If you installed the kindo-ingress chart, find its release with helm list -A and uninstall it:

    Terminal window
    helm uninstall kindo-ingress -n <namespace>

    Otherwise, delete the Ingress objects you created for Kindo’s hosts.

  5. Apply the change.

    Terminal window
    kindo upgrade --version <installed-version> --apply
  6. Check the result. Confirm that kubectl get ingress -A lists every host, that DNS points at the load balancer, and that each host serves a valid certificate.

To go back, set ingress.enabled: false, run the same kindo upgrade command, and reapply ingress-backup.yaml.