Ingress
Kindo’s hosts reach the cluster through your ingress controller and load balancer. You can route them in one of two ways:
- Your own routing. You create the Ingress objects, load-balancer rules, or gateway routes for each host. Print the hosts, backends, ports, and health checks with
kindo ingress manifest. - Kindo-managed ingress. Add an
ingress:block toinstall-contract.yaml, and Kindo creates and manages an Ingress object for every host on each install and upgrade.
Allowlists
Section titled “Allowlists”Kindo-managed ingress puts every host on one load balancer, and OAuth callbacks on integrations-api.<domain> and /webhook on api.<domain> must stay reachable from the internet. An allowlist set in the contract’s ingress.annotations, such as alb.ingress.kubernetes.io/inbound-cidrs, applies to every host and blocks them. If you restrict your load balancer to an allowlist, keep your own routing.
Move to Kindo-managed ingress
Section titled “Move to Kindo-managed ingress”Make this change on its own, in a maintenance window, on an install that is already running its target version.
-
Back up your current Ingress objects.
Terminal window kubectl get ingress -A -o yaml > ingress-backup.yaml -
Add an
ingress:block toinstall-contract.yaml. Set your ingress class, the load-balancer annotations every host shares, and how TLS terminates. For example, with ingress-nginx and cert-manager:ingress:enabled: trueclassName: nginxtls:mode: cert-managerclusterIssuer: <cluster-issuer>With an AWS Application Load Balancer and an ACM certificate:
ingress:enabled: trueclassName: albannotations:alb.ingress.kubernetes.io/group.name: kindo-sharedalb.ingress.kubernetes.io/scheme: internet-facingalb.ingress.kubernetes.io/target-type: ipalb.ingress.kubernetes.io/listen-ports: '[{"HTTPS":443}]'alb.ingress.kubernetes.io/ssl-redirect: '443'tls:mode: acmacmCertificateArn: <certificate-arn>tls.modeisnone,acm,cert-manager, orsecret(one TLS Secret namedsecretNamein every Kindo namespace). -
Preview the hosts. Compare the output with the hosts you serve today:
Terminal window kindo ingress manifest -
Remove your current routing for Kindo’s hosts. If you installed the
kindo-ingresschart, find its release withhelm list -Aand uninstall it:Terminal window helm uninstall kindo-ingress -n <namespace>Otherwise, delete the Ingress objects you created for Kindo’s hosts.
-
Apply the change.
Terminal window kindo upgrade --version <installed-version> --apply -
Check the result. Confirm that
kubectl get ingress -Alists every host, that DNS points at the load balancer, and that each host serves a valid certificate.
To go back, set ingress.enabled: false, run the same kindo upgrade command, and reapply ingress-backup.yaml.
