--- # Real GitLab on the VPS. https-redirect Middleware from the start this # time - see infrastructure/vps-standby/vault/manifests/ingress.yaml for # why it's needed (found live 2026-08-21: Traefik serves plain HTTP # alongside HTTPS unless explicitly redirected, which silently breaks # OIDC login since the callback URL computed client-side won't match # what's registered in Authentik). apiVersion: traefik.io/v1alpha1 kind: Middleware metadata: name: https-redirect namespace: gitlab spec: redirectScheme: scheme: https permanent: true --- apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: vps-gitlab namespace: gitlab annotations: cert-manager.io/cluster-issuer: letsencrypt-production traefik.ingress.kubernetes.io/router.middlewares: gitlab-https-redirect@kubernetescrd spec: ingressClassName: traefik tls: - hosts: - gitlab.vps.huskypup.net secretName: vps-gitlab-tls rules: - host: gitlab.vps.huskypup.net http: paths: - path: / pathType: Prefix backend: service: name: gitlab-webservice-default port: number: 8181