--- # See infrastructure/vps-standby/vault/manifests/ingress.yaml for the # vps.huskypup.net subdomain design rationale, and for why this # https-redirect Middleware is needed (found live 2026-08-21 diagnosing # the exact same "Missing auth_url"-shaped symptom on Vault's OIDC login - # applies equally to every VPS-standby app on this Traefik). # # CAVEAT: Authentik's provider/application configs (redirect_uris, etc.) # are replicated byte-for-byte from home and point at *.kube.huskypup.net # - SSO logins between VPS-hosted apps and this VPS Authentik instance # won't complete correctly (redirect mismatch) until that's addressed # separately. Direct/local Authentik admin login still works fine for # browsing and verifying replicated data. apiVersion: traefik.io/v1alpha1 kind: Middleware metadata: name: https-redirect namespace: authentik spec: redirectScheme: scheme: https permanent: true --- apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: vps-authentik namespace: authentik annotations: cert-manager.io/cluster-issuer: letsencrypt-production traefik.ingress.kubernetes.io/router.middlewares: authentik-https-redirect@kubernetescrd spec: ingressClassName: traefik tls: - hosts: - auth.vps.huskypup.net secretName: vps-authentik-tls rules: - host: auth.vps.huskypup.net http: paths: - path: / pathType: Prefix backend: service: name: vps-authentik-server port: number: 80