Deploys Traefik Ingress into a Kubernetes cluster via Helm.
Once you have a Corewide Solutions Portal account, this one-time action will use your browser session to retrieve credentials:
shellterraform login solutions.corewide.com
Initialize mandatory providers:
Copy and paste into your Terraform configuration and insert the variables:
hclmodule "tf_k8s_ingress_traefik" {
source = "solutions.corewide.com/kubernetes/tf-k8s-ingress-traefik/helm"
version = "~> 2.1.0"
# specify module inputs here or try one of the examples below
...
}
Initialize the setup:
shellterraform init
Corewide DevOps team strictly follows Semantic Versioning
Specification
to
provide our clients with products that have predictable upgrades between versions. We
recommend
pinning
patch versions of our modules using pessimistic
constraint operator (~>) to prevent breaking changes during upgrades.
To get new features during the upgrades (without breaking compatibility), use
~> 2.1 and run
terraform init -upgrade
For the safest setup, use strict pinning with version = "2.1.0"
|
Module
45% off
|
$302
|
| TOTAL | $540 |
| tf-k8s-cert-manager | $192 |
| tf-k8s-crd | $45 |
Deploys Traefik Ingress into a Kubernetes cluster via Helm.
All notable changes to this project are documented here.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
traefik_ingress.ingress_class_name variable (traefik by default)41.0.0 and newer)chart_version parameter for the traefik_ingress variable to control the version of Traefik Helm chart32.1.0 to 41.0.21.17.1 to 1.21.0tf-k8s-cert-manager module dependency from 2.0 to 2.1kubectl apply step requiredcert_manager.version variable in favor of cert_manager.chart_version and will be deleted in v2.4traefik_ingress.version variable in favor of traefik_ingress.chart_version and will be deleted in v2.43.03.1custom_values variable to be supplied as a single block with all subparameters instead of a set of mapstf-k8s-cert-manager module dependency from 1.1 to 2.0(Last version compatible with the Helm and the Kubernetes Terraform providers version 2.0)
k8s_flavor variableingress_class output returning incorrect valueingressClass name (ingress_class)ingressClass.name from traefik-ingress to traefikhelm_timeout parameter for traefik_ingress variable to configure deployment timeout of its Helm releaseFirst stable version
v1.x to v2.xModule from v2.0 has several management changes that require attention:
```hcl
terraform {
required_providers {
helm = {
source = "hashicorp/helm"
version = "~> 3.1"
}
text kubernetes = {
source = "hashicorp/kubernetes"
version = "~> 3.0"
}
}
}
```
Upgrade project dependencies:
bash
terraform init --upgrade
Before:
hcl
module "ingress" {
...
custom_values = [
{
name = "image.pullPolicy"
value = "Always"
},
{
name = "commonLabels.project"
value = "example"
},
]
...
}
After:
```hcl
module "ingress" {
...
custom_values = {
image = {
pullPolicy = "Always"
}
text commonLabels = {
project = "example"
}
}
...
}
```
tf-k8s-cert-manager module dependency from 1.1 to 2.0. Refer to the changelog and upgrade notes of the tf-k8s-cert-manager moduleApply the changes to make sure the state of the resources is up-to-date with the new provider version:
bashterraform apply
v2.0.x to v2.1.xModule from v2.1 has several adjustments that require attention:
Traefik Ingress Helm release was reconfigured to install and upgrade CRDs together with the Traefik Helm chart without manual kubectl apply step required
Traefik default Helm chart version is updated from 32.1.0 to 41.0.2. Traefik minimal Helm chart version is set to 41.0.0, which introduces breaking changes, follow the Traefik Helm chart changelog if any custom Helm chart-related configurations are applied
Traefik Ingress controller version is inherited from the Traefik Helm chart and is updated from 3.1.5 (default in 32.1.0 Helm chart) to 3.7.8 (default in 32.1.0 Helm chart). Follow the Traefik migration guide if any custom Traefik controller-related configurations are applied
Updated version of the tf-k8s-cert-manager module dependency from 2.0 to 2.1. Refer to the changelog and upgrade notes of the tf-k8s-cert-manager module
cert-manager Helm chart default version is updated to 1.21.0. You can skip this chapter if you have already used cert-manager Helm chart version 1.21.0 or newer
Update the declaration of the module according to the requirements and examples to match the designed configuration.
Now the configuration can be applied:
bashterraform apply
Deploy Traefik Ingress for Kubernetes with cert-manager and required parameters only:
hclmodule "ingress" {
source = "solutions.corewide.com/kubernetes/tf-k8s-ingress-traefik/helm"
version = "~> 2.1"
acme_email = "[email protected]"
}
Deploy Ingress Nginx with mandatory parameters and cert-manager's AWS Route53 integration for DNS-01 challenge. AWS Route53 RBAC configured with tf-k8s-cert-manager-dns-aws module and EKS cluster deployed with tf-aws-k8s-eks module:
hclmodule "ingress" {
source = "solutions.corewide.com/kubernetes/tf-k8s-ingress-traefik/helm"
version = "~> 2.1"
acme_email = "[email protected]"
cert_manager = {
chart_version = "1.21.0"
dns_solver_config = module.aws_cert_manager_iam.issuer_spec
service_account_annotations = module.aws_cert_manager_iam.service_account_annotation
}
}
module "eks" {
source = "solutions.corewide.com/aws/tf-aws-k8s-eks/aws"
version = "~> 8.0"
# ...
}
module "aws_cert_manager_iam" {
source = "solutions.corewide.com/aws/tf-k8s-cert-manager-dns-aws/aws"
version = "~> 2.0"
region = "us-east-1"
hosted_zone_id = "FOO"
oidc_provider_arn = module.eks.eks_identity_provider.arn
oidc_provider_url = module.eks.eks_identity_provider.url
}
Deploy Ingress Nginx with mandatory parameters and cert-manager's Google Cloud DNS integration for DNS-01 challenge. Google Cloud DNS RBAC configured with tf-k8s-cert-manager-dns-gcp module:
hclmodule "ingress" {
source = "solutions.corewide.com/kubernetes/tf-k8s-ingress-traefik/helm"
version = "~> 2.1"
acme_email = "[email protected]"
cert_manager = {
chart_version = "1.21.0"
dns_solver_config = module.gcp_cert_manager_iam.issuer_spec
service_account_annotations = module.gcp_cert_manager_iam.service_account_annotation
}
}
module "gcp_cert_manager_iam" {
source = "solutions.corewide.com/google-cloud/tf-k8s-cert-manager-dns-gcp/google"
version = "~> 2.0"
}
Deploy Ingress Nginx with mandatory parameters and cert-manager's Azure DNS integration for DNS-01 challenge. Azure DNS RBAC configured with tf-k8s-cert-manager-dns-azure module and AKS cluster deployed with tf-azure-k8s-aks module:
hclmodule "ingress" {
source = "solutions.corewide.com/kubernetes/tf-k8s-ingress-traefik/helm"
version = "~> 2.1"
acme_email = "[email protected]"
cert_manager = {
chart_version = "1.21.0"
dns_solver_config = module.azure_cert_manager_iam.issuer_spec
pod_labels = module.azure_cert_manager_iam.pod_label
service_account_labels = module.azure_cert_manager_iam.service_account_label
}
}
resource "azurerm_resource_group" "main" {
name = "foo"
location = "westus2"
}
module "aks" {
source = "solutions.corewide.com/azure/tf-azure-k8s-aks/azurerm"
version = "~> 5.0"
# ...
}
module "azure_cert_manager_iam" {
source = "solutions.corewide.com/azure/tf-k8s-cert-manager-dns-azure/azurerm"
version = "~> 1.0"
resource_group_name = azurerm_resource_group.main.name
region = azurerm_resource_group.main.location
hosted_zone_name = "example.com"
hosted_zone_id = "/subscriptions/bar/dnsZones/example.com"
subscription_id = "bar"
oidc_provider_url = module.aks.cluster.oidc_issuer_url
}
Deploy Traefik Ingress for Kubernetes with cert-manager and custom parameters:
hclmodule "ingress" {
source = "solutions.corewide.com/kubernetes/tf-k8s-ingress-traefik/helm"
version = "~> 2.1"
acme_email = "[email protected]"
traefik_ingress = {
name = "traefik-ingress"
replicas = 1
chart_version = "41.0.0"
log_level = "DEBUG"
helm_timeout = 600
}
cert_manager = {
enable_metrics = false
chart_version = "1.21.0"
ingress_classes = [
"traefik",
"contour",
]
issuer_names = [
"letsencrypt-staging",
"selfsigned",
]
custom_values = {
image = {
pullPolicy = "Always"
}
global = {
commonLabels = {
project = "example"
}
}
}
}
}
| Variable | Description | Type | Default | Required | Sensitive |
|---|---|---|---|---|---|
acme_email |
E-mail that Let's Encrypt cluster issuer will use to request certificates | string |
yes | no | |
k8s_flavor |
Name of managed Kubernetes to enable cloud-specific adjustments. Applicable values are: aks or eks |
string |
yes | no | |
cert_manager |
cert-manager parameters. The parameters are passed to tf-k8s-cert-manager module | any |
{} |
no | no |
traefik_ingress |
Traefik Ingress parameters | object |
{} |
no | no |
traefik_ingress.access_logs_enabled |
Enable/disable Traefik access logs | bool |
false |
no | no |
traefik_ingress.chart_version |
Version of Traefik Helm chart | string |
41.0.2 |
no | no |
traefik_ingress.create_namespace |
Indicates creation of dedicated namespace for Traefik Ingress deployment | bool |
true |
no | no |
traefik_ingress.custom_values |
A block of custom values for Traefik Helm chart | any |
{} |
no | no |
traefik_ingress.helm_timeout |
Time in seconds for Helm resource to install in Kubernetes | number |
600 |
no | no |
traefik_ingress.ingress_class_name |
Name of Ingress Class of Treafik Ingress | string |
traefik |
no | no |
traefik_ingress.log_level |
Traefik Ingress log level | string |
info |
no | no |
traefik_ingress.name |
Name to override Traefik Ingress release name | string |
traefik-ingress |
no | no |
traefik_ingress.namespace |
Namespace to install Traefik Ingress into | string |
traefik-ingress |
no | no |
traefik_ingress.replicas |
Number of Traefik Ingress pod replicas | number |
2 |
no | no |
traefik_ingress.version |
Version of Traefik Helm chart (Deprecated and will be deleted in v2.4) |
string |
no | no |
| Output | Description | Type | Sensitive |
|---|---|---|---|
ingress_class |
Name of Ingress Class of Traefik Ingress | attribute |
no |
ingress_hostname |
Hostname of Traefik Ingress Load Balancer | computed |
no |
ingress_ip |
External IP of Traefik Ingress Load Balancer | computed |
no |
| Dependency | Version | Kind |
|---|---|---|
terraform |
>= 1.3 |
CLI |
hashicorp/helm |
~> 3.1 |
provider |
hashicorp/kubernetes |
~> 3.0 |
provider |
tf-k8s-cert-manager |
~> 2.1 |
module |
These components are included as is under the terms of their corresponding licenses.
| Component | License |
|---|---|
| Traefik | MIT |
| Traefik Helm chart | Apache-2.0 |
| cert-manager | Apache-2.0 |