Skip to content

Traefik as a gateway API controller

See webserver/traefik.md for general docs abour traefik

Configuration

kubectl describe GatewayClass traefik
kubectl describe Gateway traefik --namespace kube-system

TLS

From Gateway API & ACME:

Traefik’s built‑in ACME/Let’s Encrypt integration works for IngressRoute and Ingress resources, but it does not issue certificates for Gateway API listeners. If you’re using the Gateway API, install cert‑manager (or another certificate controller) and reference the secret it creates in gateway.listeners.websecure.certificateRefs.

See also FR: Support configuring Letsencrypt certificates using Gateway API

DNS challenge

ListenerSets

Gateway API docs: ListenerSet

ListenerSets allow teams to define ports, hostnames, and TLS certificates in separate resources rather than cramming everything into one giant Gateway object which has a limit of 64 listeners