--- apiVersion: traefik.io/v1alpha1 kind: Middleware metadata: name: auth-proxy spec: forwardAuth: address: http://auth-proxy.auth-proxy.svc:80/auth trustForwardHeader: true authResponseHeaders: - X-Auth-Request-User - X-Auth-Request-Email - X-Auth-Request-Groups --- apiVersion: traefik.io/v1alpha1 kind: IngressRoute metadata: name: secret-reader annotations: cert-manager.io/cluster-issuer: letsencrypt spec: entryPoints: - websecure routes: - match: Host(`secret-reader.hexor.cy`) kind: Rule middlewares: - name: auth-proxy services: - name: secret-reader port: 80 tls: secretName: secret-reader-tls --- apiVersion: cert-manager.io/v1 kind: Certificate metadata: name: secret-reader-tls spec: secretName: secret-reader-tls issuerRef: name: letsencrypt kind: ClusterIssuer dnsNames: - secret-reader.hexor.cy