Ingresses
ingresses renders one Ingress per key. By default an ingress routes to the Service with the same key, so a matching services entry is all you need to wire it up:
services:
web:
ports:
http:
port: 80
targetPort: http
ingresses:
web:
className: nginx
hosts:
- example.comFor a single-ingress chart, the ingress: shorthand injects into the map under the release name, mirroring the pattern most public charts use:
ingress:
className: nginx
hosts:
- example.comAn ingress renders nothing until it has hosts, so a bare key produces no output.
Hosts and paths
Each host can be a plain string or the full object form. A plain string defaults to a single / path with ImplementationSpecific pathType:
ingresses:
web:
hosts:
- example.com # shorthand: path "/"
- host: api.example.com # full form
paths:
- path: /v1
pathType: PrefixThe backend service is looked up by the ingress key. If no service shares the key, the chart falls back to the first service alphabetically. Set an explicit backend on a path to override the automatic wiring.
TLS
tls has three modes. The simplest is a bare key (or tls: true), which derives the hosts from the ingress and names the secret <fullname>-tls:
ingresses:
web:
hosts:
- example.com
tls: # auto: secretName <fullname>-tls, hosts from aboveList mode gives per-entry control; omitted fields fall back to the same sane defaults:
tls:
- secretName: my-tls # optional, defaults to <fullname>-tls
hosts: # optional, defaults to all ingress hosts
- example.comDict mode uses the key as the default secretName and supports enabled: false to skip an entry:
tls:
my-cert:
hosts:
- example.com
old-cert:
enabled: false # skip this entryClass and annotations
className renders spec.ingressClassName (ingressClass and ingressClassName are accepted aliases). Pass controller-specific configuration through annotations:
ingresses:
web:
className: nginx
annotations:
kubernetes.io/tls-acme: "true"
hosts:
- example.comThe per-ingress annotations merge on top of the global annotations value, so a shared annotation set (an owner tag, for example) reaches the ingress too, and the per-ingress keys win. The deprecated kubernetes.io/ingress.class annotation is not needed; use className. See Annotations for the merge order across resources.
Disabling an ingress
Set enabled: false to keep an ingress in values but skip rendering it:
ingresses:
internal:
enabled: false
hosts:
- internal.example.com