Configure ingress with Helm
Configure and validate Helm-managed HTTPS ingress, public origins, proxy behavior, webhooks, and realtime streams.
Prerequisites
Provide an ingress controller, DNS, trusted TLS certificate workflow, and known proxy chain. Read the common Kubernetes ingress guide and reverse-proxy contract.
Prepare the configuration
Set chart public URLs to the exact HTTPS origin. Enable ingress and configure class, host, path, TLS Secret, certificate annotations, SSL redirect, disabled SSE buffering, suitable timeouts, and bounded request size. Configure TRUST_PROXY_HEADERS for trusted host/protocol forwarding and TRUSTED_PROXY_HOPS separately for client-IP resolution. Configure NetworkPolicy ingress namespace labels.
Deploy ingress
Render the chart and inspect the Ingress target Service/port, host, TLS, annotations, and policy selectors. Apply through the normal Helm installation/upgrade.
Verify public behavior
Check Ingress, Service, endpoints, and public readiness. Verify sign-in/callback origins, a live incident update, a signed webhook, and configured OIDC/ChatOps callbacks. Compare an in-cluster request if public access fails.
Operate it in production
Monitor certificate expiry, TLS/upstream errors, SSE disconnects, callback failures, and body-limit rejections. Trust forwarding headers only from the known chain.
Troubleshooting
404/503: inspect ingress class/rules, Service/endpoints, and readiness.
Wrong redirect: correct chart public URLs, forwarded host/protocol, and TRUST_PROXY_HEADERS; roll Web/application.
SSE or webhook fails: correct buffering/timeouts or preserve signed raw body/headers and documented size limits.
Change or remove ingress
Validate new hostname and every callback before retiring the old route. Keep HTTPS rollback available; never expose an unauthenticated direct port as fallback.
Next steps
Last updated for v2.0.0
Edit this page on GitHub