Configure Kubernetes ingress and TLS
Publish OpsKnight through HTTPS with correct origins, proxy headers, webhook handling, and realtime streams.
Prerequisites
Install an approved ingress controller, create DNS, and obtain a trusted TLS certificate workflow. In split mode, only Web receives user traffic.
Prepare public routing
Set NEXTAUTH_URL and NEXT_PUBLIC_APP_URL to the exact public HTTPS origin. Set TRUST_PROXY_HEADERS=true only when the ingress is the restricted trusted path and overwrites the forwarded host/protocol. Configure TRUSTED_PROXY_HOPS separately for the known X-Forwarded-For chain. Point ingress to the OpsKnight Service on its HTTP port and apply the shared reverse-proxy contract.
Preserve host/protocol/client forwarding, signed webhook headers, and raw bodies. Set the documented body limit, disable buffering for server-sent events, and choose an idle timeout that preserves healthy streams.
Deploy ingress
Render the Helm values or Kustomize overlay and inspect host, class, TLS Secret, Service name/port, annotations, and NetworkPolicy ingress selectors. Apply only after placeholders are removed.
kubectl -n opsknight get ingress,service,endpoints
kubectl -n opsknight describe ingress
Verify the public path
curl --fail --show-error \
'https://opsknight.example.com/api/health?mode=readiness'
Sign in, validate callback origins, observe a live incident update without refresh, send a signed webhook, and test configured OIDC/ChatOps callbacks. Compare with an in-cluster readiness request if the public path fails.
Production and security considerations
Redirect HTTP to HTTPS, monitor certificate expiry and upstream errors, restrict direct Service exposure, and trust forwarding headers only from known proxies. Avoid logging cookies, authorization headers, signing secrets, or sensitive payloads.
Troubleshooting
404/503: inspect ingress class, rules, Service selector, endpoints, and readiness.
Redirect to localhost/HTTP: correct both public URLs and forwarded protocol/host handling, then restart Web/application.
421 Misdirected Request: compare ingress host, saved Application URL, public URL variables, proxy trust, and aliases using the recovery guide.
Realtime updates stop: disable buffering and extend timeouts at every load-balancer/ingress hop.
Webhook signature fails: preserve the raw signed request and required headers; check body transformations and size limits.
Change or remove ingress
During hostname migration, validate the new origin and every provider callback before retiring the old hostname. Keep a TLS route available for rollback; do not expose a NodePort as the production fallback.
Next steps
Last updated for v2.0.0
Edit this page on GitHub