<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Gateway-Api on Gerard Samuel</title><link>https://gerardsamuel.me/tags/gateway-api/</link><description>Recent content in Gateway-Api on Gerard Samuel</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Thu, 06 Feb 2025 11:17:51 -0500</lastBuildDate><atom:link href="https://gerardsamuel.me/tags/gateway-api/index.xml" rel="self" type="application/rss+xml"/><item><title>Securing Cilium's Gateway Api with cert-manager</title><link>https://gerardsamuel.me/posts/how-to-secure-cilium-gateway-api-with-cert-manager/</link><pubDate>Thu, 06 Feb 2025 11:17:51 -0500</pubDate><guid>https://gerardsamuel.me/posts/how-to-secure-cilium-gateway-api-with-cert-manager/</guid><description>&lt;p&gt;In my Hashicorp &lt;a href="https://www.nomadproject.io/" target="_blank" rel="noreferrer"&gt;Nomad&lt;/a&gt; cluster, I am using &lt;a href="https://traefik.io/traefik/" target="_blank" rel="noreferrer"&gt;Traefik&lt;/a&gt; to proxy external connections to the running containers, and Traefik also terminates TLS connections. While it is perfectly okay to duplicate this role in Kubernetes, I decided to go another route and leverage Gateway API as the reverse proxy. To build upon my existing work with &lt;a href="https://gerardsamuel.me/posts/howto-setup-kubernetes-cilium-bgp-with-unifi-v4.1-router/" &gt;Gateway API&lt;/a&gt;, let me set up an HTTP/HTTPS proxy with redirection using Gateway API and secure it with &lt;a href="https://cert-manager.io/" target="_blank" rel="noreferrer"&gt;cert-manager&lt;/a&gt; and a few friends.&lt;/p&gt;</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://gerardsamuel.me/posts/how-to-secure-cilium-gateway-api-with-cert-manager/featured.png"/></item></channel></rss>