cfgate.iocfgate v0.2.0-alpha.11 · Release documentation
Multi-Service Example
Multiple services exposed through a single Cloudflare tunnel.
api.example.com -> api serviceweb.example.com/ -> web service (public)web.example.com/admin -> admin service (Access protected)web.example.com/repos -> api service (Access protected)Quick Start
Section titled “Quick Start”# 1. Install cfgate (see basic example)
# 2. Edit configuration files# - tunnel.yaml: set accountId# - dns.yaml: set zones[].name# - httproutes.yaml: set hostnames# - accesspolicy.yaml: set accountId and identity rules
# 3. Deploykubectl apply -k examples/multi-serviceComponents
Section titled “Components”- One
CloudflareTunnelwith 2 replicas - One
Gatewayshared by all routes - One
CloudflareDNSwatching all HTTPRoutes - Three services:
api,web, andadmin - Two HTTPRoutes:
apiandweb - Two reusable
CloudflareAccessPolicyresources incfgate-system - Two tenant-local
CloudflareAccessApplicationresources protecting namedwebroute rules - One
ReferenceGrantallowing tenant app bindings to reference central policies
Access policies live in
cfgate-system. Access applications live indemoand attach those policies to theadminandreposHTTPRoute rules. This cross-namespace policy reference requires a ReferenceGrant incfgate-system. Seereferencegrant.yaml.
Adding Services
Section titled “Adding Services”- Add deployment + service to
services.yaml - Add HTTPRoute to
httproutes.yaml - DNS record created automatically
Cleanup
Section titled “Cleanup”kubectl delete -k examples/multi-service