cfgate.iocfgate v0.2.0-alpha.11 · Release documentation
Rancher Integration
Expose Rancher 2.14+ via cfgate using Gateway API.
Prerequisites
Section titled “Prerequisites”- cfgate installed (see basic example)
- Rancher Helm chart v2.14.0+ (Gateway API support)
1. Deploy cfgate tunnel + DNS sync
Section titled “1. Deploy cfgate tunnel + DNS sync”# Edit tunnel.yaml: set accountId# Edit dns.yaml: set zones[].name to your domainkubectl apply -k examples/with-rancher/cfgate2. Install Rancher
Section titled “2. Install Rancher”helm upgrade --install rancher rancher-alpha/rancher \ --namespace cattle-system \ --create-namespace \ --values examples/with-rancher/rancher-values.yaml \ --set hostname=rancher.example.com # <-- Your domain3. Annotate Rancher’s Gateway
Section titled “3. Annotate Rancher’s Gateway”Rancher creates its own Gateway. Add the tunnel reference so cfgate can route traffic through the Cloudflare Tunnel:
kubectl annotate gateway rancher-gateway -n cattle-system \ cfgate.io/tunnel-ref=cfgate-system/rancher-tunnelThe CloudflareDNS resource discovers hostnames from all HTTPRoutes attached to this Gateway because its gatewayRoutes block is present. No per-route annotations are needed unless you use annotationFilter to limit which routes get DNS records.
4. Verify
Section titled “4. Verify”kubectl get gateway rancher-gateway -n cattle-systemkubectl get cloudflarednses -n cfgate-systemcurl -I https://rancher.example.comHow TLS Works
Section titled “How TLS Works”Browser ──HTTPS──▶ Cloudflare Edge (TLS termination) │ │ X-Forwarded-Proto: https ▼ cloudflared ──HTTP──▶ Rancher:80Rancher respects X-Forwarded-Proto and skips HTTPS redirect when tls: external is set.