LogoDocumentation
Kubernetes

Exposing Applications

This chapter explains how to make your application reachable from outside the cluster. How you do it depends on the protocol your application speaks:

  • HTTP(S) applications — web servers, REST APIs, dashboards. These share the cluster’s HTTP load balancer with every other web application, so a single public IP serves many of them. They are exposed using Gateway API (HTTPRoute), Traefik IngressRoute, or nginx Ingress (nginx-traefik).
  • Non-HTTP applications — SSH, databases, message brokers, custom TCP/UDP protocols. These cannot share the HTTP load balancer; they are exposed via LoadBalancer Services, each with an IP address of its own (public, or private within the MUNI network). Several of your Services can share one IP on different ports.

The difference in IP addresses follows from the protocol: the HTTP load balancer tells applications apart by hostname, while plain TCP/UDP traffic can only be told apart by IP address and port. Public IPv4 addresses are scarce, so prefer HTTP whenever your application can speak it.

Load balancer addresses

Each cluster publishes its HTTP load balancer under a DNS name:

ClusterLoad balancer DNS name
kuba-clusterkuba-lb.cloud.e-infra.cz
kubh-clusterkubh-lb.cerit-sc.cz
kubas-clusterkubas-lb.cloud.trusted.e-infra.cz
nrp-clusterapp1.nrp1.du.cesnet.cz
nma-clusterapps.kub1.du.cesnet.cz

kuba-pub.cerit-sc.cz is the legacy load balancer address of the kuba-cluster. Use the new address kuba-lb.cloud.e-infra.cz and migrate to it.

For your own external address, create a CNAME record that points to the load balancer name of the cluster you use. A CNAME is preferred over an A/AAAA record, because the load balancer IP address can change.

⚠️

An application behind a CNAME must not send e-mail

An application that uses a CNAME to the load balancer must not send e-mail. If it sends e-mail, the mail server sees the real hostname of the machine, not your name.

If your application sends e-mail, make the DNS name an IN (A/AAAA) record that points to the same IP address as our alias. Then the mail keeps your name.

✅

Prerequisite

These guides assume that your application (Deployment) is already deployed. If you are unsure, refer to the Hello World example.

publicity banner

On this page

einfra banner