NewWe open-sourced 50+ Laravel packages
Custom AI apps, agents and automation — Roundly ConsultingRoundly
All packages

The package ships first-class resources for Traefik’s CRDs. Build an IngressRoute from TraefikRoute and TraefikService value objects and attach middlewares by name:

use RoundlyConsulting\KubernetesApi\Resources\Types\TraefikRoute;
use RoundlyConsulting\KubernetesApi\Resources\Types\TraefikService;

// A middleware that redirects to HTTPS (permanent by default)
$cluster->traefikMiddlewares()
    ->setNamespace('shop')
    ->setName('redirect-https')
    ->redirectToScheme('https')
    ->create();

// HTTP entry point: send everything through the redirect
$cluster->traefikIngressRoutes()
    ->setNamespace('shop')
    ->setName('checkout-http')
    ->setEntryPoints(['web'])
    ->addRoute(
        TraefikRoute::hostRule('shop.example.com')
            ->addMiddleware('redirect-https')
            ->addService(TraefikService::to('checkout', '80')),
    )
    ->create();

// HTTPS entry point: host and path routing with TLS
$cluster->traefikIngressRoutes()
    ->setNamespace('shop')
    ->setName('checkout')
    ->setEntryPoints(['websecure'])
    ->addRoute(TraefikRoute::hostRule('shop.example.com')->addService(TraefikService::to('checkout', '80')))
    ->addRoute(
        TraefikRoute::matchRule('Host(`shop.example.com`) && PathPrefix(`/api`)')
            ->addService(TraefikService::to('checkout-api', '8080')),
    )
    ->setSpec('tls', ['secretName' => 'wildcard-tls'])
    ->create();

$route = $cluster->traefikIngressRoutes()->setNamespace('shop')->withName('checkout')->find();
$route->getEntryPoints();   // ['websecure']
$route->getRoutes();        // TraefikRoute[]
  • TraefikRoute::hostRule($host) and pathRule($path) build Host and PathPrefix rules; matchRule($rule) takes any Traefik rule expression.
  • addMiddleware($name, $namespace = null) references a middleware; addService(TraefikService::to($service, $port)) adds a backend.
  • TraefikMiddleware::redirectToScheme($scheme = 'https', $permanent = true) covers the common redirect; set other middleware specs with setSpec().

TLS and transport

Beyond IngressRoute and Middleware, the TLS and transport CRDs are first-class too — with getters for every setter shown:

// Point a default certificate at a kubernetes.io/tls Secret.
$cluster->traefikTlsStores()
    ->setNamespace('default')
    ->setName('default')
    ->setDefaultCertificate('wildcard-tls')
    ->create();

// Configure how Traefik dials a backend.
$cluster->traefikServersTransports()
    ->setNamespace('default')
    ->setName('backend')
    ->setServerName('backend.internal')
    ->insecureSkipVerify()
    ->setRootCAsSecrets(['backend-ca'])
    ->setCertificatesSecrets(['backend-client-cert'])   // client certificates for mTLS
    ->create();

// Constrain TLS versions and cipher suites.
$cluster->traefikTlsOptions()
    ->setNamespace('default')
    ->setName('modern')
    ->setMinVersion('VersionTLS12')
    ->setMaxVersion('VersionTLS13')
    ->setCipherSuites(['TLS_AES_256_GCM_SHA384'])
    ->create();

API group

Every Traefik resource reads kubernetes.traefik.group when it is constructed. The default, traefik.io/v1alpha1, matches Traefik v3; point it at the older group for earlier installations. A blank value is not set and keeps the bundled group; a non-string value throws InvalidConfigurationException instead of being ignored:

// config/kubernetes.php
'traefik' => [
    'group' => 'traefik.containo.us/v1alpha1',   // Traefik installations older than v3
],

The REST plurals — middlewares, tlsstores, serverstransports and tlsoptions — are pinned to the real CRDs, so they never depend on English pluralisation.

Show your open-source love

This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.

More ways to support, including crypto

By donating, you agree to our donation terms.

Want this built into your product?

We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.