# FlowerCore Digital Signage — TLS + Ingress # Deployment and Service managed by deploy script (not ArgoCD) --- apiVersion: cert-manager.io/v1 kind: Certificate metadata: name: signage-web-tls namespace: fc-signage spec: secretName: signage-web-tls issuerRef: name: step-ca-acme kind: ClusterIssuer dnsNames: - signage.iamworkin.lan --- apiVersion: traefik.io/v1alpha1 kind: IngressRoute metadata: name: signage-web namespace: fc-signage spec: entryPoints: - websecure routes: - match: Host(`signage.iamworkin.lan`) kind: Rule services: - name: signage-web port: 5190 tls: secretName: signage-web-tls --- # HTTP route for signage players that may not use TLS apiVersion: traefik.io/v1alpha1 kind: IngressRoute metadata: name: signage-web-http namespace: fc-signage spec: entryPoints: - web routes: - match: Host(`signage.iamworkin.lan`) kind: Rule services: - name: signage-web port: 5190