apiVersion: cert-manager.io/v1 kind: Certificate metadata: name: homea2-cert spec: secretName: homea2-cert issuerRef: name: letsencrypt-production-http kind: ClusterIssuer commonName: homea2.hottis.de dnsNames: - homea2.hottis.de - homea2-api.hottis.de --- apiVersion: traefik.containo.us/v1alpha1 kind: TLSOption metadata: name: mtls-required spec: clientAuth: clientAuthType: RequireAndVerifyClientCert secretNames: - mtls-ca-cert --- apiVersion: traefik.containo.us/v1alpha1 kind: IngressRoute metadata: name: ui spec: entryPoints: - websecure tls: secretName: homea2-cert options: name: mtls-required namespace: homea2 routes: - match: Host(`homea2.hottis.de`) kind: Rule services: - name: ui port: 80