From 23fc8df0f4f5a2ef2e11767c2af1abdaec609237 Mon Sep 17 00:00:00 2001 From: Caleb Braaten Date: Thu, 17 Sep 2026 03:49:07 -0700 Subject: [PATCH] Include Traefik Tags for Canary Allocations --- blog.nomad.hcl | 59 +++++++++++++++++++++++++------------------------ blog.nomad.json | 17 +++++++++++++- 2 files changed, 46 insertions(+), 30 deletions(-) diff --git a/blog.nomad.hcl b/blog.nomad.hcl index d5a430f..c28159b 100644 --- a/blog.nomad.hcl +++ b/blog.nomad.hcl @@ -3,6 +3,34 @@ locals { HOST = "cbraaten.dev" + + # shared by both production and canary allocations so Traefik never + # loses sight of the router during a rolling switchover + traefik_tags = [ + # ----- router for the naked domain ----- + "traefik.enable=true", + "traefik.http.routers.blog.rule=Host(`${local.HOST}`)", + "traefik.http.routers.blog.entrypoints=websecure", + "traefik.http.routers.blog.tls=true", + "traefik.http.routers.blog.service=blog-svc", + + # ----- router for the www domain ----- + "traefik.http.routers.blog-www.rule=Host(`www.${local.HOST}`)", + "traefik.http.routers.blog-www.entrypoints=websecure", + "traefik.http.routers.blog-www.tls=true", + "traefik.http.routers.blog-www.middlewares=redirect-www-to-root", + + # ----- middleware that does the 301 redirect ----- + "traefik.http.middlewares.redirect-www-to-root.redirectregex.regex=^https?://www\\.${local.HOST}(.*)", + "traefik.http.middlewares.redirect-www-to-root.redirectregex.replacement=https://${local.HOST}$${1}", + "traefik.http.middlewares.redirect-www-to-root.redirectregex.permanent=true", + + # ----- service and health check ----- + "traefik.http.services.blog-svc.loadbalancer.healthcheck.path=/healthz", + "traefik.http.services.blog-svc.loadbalancer.healthcheck.interval=5s", + "traefik.http.services.blog-svc.loadbalancer.healthcheck.timeout=2s", + "traefik.http.services.blog-svc.loadbalancer.healthcheck.hostname=${local.HOST}", + ] } variable "image_tag" { @@ -31,35 +59,8 @@ job "blog" { provider = "consul" port = "http" - tags = [ - # ----- router for the naked domain ----- - "traefik.enable=true", - "traefik.http.routers.blog.rule=Host(`${local.HOST}`)", - "traefik.http.routers.blog.entrypoints=websecure", - "traefik.http.routers.blog.tls=true", - "traefik.http.routers.blog.service=blog-svc", - - # ----- router for the www domain (new) ----- - "traefik.http.routers.blog-www.rule=Host(`www.${local.HOST}`)", - "traefik.http.routers.blog-www.entrypoints=websecure", - "traefik.http.routers.blog-www.tls=true", - "traefik.http.routers.blog-www.middlewares=redirect-www-to-root", - - # ----- middleware that does the 301 redirect ----- - "traefik.http.middlewares.redirect-www-to-root.redirectregex.regex=^https?://www\\.${local.HOST}(.*)", - "traefik.http.middlewares.redirect-www-to-root.redirectregex.replacement=https://${local.HOST}$${1}", - "traefik.http.middlewares.redirect-www-to-root.redirectregex.permanent=true", - - # ----- service and health check ----- - "traefik.http.services.blog-svc.loadbalancer.healthcheck.path=/healthz", - "traefik.http.services.blog-svc.loadbalancer.healthcheck.interval=5s", - "traefik.http.services.blog-svc.loadbalancer.healthcheck.timeout=2s", - "traefik.http.services.blog-svc.loadbalancer.healthcheck.hostname=${local.HOST}", - ] - - # canary allocations register with these tags instead, so Traefik - # does not route production traffic to them before promotion - canary_tags = ["canary"] + tags = local.traefik_tags + canary_tags = local.traefik_tags check { name = "blog-health" diff --git a/blog.nomad.json b/blog.nomad.json index 27830e5..b9366cb 100644 --- a/blog.nomad.json +++ b/blog.nomad.json @@ -119,7 +119,22 @@ "traefik.http.services.blog-svc.loadbalancer.healthcheck.hostname=cbraaten.dev" ], "CanaryTags": [ - "canary" + "traefik.enable=true", + "traefik.http.routers.blog.rule=Host(`cbraaten.dev`)", + "traefik.http.routers.blog.entrypoints=websecure", + "traefik.http.routers.blog.tls=true", + "traefik.http.routers.blog.service=blog-svc", + "traefik.http.routers.blog-www.rule=Host(`www.cbraaten.dev`)", + "traefik.http.routers.blog-www.entrypoints=websecure", + "traefik.http.routers.blog-www.tls=true", + "traefik.http.routers.blog-www.middlewares=redirect-www-to-root", + "traefik.http.middlewares.redirect-www-to-root.redirectregex.regex=^https?://www\\.cbraaten.dev(.*)", + "traefik.http.middlewares.redirect-www-to-root.redirectregex.replacement=https://cbraaten.dev${1}", + "traefik.http.middlewares.redirect-www-to-root.redirectregex.permanent=true", + "traefik.http.services.blog-svc.loadbalancer.healthcheck.path=/healthz", + "traefik.http.services.blog-svc.loadbalancer.healthcheck.interval=5s", + "traefik.http.services.blog-svc.loadbalancer.healthcheck.timeout=2s", + "traefik.http.services.blog-svc.loadbalancer.healthcheck.hostname=cbraaten.dev" ], "EnableTagOverride": false, "PortLabel": "http",