--- apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: harbor-registry-ingress namespace: harbor-registry annotations: cert-manager.io/cluster-issuer: letsencrypt-production # Harbor-specific settings nginx.ingress.kubernetes.io/proxy-body-size: "0" nginx.ingress.kubernetes.io/proxy-read-timeout: "600" nginx.ingress.kubernetes.io/proxy-send-timeout: "600" # SSL and redirect handling nginx.ingress.kubernetes.io/backend-protocol: "HTTPS" nginx.ingress.kubernetes.io/ssl-redirect: "false" nginx.ingress.kubernetes.io/proxy-ssl-verify: "false" spec: ingressClassName: nginx tls: - hosts: - secretName: -tls rules: - host: http: paths: # Harbor - route to HTTPS service to avoid internal redirects - path: / pathType: Prefix backend: service: name: harbor-registry port: number: 443