Networking
CRAFT uses Gateway API for traffic routing, cert-manager for TLS certificate lifecycle, and external-dns for automatic DNS record management. This guide covers the networking stack across cloud and on-premises environments.Gateway API
EM-Runtime uses the Kubernetes Gateway API (v1) for all external traffic routing. Gateway API replaces traditional Ingress with a more expressive, role-oriented model.Ingress Flow
Gateway Resource
The Gateway resource defines the load balancer and listeners. It must exist before the em-runtime chart deploys HTTPRoutes.HTTPRoute Rules
The em-runtime Helm chart creates an HTTPRoute with these default rules:Gateway Controllers by Platform
Configuration in Helm
cert-manager
cert-manager automates TLS certificate provisioning and renewal. It supports ACME (Let’s Encrypt) and internal CA issuers.Certificate Flow
Installation
Install cert-manager with Gateway API support:ClusterIssuer Configuration
- Let's Encrypt (Production)
- Internal CA (On-Prem)
DNS-01 Solver by Provider
Gateway Annotation
Annotate the Gateway to trigger automatic certificate provisioning:external-dns
external-dns synchronizes Kubernetes resources (Gateway, Service, Ingress) with DNS providers, automatically creating A/CNAME records.How It Works
- external-dns watches Gateway and Service resources for hostname annotations
- When a Gateway gets an external IP, external-dns creates a DNS A record
- Records are updated or removed as resources change
Configuration by Provider
- GCP Cloud DNS
- AWS Route 53
- On-Prem (RFC2136)
dns.admin role.TLS Requirements
Network Policies
For on-premises deployments, configure Kubernetes NetworkPolicies for defense in depth:Restrict data-insights egress to allowlisted LLM API endpoints (OpenAI, Anthropic, Vertex AI) for SSRF mitigation.
Firewall Rules
Ensure the following traffic is permitted:DNS Architecture
One DNS A record pointing the platform hostname to the load balancer IP/CNAME:Troubleshooting
Certificate not provisioning
Certificate not provisioning
Gateway not getting external IP
Gateway not getting external IP
DNS records not created
DNS records not created
Next Steps
Prerequisites
Complete networking prerequisites and firewall rules.

