will be interesting how the cname works out for ingress, it must be the same IP space as traefik is on, otherwise dns points to ip with nothing
Traefik Ingress Controller
See /ripe87/application.yaml for a basic example without authentication.
Deployment
With ArgoCD. Render it locally:
cp ../shared/network-policy.yml .
kustomize build . --enable-helm