apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization # No top-level namespace - resources declare their own namespaces resources: # ingress-nginx-controller-alias.yaml REMOVED — it was a ClusterIP Service named # ingress-nginx-controller with a stale selector (instance: ingress-nginx-bootstrap, # a release that no longer exists). ingress-config's selfHeal kept re-applying it # over the helm release's real LoadBalancer Service of the same name, reverting it # to a ClusterIP with zero endpoints -> LB IP .160 unannounced -> cluster-wide # outage. CoreDNS rewrites *.riotpiao.com to ingress-nginx-controller.ingress-nginx # .svc, which is the helm Service directly — no alias needed. - riotpiao-com-cert.yaml # Certificate for *.riotpiao.com (ingress-nginx namespace) - ingress.yaml # Ingress rules for all services (multiple namespaces)