# Kubernetes + traefik 2 gitlab route ssh port

**URL:** <https://community.traefik.io/t/kubernetes-traefik-2-gitlab-route-ssh-port/18112>\
**Category:** Traefik v2\
**Tags:** kubernetes-ingress\
**Created:** [March 31, 2023, 8:39pm UTC](https://community.traefik.io/t/kubernetes-traefik-2-gitlab-route-ssh-port/18112 "2023-03-31T20:39:37Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![fritz0011](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/fritz0011/32/6894_2.png) [@fritz0011](https://community.traefik.io/u/fritz0011)\
**Post date:** [March 31, 2023, 8:39pm UTC](https://community.traefik.io/t/kubernetes-traefik-2-gitlab-route-ssh-port/18112/1 "2023-03-31T20:39:37Z")

</div>

Hello ,

For couple of days I'm trying to figure out a way to access gitlab hosted on a k8s cluster

So, kubernetes 1.23.13; traefik 2.8.7  
Kubernetes cluster up and running

access gitlab over HTTPS  
IngressRouteTCP

```auto
apiVersion: v1
items:
- apiVersion: traefik.containo.us/v1alpha1
  kind: IngressRouteTCP
  metadata:
    annotations:
      ingress.kubernetes.io/ssl-passthrough: "true"
    name: gitlab-ingress
    namespace: gitlab
  spec:
    entryPoints:
    - websecure
    routes:
    - kind: Rule
      match: HostSNI(`*`)
      priority: 1
      services:
      - name: gitlab-ce
        port: 443
    tls:
      certResolver: gitlab
      passthrough: true

```

IngressRouteTCP for ssh

```auto
- apiVersion: traefik.containo.us/v1alpha1
  kind: IngressRouteTCP
  metadata:
    name: gitlab-ssh
    namespace: gitlab
  spec:
    entryPoints:
    - gitlab-ssh
    routes:
    - kind: Rule
      match: HostSNI(`*`)
      priority: 2
      services:
      - name: gitlab-ce
        port: 22

```

Since traefik was already installed, I had to patch the traefik deployment to create gitlab-ssh entrypoint:

```auto
spec:
  containers:
  - args:
    - --global.checknewversion
    - --global.sendanonymoususage
    - --entrypoints.metrics.address=:9100/tcp
    - --entrypoints.traefik.address=:9000/tcp
    - --entrypoints.web.address=:8000/tcp
    - --entrypoints.websecure.address=:8443/tcp
    - --entrypoints.gitlab-ssh.address=:2222/tcp

```

```auto
        ports:
        - containerPort: 9100
          name: metrics
          protocol: TCP
        - containerPort: 9000
          name: traefik
          protocol: TCP
        - containerPort: 8000
          name: web
          protocol: TCP
        - containerPort: 8443
          name: websecure
          protocol: TCP
        - containerPort: 2222
          name: gitlab-ssh

```

So , as I have said, gitlab is accessible over HTTPS

but git clone ssh://gitlab-domain:2222/project/prj1.git fails ... ☹

Am I doing something wrong, do I miss something ?!

---

<div class="post-metadata">

**Author:** ![sachasmart](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/sachasmart/32/10872_2.png) [@sachasmart](https://community.traefik.io/u/sachasmart)\
**Post date:** [November 12, 2025, 1:42am UTC](https://community.traefik.io/t/kubernetes-traefik-2-gitlab-route-ssh-port/18112/2 "2025-11-12T01:42:59Z")

</div>

Hey! I am currently running into this. Did you manage to resolve this? Any guidance that you could recommend to others 🙂
