From a93619acab237b6c71559529877e029b6dc5c58d Mon Sep 17 00:00:00 2001
From: "aspire-repo-bot[bot]"
<268009190+aspire-repo-bot[bot]@users.noreply.github.com>
Date: Tue, 25 Aug 2026 00:22:43 +0000
Subject: [PATCH 1/4] docs: document hostname inheritance for Ingress paths and
Gateway routes
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---
.../docs/deployment/kubernetes-ingress.mdx | 33 +++++++++++++++++++
1 file changed, 33 insertions(+)
diff --git a/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx b/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx
index 75507028c..0e64d4945 100644
--- a/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx
+++ b/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx
@@ -113,6 +113,39 @@ await ingress.withPath('/', web.getEndpoint('http'));
the `HTTPRoute` resource it generates.
+## Hostname inheritance for paths and routes
+
+`WithHostname(...)` on the Ingress or Gateway sets the hostname that applies
+to any path (`WithPath`) or route (`WithRoute`) you add **without** an
+explicit hostname of its own. This lets you set the hostname once and reuse it
+across every hostless path or route:
+
+```csharp title="AppHost.cs"
+var ingress = k8s.AddIngress("public")
+ .WithHostname("app.example.com")
+ .WithTls();
+
+// Both paths inherit "app.example.com" from WithHostname(...).
+ingress.WithPath("/api", api.GetEndpoint("http"));
+ingress.WithPath("/", web.GetEndpoint("http"));
+```
+
+If a path or route specifies its own hostname — via the host-scoped
+`WithPath("api.example.com", "/", endpoint)` overload, or the equivalent on
+`WithRoute` — that explicit hostname takes precedence over the one from
+`WithHostname(...)`.
+
+`WithDefaultBackend(endpoint)` is unaffected by `WithHostname(...)`: the
+default backend always generates a catch-all rule (no `host` restriction) so
+it keeps accepting any traffic that doesn't match a more specific path or
+route, including the TLS compatibility rule Aspire generates for it.
+
+
+
## TLS and certificates
When you configure TLS with `WithTls()`, Aspire handles the initial bootstrapping:
From e7fbfc615e158554148f2c5bc5fed4ba9dff83b4 Mon Sep 17 00:00:00 2001
From: Maddy Montaquila
Date: Tue, 29 Sep 2026 16:25:30 -0400
Subject: [PATCH 2/4] Apply suggestion from @alistairmatthews
Co-authored-by: Alistair Matthews
---
.../src/content/docs/deployment/kubernetes-ingress.mdx | 7 +++----
1 file changed, 3 insertions(+), 4 deletions(-)
diff --git a/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx b/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx
index 0e64d4945..f2bc6f25a 100644
--- a/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx
+++ b/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx
@@ -115,10 +115,9 @@ await ingress.withPath('/', web.getEndpoint('http'));
## Hostname inheritance for paths and routes
-`WithHostname(...)` on the Ingress or Gateway sets the hostname that applies
-to any path (`WithPath`) or route (`WithRoute`) you add **without** an
-explicit hostname of its own. This lets you set the hostname once and reuse it
-across every hostless path or route:
+The `WithHostname()` method on the Ingress or Gateway sets the hostname that applies
+to any path or route you add **without** an
+explicit hostname of its own, by using `WithPath` or `WithRoute`. This arrangement lets you set the hostname once and reuse it across every hostless path or route:
```csharp title="AppHost.cs"
var ingress = k8s.AddIngress("public")
From eb690324431b7f1410610bdfe42ed7afc3f104ba Mon Sep 17 00:00:00 2001
From: Maddy Montaquila
Date: Tue, 29 Sep 2026 16:25:46 -0400
Subject: [PATCH 3/4] Apply suggestion from @alistairmatthews
Co-authored-by: Alistair Matthews
---
src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx b/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx
index f2bc6f25a..3ab8e8b1c 100644
--- a/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx
+++ b/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx
@@ -135,7 +135,7 @@ If a path or route specifies its own hostname — via the host-scoped
`WithHostname(...)`.
`WithDefaultBackend(endpoint)` is unaffected by `WithHostname(...)`: the
-default backend always generates a catch-all rule (no `host` restriction) so
+default backend always generates a catch-all rule, no `host` restriction. Thus
it keeps accepting any traffic that doesn't match a more specific path or
route, including the TLS compatibility rule Aspire generates for it.
From 568445a0fedd47c3a3bff5b2bc3e1d806a77d784 Mon Sep 17 00:00:00 2001
From: Maddy Montaquila
Date: Tue, 29 Sep 2026 16:25:56 -0400
Subject: [PATCH 4/4] Apply suggestion from @alistairmatthews
Co-authored-by: Alistair Matthews
---
.../src/content/docs/deployment/kubernetes-ingress.mdx | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
diff --git a/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx b/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx
index 3ab8e8b1c..85812d4bc 100644
--- a/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx
+++ b/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx
@@ -129,10 +129,9 @@ ingress.WithPath("/api", api.GetEndpoint("http"));
ingress.WithPath("/", web.GetEndpoint("http"));
```
-If a path or route specifies its own hostname — via the host-scoped
+If a path or route specifies its own hostname, that explicit hostname takes precedence over the one from `WithHostname()`. You can specify the hostname by using the host-scoped
`WithPath("api.example.com", "/", endpoint)` overload, or the equivalent on
-`WithRoute` — that explicit hostname takes precedence over the one from
-`WithHostname(...)`.
+`WithRoute` .
`WithDefaultBackend(endpoint)` is unaffected by `WithHostname(...)`: the
default backend always generates a catch-all rule, no `host` restriction. Thus