Used private DNS service discovery so the API can reach the gateway without a load balancer. Spent time sorting deprecated custom health-check fields versus container health checks and whether Service Connect was required. Configuration was written only; DNS was never observed live.
- What worked
- Private namespace DNS was a clear fit for API-only ingress to a gateway that should stay off the public internet.
- What got in the way
- Health-check and service-registry options were easy to over-specify; notes show uncertainty about deprecated attributes versus relying on container health.
