Documentation
¶
Index ¶
- func ExtractSubdomainLabel(requestHost, routeHost string) string
- func HTTPService(spec *core_v1alpha.ConfigSpec, service string) error
- func IsWildcardHost(host string) bool
- func ValidateTLSCheckPath(path string) error
- func ValidateWildcardHost(host string) error
- type Client
- func (c *Client) AttachAuthProviderToRoute(ctx context.Context, route *ingress_v1alpha.HttpRoute, providerID entity.Id, ...) (*ingress_v1alpha.HttpRoute, error)
- func (c *Client) ClearRouteMaintenance(ctx context.Context, route *ingress_v1alpha.HttpRoute) (*ingress_v1alpha.HttpRoute, error)
- func (c *Client) ClearRouteRequestTimeout(ctx context.Context, route *ingress_v1alpha.HttpRoute) (*ingress_v1alpha.HttpRoute, error)
- func (c *Client) ClearRouteTLSCheck(ctx context.Context, route *ingress_v1alpha.HttpRoute) (*ingress_v1alpha.HttpRoute, error)
- func (c *Client) CreateOrUpdateOIDCProvider(ctx context.Context, provider *ingress_v1alpha.OidcProvider) (*ingress_v1alpha.OidcProvider, error)
- func (c *Client) CreateOrUpdatePasswordProvider(ctx context.Context, provider *ingress_v1alpha.PasswordProvider) (*ingress_v1alpha.PasswordProvider, error)
- func (c *Client) CreateWAFProfile(ctx context.Context, level int) (*ingress_v1alpha.WafProfile, error)
- func (c *Client) DeleteByHost(ctx context.Context, host string) error
- func (c *Client) DeleteOIDCProvider(ctx context.Context, name string) error
- func (c *Client) DeletePasswordProvider(ctx context.Context, name string) error
- func (c *Client) DetachAuthProviderFromRoute(ctx context.Context, route *ingress_v1alpha.HttpRoute) (*ingress_v1alpha.HttpRoute, error)
- func (c *Client) DetachWAFProfile(ctx context.Context, host string) (*ingress_v1alpha.HttpRoute, error)
- func (c *Client) DetachWAFProfileFromRoute(ctx context.Context, route *ingress_v1alpha.HttpRoute) (*ingress_v1alpha.HttpRoute, error)
- func (c *Client) EnsureSingleDefault(ctx context.Context, routeToKeep *ingress_v1alpha.HttpRoute) error
- func (c *Client) GetEntityStore() *entityserver.Client
- func (c *Client) GetOIDCProvider(ctx context.Context, name string) (*ingress_v1alpha.OidcProvider, error)
- func (c *Client) GetPasswordProvider(ctx context.Context, name string) (*ingress_v1alpha.PasswordProvider, error)
- func (c *Client) GetWAFProfileByID(ctx context.Context, id entity.Id) (*ingress_v1alpha.WafProfile, error)
- func (c *Client) List(ctx context.Context) ([]*RouteWithMeta, error)
- func (c *Client) ListOIDCProviders(ctx context.Context) ([]*ingress_v1alpha.OidcProvider, error)
- func (c *Client) ListPasswordProviders(ctx context.Context) ([]*ingress_v1alpha.PasswordProvider, error)
- func (c *Client) Lookup(ctx context.Context, host string) (*ingress_v1alpha.HttpRoute, error)
- func (c *Client) LookupDefault(ctx context.Context) (*ingress_v1alpha.HttpRoute, error)
- func (c *Client) LookupWithWildcard(ctx context.Context, host string) (*ingress_v1alpha.HttpRoute, error)
- func (c *Client) SetDefault(ctx context.Context, appId entity.Id) (*ingress_v1alpha.HttpRoute, error)
- func (c *Client) SetRoute(ctx context.Context, host string, appID entity.Id, services ...string) (*ingress_v1alpha.HttpRoute, error)
- func (c *Client) SetRouteMaintenance(ctx context.Context, route *ingress_v1alpha.HttpRoute, ...) (*ingress_v1alpha.HttpRoute, error)
- func (c *Client) SetRouteRequestTimeout(ctx context.Context, route *ingress_v1alpha.HttpRoute, timeout string) (*ingress_v1alpha.HttpRoute, error)
- func (c *Client) SetRouteTLSCheck(ctx context.Context, route *ingress_v1alpha.HttpRoute, path string) (*ingress_v1alpha.HttpRoute, error)
- func (c *Client) SetRouteWAFLevel(ctx context.Context, host string, level int) (*ingress_v1alpha.HttpRoute, error)
- func (c *Client) SetRouteWAFLevelOnRoute(ctx context.Context, route *ingress_v1alpha.HttpRoute, level int) (*ingress_v1alpha.HttpRoute, error)
- func (c *Client) UnsetDefault(ctx context.Context) (*ingress_v1alpha.HttpRoute, error)
- type RouteWithMeta
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func ExtractSubdomainLabel ¶ added in v0.8.0
ExtractSubdomainLabel extracts an ephemeral label from a request host by comparing it against the route's configured host pattern. For example, if requestHost is "feat-x.app.example.com" and the route host is "*.app.example.com", it returns "feat-x". Returns an empty string if the route is not a wildcard or if there's no subdomain prefix.
func HTTPService ¶ added in v0.15.0
func HTTPService(spec *core_v1alpha.ConfigSpec, service string) error
HTTPService validates that service exists and is HTTP-capable, so a route is only written for a service the launcher will actually serve HTTP from. An omitted port type means HTTP, and web keeps an exemption for the shapes appspec.Build turns into a working port-3000 listener.
The rule is deliberately about the declaration, not about the container port appspec.Build ends up emitting; the two do not correspond exactly. A web service that declares no port at all is admitted even though appspec.Build gives it {3000, type: tcp} when port_type says tcp, because the app is still told PORT=3000 and that is the port the activator falls back to when it finds no HTTP-typed port. A web service that names a port with a non-HTTP type is rejected: nothing lines the app's port up with the activator's fallback, so the route could not serve. See TestHTTPServiceRejectsScalarWebWithUnroutablePort.
func IsWildcardHost ¶ added in v0.14.0
IsWildcardHost reports whether host is a wildcard route pattern (e.g. *.example.com).
func ValidateTLSCheckPath ¶ added in v0.16.0
ValidateTLSCheckPath checks that path is usable as a route's tls_check. It must be an absolute path on the app with no query or fragment, since the ingress appends its own "?domain=" query when it asks. A leading "//" is refused because URL parsing reads it as a host, not a path.
func ValidateWildcardHost ¶ added in v0.6.0
ValidateWildcardHost validates a wildcard host pattern. Valid patterns: *.example.com, *.sub.example.com Invalid: *.com, foo.*.com, **, *
Types ¶
type Client ¶
type Client struct {
// contains filtered or unexported fields
}
Client provides a domain-specific client for HttpRoute entities
func (*Client) AttachAuthProviderToRoute ¶ added in v0.8.0
func (c *Client) AttachAuthProviderToRoute(ctx context.Context, route *ingress_v1alpha.HttpRoute, providerID entity.Id, claimMappings []ingress_v1alpha.ClaimMappings) (*ingress_v1alpha.HttpRoute, error)
AttachAuthProviderToRoute associates an auth provider with an already-resolved route. The providerID should be the entity ID of either an OIDC or password provider.
func (*Client) ClearRouteMaintenance ¶ added in v0.14.0
func (c *Client) ClearRouteMaintenance(ctx context.Context, route *ingress_v1alpha.HttpRoute) (*ingress_v1alpha.HttpRoute, error)
ClearRouteMaintenance returns a route to normal serving. The whole component is dropped, so the reason and operator recorded on entry don't linger on a route that's serving again.
func (*Client) ClearRouteRequestTimeout ¶ added in v0.14.0
func (c *Client) ClearRouteRequestTimeout(ctx context.Context, route *ingress_v1alpha.HttpRoute) (*ingress_v1alpha.HttpRoute, error)
ClearRouteRequestTimeout removes the per-route timeout override, so the route falls back to the server-wide http_request_timeout.
func (*Client) ClearRouteTLSCheck ¶ added in v0.16.0
func (c *Client) ClearRouteTLSCheck(ctx context.Context, route *ingress_v1alpha.HttpRoute) (*ingress_v1alpha.HttpRoute, error)
ClearRouteTLSCheck removes the route's TLS check, so names under it get certificates only when they are live ephemeral deploys.
func (*Client) CreateOrUpdateOIDCProvider ¶ added in v0.4.0
func (c *Client) CreateOrUpdateOIDCProvider(ctx context.Context, provider *ingress_v1alpha.OidcProvider) (*ingress_v1alpha.OidcProvider, error)
CreateOrUpdateOIDCProvider creates or updates an OIDC provider
func (*Client) CreateOrUpdatePasswordProvider ¶ added in v0.8.0
func (c *Client) CreateOrUpdatePasswordProvider(ctx context.Context, provider *ingress_v1alpha.PasswordProvider) (*ingress_v1alpha.PasswordProvider, error)
CreateOrUpdatePasswordProvider creates or updates a password provider
func (*Client) CreateWAFProfile ¶ added in v0.8.0
func (c *Client) CreateWAFProfile(ctx context.Context, level int) (*ingress_v1alpha.WafProfile, error)
func (*Client) DeleteByHost ¶
DeleteByHost deletes an http_route by hostname
func (*Client) DeleteOIDCProvider ¶ added in v0.4.0
DeleteOIDCProvider deletes an OIDC provider by name
func (*Client) DeletePasswordProvider ¶ added in v0.8.0
DeletePasswordProvider deletes a password provider by name
func (*Client) DetachAuthProviderFromRoute ¶ added in v0.8.0
func (c *Client) DetachAuthProviderFromRoute(ctx context.Context, route *ingress_v1alpha.HttpRoute) (*ingress_v1alpha.HttpRoute, error)
DetachAuthProviderFromRoute removes auth provider association from a route
func (*Client) DetachWAFProfile ¶ added in v0.8.0
func (*Client) DetachWAFProfileFromRoute ¶ added in v0.8.0
func (c *Client) DetachWAFProfileFromRoute(ctx context.Context, route *ingress_v1alpha.HttpRoute) (*ingress_v1alpha.HttpRoute, error)
func (*Client) EnsureSingleDefault ¶
func (c *Client) EnsureSingleDefault(ctx context.Context, routeToKeep *ingress_v1alpha.HttpRoute) error
EnsureSingleDefault removes any default routes but the one specified
func (*Client) GetEntityStore ¶ added in v0.4.0
func (c *Client) GetEntityStore() *entityserver.Client
GetEntityStore returns the underlying entity store
func (*Client) GetOIDCProvider ¶ added in v0.4.0
func (c *Client) GetOIDCProvider(ctx context.Context, name string) (*ingress_v1alpha.OidcProvider, error)
GetOIDCProvider looks up an OIDC provider by name
func (*Client) GetPasswordProvider ¶ added in v0.8.0
func (c *Client) GetPasswordProvider(ctx context.Context, name string) (*ingress_v1alpha.PasswordProvider, error)
GetPasswordProvider looks up a password provider by name
func (*Client) GetWAFProfileByID ¶ added in v0.8.0
func (c *Client) GetWAFProfileByID(ctx context.Context, id entity.Id) (*ingress_v1alpha.WafProfile, error)
func (*Client) List ¶
func (c *Client) List(ctx context.Context) ([]*RouteWithMeta, error)
List returns all http_routes with metadata
func (*Client) ListOIDCProviders ¶ added in v0.4.0
func (c *Client) ListOIDCProviders(ctx context.Context) ([]*ingress_v1alpha.OidcProvider, error)
ListOIDCProviders returns all OIDC providers
func (*Client) ListPasswordProviders ¶ added in v0.8.0
func (c *Client) ListPasswordProviders(ctx context.Context) ([]*ingress_v1alpha.PasswordProvider, error)
ListPasswordProviders returns all password providers
func (*Client) LookupDefault ¶
LookupDefault finds the default http_route
func (*Client) LookupWithWildcard ¶ added in v0.6.0
func (c *Client) LookupWithWildcard(ctx context.Context, host string) (*ingress_v1alpha.HttpRoute, error)
LookupWithWildcard finds an http_route by hostname with wildcard fallback. It tries in order: exact match, then wildcard subdomain (*.rest). A wildcard like *.example.com matches foo.example.com but not example.com itself.
func (*Client) SetDefault ¶
func (c *Client) SetDefault(ctx context.Context, appId entity.Id) (*ingress_v1alpha.HttpRoute, error)
SetDefault sets the default route to the provided app
func (*Client) SetRoute ¶
func (c *Client) SetRoute(ctx context.Context, host string, appID entity.Id, services ...string) (*ingress_v1alpha.HttpRoute, error)
SetRoute creates or updates an http_route for the given host, app, and service. A caller that supplies a service gets active-configuration validation at the ingress write boundary. Calls without one retain the legacy web route shape.
func (*Client) SetRouteMaintenance ¶ added in v0.14.0
func (c *Client) SetRouteMaintenance(ctx context.Context, route *ingress_v1alpha.HttpRoute, reason, backAt, startedAt, startedBy string) (*ingress_v1alpha.HttpRoute, error)
SetRouteMaintenance puts a route into maintenance. The router serves a holding page for the route until the state is cleared.
reason and backAt always take effect. startedAt and startedBy are a proposal: they are recorded only if the route is not already in maintenance, so revising the reason mid-window leaves the original opener and start time alone.
That decision happens here, inside the read-modify-write, rather than in the caller. A caller deciding it from its own earlier read can be wrong by the time the write lands: two operators opening a window at once would both see "not in maintenance", and the second write would replace the first operator's stamp with its own.
func (*Client) SetRouteRequestTimeout ¶ added in v0.14.0
func (c *Client) SetRouteRequestTimeout(ctx context.Context, route *ingress_v1alpha.HttpRoute, timeout string) (*ingress_v1alpha.HttpRoute, error)
SetRouteRequestTimeout sets the per-route ingress request timeout override. The timeout is stored as a duration string (e.g. "10m") and must parse to a positive duration.
func (*Client) SetRouteTLSCheck ¶ added in v0.16.0
func (c *Client) SetRouteTLSCheck(ctx context.Context, route *ingress_v1alpha.HttpRoute, path string) (*ingress_v1alpha.HttpRoute, error)
SetRouteTLSCheck sets the path the ingress asks before issuing an on-demand certificate for a name under this route.
func (*Client) SetRouteWAFLevel ¶ added in v0.8.0
func (*Client) SetRouteWAFLevelOnRoute ¶ added in v0.8.0
func (c *Client) SetRouteWAFLevelOnRoute(ctx context.Context, route *ingress_v1alpha.HttpRoute, level int) (*ingress_v1alpha.HttpRoute, error)
func (*Client) UnsetDefault ¶
UnsetDefault unsets the default route, if any. It returns the route that it unset the default from.
type RouteWithMeta ¶
type RouteWithMeta struct {
Route *ingress_v1alpha.HttpRoute
CreatedAt int64
UpdatedAt int64
}
RouteWithMeta includes an http_route with its metadata