ingress

package
v0.16.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 29, 2026 License: Apache-2.0 Imports: 16 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func ExtractSubdomainLabel added in v0.8.0

func ExtractSubdomainLabel(requestHost, routeHost string) string

ExtractSubdomainLabel extracts an ephemeral label from a request host by comparing it against the route's configured host pattern. For example, if requestHost is "feat-x.app.example.com" and the route host is "*.app.example.com", it returns "feat-x". Returns an empty string if the route is not a wildcard or if there's no subdomain prefix.

func HTTPService added in v0.15.0

func HTTPService(spec *core_v1alpha.ConfigSpec, service string) error

HTTPService validates that service exists and is HTTP-capable, so a route is only written for a service the launcher will actually serve HTTP from. An omitted port type means HTTP, and web keeps an exemption for the shapes appspec.Build turns into a working port-3000 listener.

The rule is deliberately about the declaration, not about the container port appspec.Build ends up emitting; the two do not correspond exactly. A web service that declares no port at all is admitted even though appspec.Build gives it {3000, type: tcp} when port_type says tcp, because the app is still told PORT=3000 and that is the port the activator falls back to when it finds no HTTP-typed port. A web service that names a port with a non-HTTP type is rejected: nothing lines the app's port up with the activator's fallback, so the route could not serve. See TestHTTPServiceRejectsScalarWebWithUnroutablePort.

func IsWildcardHost added in v0.14.0

func IsWildcardHost(host string) bool

IsWildcardHost reports whether host is a wildcard route pattern (e.g. *.example.com).

func ValidateTLSCheckPath added in v0.16.0

func ValidateTLSCheckPath(path string) error

ValidateTLSCheckPath checks that path is usable as a route's tls_check. It must be an absolute path on the app with no query or fragment, since the ingress appends its own "?domain=" query when it asks. A leading "//" is refused because URL parsing reads it as a host, not a path.

func ValidateWildcardHost added in v0.6.0

func ValidateWildcardHost(host string) error

ValidateWildcardHost validates a wildcard host pattern. Valid patterns: *.example.com, *.sub.example.com Invalid: *.com, foo.*.com, **, *

Types

type Client

type Client struct {
	// contains filtered or unexported fields
}

Client provides a domain-specific client for HttpRoute entities

func NewClient

func NewClient(log *slog.Logger, client rpc.Client) *Client

NewClient creates a new Ingress client from an RPC client

func (*Client) AttachAuthProviderToRoute added in v0.8.0

func (c *Client) AttachAuthProviderToRoute(ctx context.Context, route *ingress_v1alpha.HttpRoute, providerID entity.Id, claimMappings []ingress_v1alpha.ClaimMappings) (*ingress_v1alpha.HttpRoute, error)

AttachAuthProviderToRoute associates an auth provider with an already-resolved route. The providerID should be the entity ID of either an OIDC or password provider.

func (*Client) ClearRouteMaintenance added in v0.14.0

func (c *Client) ClearRouteMaintenance(ctx context.Context, route *ingress_v1alpha.HttpRoute) (*ingress_v1alpha.HttpRoute, error)

ClearRouteMaintenance returns a route to normal serving. The whole component is dropped, so the reason and operator recorded on entry don't linger on a route that's serving again.

func (*Client) ClearRouteRequestTimeout added in v0.14.0

func (c *Client) ClearRouteRequestTimeout(ctx context.Context, route *ingress_v1alpha.HttpRoute) (*ingress_v1alpha.HttpRoute, error)

ClearRouteRequestTimeout removes the per-route timeout override, so the route falls back to the server-wide http_request_timeout.

func (*Client) ClearRouteTLSCheck added in v0.16.0

func (c *Client) ClearRouteTLSCheck(ctx context.Context, route *ingress_v1alpha.HttpRoute) (*ingress_v1alpha.HttpRoute, error)

ClearRouteTLSCheck removes the route's TLS check, so names under it get certificates only when they are live ephemeral deploys.

func (*Client) CreateOrUpdateOIDCProvider added in v0.4.0

func (c *Client) CreateOrUpdateOIDCProvider(ctx context.Context, provider *ingress_v1alpha.OidcProvider) (*ingress_v1alpha.OidcProvider, error)

CreateOrUpdateOIDCProvider creates or updates an OIDC provider

func (*Client) CreateOrUpdatePasswordProvider added in v0.8.0

func (c *Client) CreateOrUpdatePasswordProvider(ctx context.Context, provider *ingress_v1alpha.PasswordProvider) (*ingress_v1alpha.PasswordProvider, error)

CreateOrUpdatePasswordProvider creates or updates a password provider

func (*Client) CreateWAFProfile added in v0.8.0

func (c *Client) CreateWAFProfile(ctx context.Context, level int) (*ingress_v1alpha.WafProfile, error)

func (*Client) DeleteByHost

func (c *Client) DeleteByHost(ctx context.Context, host string) error

DeleteByHost deletes an http_route by hostname

func (*Client) DeleteOIDCProvider added in v0.4.0

func (c *Client) DeleteOIDCProvider(ctx context.Context, name string) error

DeleteOIDCProvider deletes an OIDC provider by name

func (*Client) DeletePasswordProvider added in v0.8.0

func (c *Client) DeletePasswordProvider(ctx context.Context, name string) error

DeletePasswordProvider deletes a password provider by name

func (*Client) DetachAuthProviderFromRoute added in v0.8.0

func (c *Client) DetachAuthProviderFromRoute(ctx context.Context, route *ingress_v1alpha.HttpRoute) (*ingress_v1alpha.HttpRoute, error)

DetachAuthProviderFromRoute removes auth provider association from a route

func (*Client) DetachWAFProfile added in v0.8.0

func (c *Client) DetachWAFProfile(ctx context.Context, host string) (*ingress_v1alpha.HttpRoute, error)

func (*Client) DetachWAFProfileFromRoute added in v0.8.0

func (c *Client) DetachWAFProfileFromRoute(ctx context.Context, route *ingress_v1alpha.HttpRoute) (*ingress_v1alpha.HttpRoute, error)

func (*Client) EnsureSingleDefault

func (c *Client) EnsureSingleDefault(ctx context.Context, routeToKeep *ingress_v1alpha.HttpRoute) error

EnsureSingleDefault removes any default routes but the one specified

func (*Client) GetEntityStore added in v0.4.0

func (c *Client) GetEntityStore() *entityserver.Client

GetEntityStore returns the underlying entity store

func (*Client) GetOIDCProvider added in v0.4.0

func (c *Client) GetOIDCProvider(ctx context.Context, name string) (*ingress_v1alpha.OidcProvider, error)

GetOIDCProvider looks up an OIDC provider by name

func (*Client) GetPasswordProvider added in v0.8.0

func (c *Client) GetPasswordProvider(ctx context.Context, name string) (*ingress_v1alpha.PasswordProvider, error)

GetPasswordProvider looks up a password provider by name

func (*Client) GetWAFProfileByID added in v0.8.0

func (c *Client) GetWAFProfileByID(ctx context.Context, id entity.Id) (*ingress_v1alpha.WafProfile, error)

func (*Client) List

func (c *Client) List(ctx context.Context) ([]*RouteWithMeta, error)

List returns all http_routes with metadata

func (*Client) ListOIDCProviders added in v0.4.0

func (c *Client) ListOIDCProviders(ctx context.Context) ([]*ingress_v1alpha.OidcProvider, error)

ListOIDCProviders returns all OIDC providers

func (*Client) ListPasswordProviders added in v0.8.0

func (c *Client) ListPasswordProviders(ctx context.Context) ([]*ingress_v1alpha.PasswordProvider, error)

ListPasswordProviders returns all password providers

func (*Client) Lookup

func (c *Client) Lookup(ctx context.Context, host string) (*ingress_v1alpha.HttpRoute, error)

Lookup finds an http_route by hostname, returns nil if not found

func (*Client) LookupDefault

func (c *Client) LookupDefault(ctx context.Context) (*ingress_v1alpha.HttpRoute, error)

LookupDefault finds the default http_route

func (*Client) LookupWithWildcard added in v0.6.0

func (c *Client) LookupWithWildcard(ctx context.Context, host string) (*ingress_v1alpha.HttpRoute, error)

LookupWithWildcard finds an http_route by hostname with wildcard fallback. It tries in order: exact match, then wildcard subdomain (*.rest). A wildcard like *.example.com matches foo.example.com but not example.com itself.

func (*Client) SetDefault

func (c *Client) SetDefault(ctx context.Context, appId entity.Id) (*ingress_v1alpha.HttpRoute, error)

SetDefault sets the default route to the provided app

func (*Client) SetRoute

func (c *Client) SetRoute(ctx context.Context, host string, appID entity.Id, services ...string) (*ingress_v1alpha.HttpRoute, error)

SetRoute creates or updates an http_route for the given host, app, and service. A caller that supplies a service gets active-configuration validation at the ingress write boundary. Calls without one retain the legacy web route shape.

func (*Client) SetRouteMaintenance added in v0.14.0

func (c *Client) SetRouteMaintenance(ctx context.Context, route *ingress_v1alpha.HttpRoute, reason, backAt, startedAt, startedBy string) (*ingress_v1alpha.HttpRoute, error)

SetRouteMaintenance puts a route into maintenance. The router serves a holding page for the route until the state is cleared.

reason and backAt always take effect. startedAt and startedBy are a proposal: they are recorded only if the route is not already in maintenance, so revising the reason mid-window leaves the original opener and start time alone.

That decision happens here, inside the read-modify-write, rather than in the caller. A caller deciding it from its own earlier read can be wrong by the time the write lands: two operators opening a window at once would both see "not in maintenance", and the second write would replace the first operator's stamp with its own.

func (*Client) SetRouteRequestTimeout added in v0.14.0

func (c *Client) SetRouteRequestTimeout(ctx context.Context, route *ingress_v1alpha.HttpRoute, timeout string) (*ingress_v1alpha.HttpRoute, error)

SetRouteRequestTimeout sets the per-route ingress request timeout override. The timeout is stored as a duration string (e.g. "10m") and must parse to a positive duration.

func (*Client) SetRouteTLSCheck added in v0.16.0

func (c *Client) SetRouteTLSCheck(ctx context.Context, route *ingress_v1alpha.HttpRoute, path string) (*ingress_v1alpha.HttpRoute, error)

SetRouteTLSCheck sets the path the ingress asks before issuing an on-demand certificate for a name under this route.

func (*Client) SetRouteWAFLevel added in v0.8.0

func (c *Client) SetRouteWAFLevel(ctx context.Context, host string, level int) (*ingress_v1alpha.HttpRoute, error)

func (*Client) SetRouteWAFLevelOnRoute added in v0.8.0

func (c *Client) SetRouteWAFLevelOnRoute(ctx context.Context, route *ingress_v1alpha.HttpRoute, level int) (*ingress_v1alpha.HttpRoute, error)

func (*Client) UnsetDefault

func (c *Client) UnsetDefault(ctx context.Context) (*ingress_v1alpha.HttpRoute, error)

UnsetDefault unsets the default route, if any. It returns the route that it unset the default from.

type RouteWithMeta

type RouteWithMeta struct {
	Route     *ingress_v1alpha.HttpRoute
	CreatedAt int64
	UpdatedAt int64
}

RouteWithMeta includes an http_route with its metadata

Directories

Path Synopsis

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL