From dcb2a86f9a4900137c942f75ca9145e25b173834 Mon Sep 17 00:00:00 2001 From: Niklas Ye Date: Thu, 6 Aug 2026 12:01:13 +0200 Subject: [PATCH] chart: bind the HTTPRoute to a named gateway listener MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The route carried no sectionName, so it attached to every listener whose hostname matched — including the hostname-less plaintext HTTP listener. On a publicly reachable hostname that means the API accepts bearer tokens over cleartext. networking.listener names the listener to bind to. It defaults to empty, which keeps the previous attach-to-all behaviour. Also document the Kubernetes install path, which the README omitted. --- README.md | 25 +++++++++++++++++++ charts/terdut-server/Chart.yaml | 2 +- charts/terdut-server/templates/httpproxy.yaml | 3 +++ charts/terdut-server/values.yaml | 4 +++ 4 files changed, 33 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index e185bb4..04bc8c8 100644 --- a/README.md +++ b/README.md @@ -50,6 +50,31 @@ docker run -p 8080:8080 -v $(pwd)/data:/data \ terdut-server ``` +### Kubernetes + +A Helm chart is published from this repository: + +```bash +helm repo add terdut-server https://yeniklas.github.io/terdut-server +helm upgrade --install terdut-server terdut-server/terdut-server \ + --namespace terdut-server --create-namespace \ + --set networking.hostname=terdut.example.com +``` + +The chart expects a [Gateway API](https://gateway-api.sigs.k8s.io/) Gateway named `envoy-main` in +the `envoy-gateway-system` namespace to already exist — it renders an `HTTPRoute` against it rather +than an `Ingress`. TLS is terminated at the gateway, so the server itself never sees a certificate. + +| Value | Default | Description | +|---|---|---| +| `networking.hostname` | `terdut.example.com` | Hostname the `HTTPRoute` serves | +| `networking.listener` | `""` | Gateway listener (`sectionName`) to bind to. Empty attaches to every matching listener, **including plaintext HTTP** — set it to the HTTPS listener's name to serve TLS only | +| `networking.servicePort` | `8080` | Port the route forwards to; keep in sync with `service.port` | +| `bootstrap.enabled` | `true` | Runs a post-install hook that creates the first user and stores its API key in the `-admin-key` Secret. Already-bootstrapped servers are left alone | + +The API key travels in an `Authorization: Bearer` header, so set `networking.listener` whenever the +hostname is reachable outside a trusted network. + --- ## Configuration diff --git a/charts/terdut-server/Chart.yaml b/charts/terdut-server/Chart.yaml index 98e8a4d..0b8ad33 100644 --- a/charts/terdut-server/Chart.yaml +++ b/charts/terdut-server/Chart.yaml @@ -2,5 +2,5 @@ apiVersion: v2 name: terdut-server description: A Helm chart for Terminal Duty — on-call alert management server type: application -version: 0.2.0 +version: 0.5.0 appVersion: "latest" diff --git a/charts/terdut-server/templates/httpproxy.yaml b/charts/terdut-server/templates/httpproxy.yaml index 2d06fd7..9881b2f 100644 --- a/charts/terdut-server/templates/httpproxy.yaml +++ b/charts/terdut-server/templates/httpproxy.yaml @@ -9,6 +9,9 @@ spec: parentRefs: - name: envoy-main namespace: envoy-gateway-system + {{- with .Values.networking.listener }} + sectionName: {{ . | quote }} + {{- end }} rules: - backendRefs: - name: {{ include "terdut-server.fullname" . }} diff --git a/charts/terdut-server/values.yaml b/charts/terdut-server/values.yaml index d1e4bc9..35ab810 100644 --- a/charts/terdut-server/values.yaml +++ b/charts/terdut-server/values.yaml @@ -1,6 +1,10 @@ networking: hostname: "terdut.example.com" servicePort: 8080 + # Gateway listener to bind the HTTPRoute to. Empty attaches to every matching + # listener, including plaintext HTTP. Set this to the name of the HTTPS + # listener to serve the API over TLS only. + listener: "" image: repository: ghcr.io/yeniklas/terdut-server