chart: bind the HTTPRoute to a named gateway listener
Release / test (push) Failing after 7s
Release / build (amd64, darwin) (push) Has been skipped
Release / build (amd64, linux) (push) Has been skipped
Release / build (arm64, darwin) (push) Has been skipped
Release / build (arm64, linux) (push) Has been skipped
Release / docker (push) Has been skipped
Release / chart (push) Has been skipped
Release / release (push) Has been skipped

The route carried no sectionName, so it attached to every listener whose
hostname matched — including the hostname-less plaintext HTTP listener.
On a publicly reachable hostname that means the API accepts bearer tokens
over cleartext.

networking.listener names the listener to bind to. It defaults to empty,
which keeps the previous attach-to-all behaviour.

Also document the Kubernetes install path, which the README omitted.
This commit is contained in:
Niklas Ye
2026-08-06 12:01:13 +02:00
parent be739c319f
commit dcb2a86f9a
4 changed files with 33 additions and 1 deletions
+1 -1
View File
@@ -2,5 +2,5 @@ apiVersion: v2
name: terdut-server
description: A Helm chart for Terminal Duty — on-call alert management server
type: application
version: 0.2.0
version: 0.5.0
appVersion: "latest"
@@ -9,6 +9,9 @@ spec:
parentRefs:
- name: envoy-main
namespace: envoy-gateway-system
{{- with .Values.networking.listener }}
sectionName: {{ . | quote }}
{{- end }}
rules:
- backendRefs:
- name: {{ include "terdut-server.fullname" . }}
+4
View File
@@ -1,6 +1,10 @@
networking:
hostname: "terdut.example.com"
servicePort: 8080
# Gateway listener to bind the HTTPRoute to. Empty attaches to every matching
# listener, including plaintext HTTP. Set this to the name of the HTTPS
# listener to serve the API over TLS only.
listener: ""
image:
repository: ghcr.io/yeniklas/terdut-server