Skip to content

Releases: max3584/rproxy-gateway

v0.4.7

Choose a tag to compare

@github-actions github-actions released this 10 Oct 08:22
8846d2f

修正

  • Gateway API v1.0・v1.1 の CRD でも動くようになりました(#63):これらの CRD では GatewayClass の status.supportedFeatures の形が v1.2 以降と違い、API サーバが status を丸ごと断っていました。GatewayClass が Accepted にならず、何も動きませんでした。今は断られたら supportedFeatures を外して書き直します。
    • v1.0 では、Gateway ごとの RproxyGatewayParameters(Gateway の infrastructure.parametersRef、v1.1 から)は使えません。GatewayClass の parametersRef は使えます。
    • v1.1 では GRPCRoute がまだ動きません(#61)。

変更

  • 対応する版(README の「対応する版」):Gateway API の CRD は v1.0 から、Kubernetes は chart の範囲(1.29 以上)の最新(1.37.1)まで確かめています。互換性テストは毎週、その時点の最新の Kubernetes・Gateway API まで自動で回ります。

rproxy: rproxy-api v0.4.5 · UI: TCP-UDP-rproxy-ui v0.4.2


Fixed

  • Gateway API v1.0 and v1.1 CRDs work (#63): their GatewayClass status.supportedFeatures has a different shape from v1.2 on, and the API server refused the whole status, so the GatewayClass was never Accepted and nothing worked. A refused status is now written again without supportedFeatures.
    • On v1.0, per-Gateway RproxyGatewayParameters (Gateway infrastructure.parametersRef, from v1.1) are not available; the GatewayClass parametersRef is.
    • On v1.1, GRPCRoute does not work yet (#61).

Changed

  • Supported versions (README "Supported versions"): Gateway API CRDs from v1.0, and Kubernetes across the chart's range (1.29 and later) up to the newest (1.37.1). The compatibility run goes every week up to the newest Kubernetes and Gateway API released at that time.

rproxy: rproxy-api v0.4.5 · UI: TCP-UDP-rproxy-ui v0.4.2

v0.4.6

Choose a tag to compare

@github-actions github-actions released this 09 Oct 16:43
33c07fb

追加

  • 古い Gateway API の CRD に対応(#58):Gateway API v1.2〜v1.5 の CRD(TCPRoute・UDPRoute が v1alpha2 だけ、v1.4 の TLSRoute が v1alpha3、ReferenceGrant が v1beta1 など)も見つけて扱います。前は v1 か推奨の版がない種類を見落としていました。対応する Kubernetes と Gateway API の版は README の「対応する版」の表にあります(Kubernetes 1.29〜1.37、Gateway API v1.2〜v1.7)。
  • rproxy は rproxy-api v0.4.5 になりました(イメージ ghcr.io/max3584/rproxy-gateway/rproxy:0.4.5)。UDP のセッションのメモリが 1 セッションあたり約 58 KiB から約 12 KiB に減ります。

修正

  • UDP の転送先が ICMP の到達不能を返したとき、その転送先に気づくようになりました(rproxy-api v0.4.5)。

rproxy: rproxy-api v0.4.5 · UI: TCP-UDP-rproxy-ui v0.4.2


Added

  • Older Gateway API CRDs (#58): resources from Gateway API v1.2 to v1.5 CRDs are found and handled too (TCPRoute and UDPRoute only as v1alpha2, TLSRoute as v1alpha3 in v1.4, ReferenceGrant as v1beta1, and so on). Before, kinds without v1 or a recommended version were missed. Supported Kubernetes and Gateway API versions are in the README "Supported versions" table (Kubernetes 1.29 to 1.37, Gateway API v1.2 to v1.7).
  • rproxy is now rproxy-api v0.4.5 (image ghcr.io/max3584/rproxy-gateway/rproxy:0.4.5): UDP session memory goes from about 58 KiB to about 12 KiB per session.

Fixed

  • A UDP backend answering with ICMP port unreachable is now noticed (rproxy-api v0.4.5).

rproxy: rproxy-api v0.4.5 · UI: TCP-UDP-rproxy-ui v0.4.2

v0.4.5

Choose a tag to compare

@github-actions github-actions released this 09 Oct 06:34
904ce74

追加

  • Gateway API の機能を足しました(conformance の GATEWAY-HTTP の extended は 58/58)。
    • 同じポートの HTTPS のリスナーの名前違いのリクエストに 421(GatewayHTTPSListenerDetectMisdirectedRequests、#48)。
    • backendRef の CORS・RequestRedirect・RequestMirror のフィルタ(#49)。
    • HTTPRoute の ExternalAuth フィルタ(HTTP・gRPC、forwardBody、backendRef の上でも。#51)。Gateway API v1.6.3 にはこの機能の conformance の試験がないので、レポートには出ません。
  • fleet で、Gateway ごとのアドレスで待ち受けられるようになりました(#47)。fleet.listen: addresses のとき、spec.addresses(addressCIDRs の内)を持つ Gateway はそのアドレスで待ち受けるので、同じポートを別のアドレスの Gateway で使えます。アドレスはプラットフォーム(keepalived・kube-vip・MetalLB など)が用意します(docs/PLATFORM.md)。
  • 送り先の障害に早く気づくようにしました(#50・#55)。
    • 受け身のヘルスチェックを既定で有効にしました(HTTP:gateway の失敗 3 回、L4:1 回で外し、10 秒から最大 1 分)。
    • 送り先への接続のタイムアウトの既定を 1 秒にしました。
    • HTTPRoute の規則に timeouts がないとき、応答の時間切れの既定を 30 秒にしました(応答ヘッダが届くまでの時間。ダウンロード・SSE・WebSocket は切りません。GRPCRoute には付けません)。chart の backends.* で変えられます。
    • EndpointSlice は ready の宛先を使い、ready が 1 つもないときだけ終了中の宛先を使います。
    • RproxyPolicy に connectTimeout・responseTimeout を足しました。
  • プラットフォームの設定の文書 docs/PLATFORM.md(日英):MetalLB・kube-vip・Cilium・クラウドの LB・NodePort と HAProxy・fleet とノードの keepalived・ClusterIP の設定例と、構成ごとの途切れの目安。
  • rproxy を rproxy-api v0.4.3 にしました(イメージ ghcr.io/max3584/rproxy-gateway/rproxy:0.4.3)。

変更

  • v0.4.4 の組み込みの VIP(fleet.vip)を外しました(#54)。既定で切っていて、1 日だけ出していた機能のため、パッチで外します。アドレスはプラットフォームに任せてください(docs/PLATFORM.md に移り方と片付けの手順)。fleet.vip を設定したままの helm upgrade は、案内のエラーで止まります。
  • rproxy の CRD を v1beta1 にしました(#52)。保存する版は v1beta1 で、v1alpha1 も同じ形で受け付けます(非推奨)。今のオブジェクトはそのまま使えます。保存の版の移し方は docs/DESIGN-v0.4.x.md の 11.4。新しい CRD は helm upgrade の前に入れてください。
  • 受け身のヘルスチェック・接続のタイムアウト・応答の時間切れの既定は、今ある Gateway にも付きます(接続を切らずに変わります)。RproxyPolicy や HTTPRoute の timeouts があれば、そちらが勝ちます。
  • fleet の Gateway どうしのポートの取り合いは、古い Gateway が持ちます(後の Gateway のリスナーは PortUnavailable)。

rproxy: rproxy-api v0.4.3 · UI: TCP-UDP-rproxy-ui v0.4.2


Added

  • More Gateway API features (GATEWAY-HTTP extended now 58/58 in conformance).
    • 421 for misdirected requests across HTTPS listeners on one port (GatewayHTTPSListenerDetectMisdirectedRequests, #48).
    • backendRef filters CORS, RequestRedirect and RequestMirror (#49).
    • HTTPRoute ExternalAuth (HTTP and gRPC, forwardBody, also on backendRefs; #51). Gateway API v1.6.3 has no conformance test for it, so it does not appear in the report.
  • fleet listens on each Gateway's own addresses (#47): with fleet.listen: addresses, a Gateway with spec.addresses (within addressCIDRs) listens on them, so Gateways on different addresses can share a port. The platform (keepalived, kube-vip, MetalLB, …) provides the addresses (docs/en/PLATFORM.md).
  • Backend failures are noticed sooner (#50, #55).
    • Passive health checks are on by default (HTTP: out after 3 gateway errors, L4: after 1; 10 s doubling up to 1 min).
    • Backend connect timeout defaults to 1 s.
    • Without timeouts on an HTTPRoute rule, a 30 s response timeout applies (time to response headers; downloads, SSE and WebSockets are not cut; not set on GRPCRoute). Change it with the chart's backends.*.
    • EndpointSlices: ready endpoints are used; terminating ones only when none is ready.
    • RproxyPolicy gains connectTimeout and responseTimeout.
  • Platform guide docs/en/PLATFORM.md: examples for MetalLB, kube-vip, Cilium, cloud LBs, NodePort with HAProxy, fleet with keepalived on the nodes, and ClusterIP, with expected gaps per setup.
  • rproxy is now rproxy-api v0.4.3 (image ghcr.io/max3584/rproxy-gateway/rproxy:0.4.3).

Changed

  • The built-in VIP of v0.4.4 (fleet.vip) is removed (#54). It was off by default and shipped for one day, so it goes in a patch; leave addresses to the platform (migration and cleanup in docs/en/PLATFORM.md). helm upgrade with fleet.vip still set stops with a pointer to the docs.
  • rproxy CRDs are v1beta1 (#52): v1beta1 is the storage version and v1alpha1 is still served with the same schema (deprecated); existing objects keep working. Storage migration is in docs/en/DESIGN-v0.4.x.md 11.4. Install the new CRDs before helm upgrade.
  • The passive health check, connect timeout and response timeout defaults apply to existing Gateways too (changed live, connections kept). RproxyPolicy or HTTPRoute timeouts win when set.
  • Port conflicts between fleet Gateways go to the older Gateway (the newer listener gets PortUnavailable).

rproxy: rproxy-api v0.4.3 · UI: TCP-UDP-rproxy-ui v0.4.2

v0.4.4

Choose a tag to compare

@github-actions github-actions released this 08 Oct 17:13
94390af

追加

  • fleet の rproxy の Pod が VIP を直接持てるようになりました(#43・#44)。chart の fleet.vip(既定は off)。
    • Pod ごとの vip コンテナ(rproxy-gateway vip)が、VIP ごとに Kubernetes の Lease でリーダーを選び、自分のノードに VIP を付けて gratuitous ARP(IPv6 は unsolicited NA)で知らせます。
    • VIP を持つのは、rproxy が準備を終え(/readyz)、コントローラがルールを当て終えた Pod だけです。rproxy が止まり始めたとき・Pod の終了・ノードの cordon では、先に VIP を外してから Lease を空けます。計画した移動(Pod の削除・入れ替え・drain)は 1 秒未満で移ります(受け入れテストで 0.1〜1.2 秒の途切れ)。
    • Kubernetes の API サーバに届かないときは、既定で VIP を持ち続けます(hold、release も選べます)。ほかの機械が同じ VIP を告げたら手放します。
    • Lease の既定:期限 3 秒・更新 1 秒・やり直し 0.5 秒。
    • VIP は管理者が fleet.vip.addresses に並べたものだけで、Gateway の spec.addresses はその中から選びます(addressCIDRs の外や、Service・ノードと重なるものは使いません)。持ち主のいない VIP を使う Gateway は Programmed: False(AddressNotUsable)。
    • Kustomize の例 config/samples/fleet-vip。
  • rproxy を rproxy-api v0.4.2 にしました(イメージ ghcr.io/max3584/rproxy-gateway/rproxy:0.4.2)(#45)。

変更

  • rproxy v0.4.2 はトークンファイルを自分で読み直すので、UI を有効・無効にしても Pod を入れ替えません。fleet でも手での rollout restart は要りません。UI の一覧には、UI のトークンを受け付けると確かめた Pod だけを載せます。
  • VIP を使うとき、vip コンテナは NET_ADMIN・NET_RAW と、自分の Pod・ノードを読む権限、Lease の権限を持ちます。fleet の namespace の PodSecurity は privileged が要ります(docs/SECURITY.md)。VIP を使わない入れ方は変わりません。

rproxy: rproxy-api v0.4.2 · UI: TCP-UDP-rproxy-ui v0.4.2


Added

  • fleet rproxy pods can hold VIPs directly (#43, #44), chart fleet.vip (off by default).
    • A vip container per pod (rproxy-gateway vip) elects a leader per VIP with a Kubernetes Lease, adds the VIP on its node and announces it with gratuitous ARP (unsolicited NA for IPv6).
    • Only a pod whose rproxy is ready (/readyz) and has its rule sets applied holds a VIP. When rproxy starts stopping, the pod terminates or the node is cordoned, the VIP is removed first and then the Lease released. Planned moves (pod deletion, rollout, drain) hand over in under a second (0.1–1.2 s gaps in the acceptance test).
    • If the Kubernetes API server is unreachable the VIP is kept by default (hold; release is available). Another machine announcing the same VIP makes it let go.
    • Lease defaults: duration 3 s, renew 1 s, retry 0.5 s.
    • VIPs are only those an admin lists in fleet.vip.addresses; a Gateway's spec.addresses picks from them (never outside addressCIDRs, nor overlapping Services or nodes). A Gateway on a VIP without a holder gets Programmed: False (AddressNotUsable).
    • Kustomize example config/samples/fleet-vip.
  • rproxy is now rproxy-api v0.4.2 (image ghcr.io/max3584/rproxy-gateway/rproxy:0.4.2) (#45).

Changed

  • rproxy v0.4.2 re-reads its token file, so enabling or disabling the UI no longer rolls pods, and fleet no longer needs a manual rollout restart. The UI list only includes pods confirmed to accept the UI token.
  • With VIPs, the vip container has NET_ADMIN, NET_RAW, read access to its own pod and node, and Lease permissions; the fleet namespace needs the privileged PodSecurity level (docs/en/SECURITY.md). Installs without VIPs are unchanged.

rproxy: rproxy-api v0.4.2 · UI: TCP-UDP-rproxy-ui v0.4.2

v0.4.3

Choose a tag to compare

@github-actions github-actions released this 08 Oct 15:18
aa453ef

追加

  • UI(TCP-UDP-rproxy-ui v0.4.2)から Kubernetes の rproxy を見られるようになりました(#41)。
    • chart の ui.namespace(--ui-namespace)を設定すると、その namespace に Secret rproxy-ui-discovery(rproxy の Pod の一覧・CA・読むだけのトークン)を書きます。中身が変わったときだけ更新し、見せる Gateway がなくなれば消します。
    • 見せるのは、ui.namespace があり、Gateway の parameters で ui.visible が false でないものだけです。
    • トークンは rules:read・metrics:read だけで、書き込みは rproxy が 403 で断ります。
    • 一覧には、トークンを受け付けられる Pod だけを載せます(Ready・ルールを当て終えた・終了中でない・今のトークンで起動した Pod)。
    • 見せる Gateway の NetworkPolicy に、UI の Pod(ui.podSelector、既定 app.kubernetes.io/name: rproxy-ui・app.kubernetes.io/component: ui)から制御 API への許可を足します。Secret の権限は UI の namespace の Role だけです。

変更

  • UI を有効・無効にしたとき、Gateway を見せる・隠すときに、その Gateway の rproxy の Pod が 1 回入れ替わります(rproxy がトークンファイルを起動時に読むため。2 つ以上なら途切れは 1 秒未満)。fleet は、UI のトークンを足したあとに DaemonSet を rollout restart してください。
  • ui.namespace を外したときは、前の namespace の rproxy-ui-discovery を手で消してください。

rproxy: rproxy-api v0.4.1 · UI: TCP-UDP-rproxy-ui v0.4.2


Added

  • The UI (TCP-UDP-rproxy-ui v0.4.2) can show Kubernetes rproxy (#41).
    • With the chart's ui.namespace (--ui-namespace), the controller writes Secret rproxy-ui-discovery (rproxy pods, CA, a read-only token) into that namespace, updates it only on change, and removes it when no Gateway is shown.
    • Shown only when ui.namespace is set and the Gateway's parameters do not set ui.visible: false.
    • The token has only rules:read and metrics:read; rproxy refuses writes with 403.
    • Only pods that accept the token are listed (Ready, rule set applied, not terminating, started with the current token).
    • Shown Gateways' NetworkPolicy lets the UI pods (ui.podSelector, default app.kubernetes.io/name: rproxy-ui and app.kubernetes.io/component: ui) reach the control API. Secret permissions are a Role in the UI namespace only.

Changed

  • Enabling or disabling the UI, or showing or hiding a Gateway, rolls that Gateway's rproxy pods once (rproxy reads its token file at start; under a second of gap with 2+ replicas). For fleet, rollout restart the DaemonSet after adding the UI token.
  • After removing ui.namespace, delete the old namespace's rproxy-ui-discovery by hand.

rproxy: rproxy-api v0.4.1 · UI: TCP-UDP-rproxy-ui v0.4.2

v0.4.2

Choose a tag to compare

@github-actions github-actions released this 08 Oct 12:57
502351a

追加

  • Gateway ごとに managed の rproxy の形を変えられるようになりました(#36)。新しい CRD RproxyGatewayParameters(短縮名 rpgwp)。
    • GatewayClass の parametersRef(コントローラの namespace のもの)で既定を、Gateway の spec.infrastructure.parametersRef(同じ namespace のもの)で上書きを指定します。
    • replicas・resources・PDB・topologySpread・probe・停止の時間などを Gateway ごとに変えられます。nodeSelector・tolerations・affinity・priorityClass・Service の種類などは、クラスの policy で許したときだけ利用者が変えられます。イメージと環境変数はクラスだけが決めます。
    • 誤りは Accepted: False(InvalidParameters、項目の名前つき)。すでに動いている rproxy は、参照が誤りになっても最後の正しい形のまま動かし続けます。
    • namespace の admin に parameters を編集する権限を足す ClusterRole(rbac.aggregateToAdmin)。
  • Kustomize で入れられるようになりました(#37)。
    • リリースに install.yaml・install-fleet.yaml・crds.yaml を添付します。
    • リポジトリの config/(default・fleet・crd)を Kustomize の土台として使えます。config/samples/ に overlay の例があります。
    • chart のコントローラの設定は ConfigMap(envFrom)から読むようにしました。chart の値の書き方は変わりません。
  • rproxy を止めるとき、接続を流し終えてから止めます(#39)。rproxy は rproxy-api v0.4.1 になりました(イメージ ghcr.io/max3584/rproxy-gateway/rproxy:0.4.1)。
    • managed:止まり始めてから 15 秒は受け付けを続け(delay)、そのあと今の接続の終わりを 25 秒まで待ちます(drain)。値は managed.shutdown か parameters の rproxy.shutdown。
    • fleet:delay 5 秒・drain 25 秒(fleet.shutdown)。前に置くロードバランサや VIP のヘルスチェックは /readyz に向けてください。

変更

  • managed の rproxy の readiness は /readyz を見ます(止まり始めるとすぐ宛先から外れます)。止める前の待ち(preStop)は既定で付けません。比べた結果、MetalLB の L2 と Local ではこの形が最も途切れが短くなりました(Pod の削除・入れ替え・drain で 0.2〜1.2 秒)。
    • managed.preStopSeconds を指定している環境は、その値を今までどおり使います。
    • Pod の終了の猶予は delay + drain + 5 秒(既定 45 秒)です。
    • rproxy-api v0.4.0 のイメージを使っているときは、v0.4.1 の形(preStop 15 秒、/healthz)のままです。
  • Gateway からの parametersRef は、受け付けなかった v0.4.1 までと違い、使えるようになりました。fleet モードでは InvalidParameters です。
  • 新しい CRD を使うときは、helm upgrade の前に CRD を入れてください(helm upgrade は新しい CRD を入れません)。

rproxy: rproxy-api v0.4.1


Added

  • Per-Gateway shape of managed rproxy (#36): a new CRD RproxyGatewayParameters (short name rpgwp).
    • Defaults through the GatewayClass parametersRef (in the controller's namespace), overrides through the Gateway's spec.infrastructure.parametersRef (same namespace).
    • Replicas, resources, PDB, topology spread, probes, shutdown timing and more per Gateway. nodeSelector, tolerations, affinity, priorityClass, Service type and the like are open to tenants only when the class policy allows them; the image and environment are class-only.
    • Errors set Accepted: False (InvalidParameters, naming the field). A running rproxy keeps its last good shape when its reference turns invalid.
    • A ClusterRole aggregated to namespace admins for editing parameters (rbac.aggregateToAdmin).
  • Install with Kustomize (#37).
    • Releases attach install.yaml, install-fleet.yaml and crds.yaml.
    • config/ in the repository (default, fleet, crd) works as a Kustomize base; overlay examples are in config/samples/.
    • The chart's controller settings now come from a ConfigMap (envFrom); chart values are unchanged.
  • rproxy drains connections before stopping (#39). rproxy is now rproxy-api v0.4.1 (image ghcr.io/max3584/rproxy-gateway/rproxy:0.4.1).
    • managed: keeps accepting for 15 s after stopping starts (delay), then waits up to 25 s for current connections (drain). Set with managed.shutdown or rproxy.shutdown in parameters.
    • fleet: delay 5 s, drain 25 s (fleet.shutdown). Point health checks of load balancers or VIPs in front at /readyz.

Changed

  • managed rproxy readiness uses /readyz (taken out of endpoints as soon as stopping starts), and no preStop by default. Compared variants showed this gives the shortest gaps with MetalLB L2 and Local (0.2–1.2 s on pod deletion, rollout and drain).
    • Installs that set managed.preStopSeconds keep that value.
    • Pod termination grace is delay + drain + 5 s (45 s by default).
    • With an rproxy-api v0.4.0 image, pods keep the v0.4.1 shape (preStop 15 s, /healthz).
  • A Gateway's parametersRef, refused up to v0.4.1, is now used; in fleet mode it gets InvalidParameters.
  • Install the new CRD before helm upgrade (helm upgrade does not install new CRDs).

rproxy: rproxy-api v0.4.1

v0.4.1

Choose a tag to compare

@github-actions github-actions released this 08 Oct 05:21
6afbcea

修正

  • rproxy を 2 つ以上動かしているとき、Pod の削除や入れ替えで 10〜15 秒すべての通信が止まっていたのを直しました。 外部の入口を受け持つノードの Pod を消したときや rollout restart でも、途切れは 1 秒未満になります(MetalLB の L2・externalTrafficPolicy: Local で 0.2〜0.3 秒)。
    • rproxy を止める前に待つようにしました(preStop、既定 15 秒、managed.preStopSeconds)。そのあいだに入口が別のノードに移ります。入れ替えは新しい Pod が準備できてから古い Pod を止めます。
    • コントローラがルールを入れ終えてから、Pod が通信を受けるようにしました(readinessGate rproxy.max3584.net/ruleset-applied。fleet の Pod も同じ)。
  • 証明書を配るコンテナが止まる合図を無視していて、Pod の終了と drain が 30 秒ほど遅れていたのを直しました。

追加

  • managed.replicas が 2 以上のとき、Gateway ごとに PodDisruptionBudget(maxUnavailable: 1)と、Pod をノードに散らす指定(topologySpreadConstraints)を作ります。
  • chart の値:managed.externalTrafficPolicy(空なら今までどおり)、managed.allocateLoadBalancerNodePorts、managed.readinessProbe(既定 2 秒ごと・2 回失敗で外す)、managed.livenessProbe、managed.preStopSeconds。
  • 1 つの Gateway の Pod へのルールの反映を、並べて送るようにしました。
  • 構成ごとの止まる時間の目安と勧め(L2・BGP・NodePort と自前の LB、Local と Cluster)を README と docs/DESIGN.md に書きました。

変更

  • コントローラに pods/status の patch と poddisruptionbudgets の権限を足しました(chart の ClusterRole と、watchNamespaces のときの Role)。
  • Pod の終了の猶予は preStop + 15 秒になります(既定 30 秒)。

rproxy は rproxy-api v0.4.0 のままです(イメージ ghcr.io/max3584/rproxy-gateway/rproxy:0.4.0)。


Fixed

  • With two or more rproxy replicas, deleting or restarting a pod stopped all traffic for 10–15 s. Deleting the pod on the node announcing the address, or rollout restart, now gaps for under a second (0.2–0.3 s with MetalLB L2 and externalTrafficPolicy: Local).
    • rproxy now waits before stopping (preStop, 15 s by default, managed.preStopSeconds) so the address moves to another node first; a rollout stops an old pod only after a new one is ready.
    • Pods receive traffic only after the controller has applied their rule set (readinessGate rproxy.max3584.net/ruleset-applied; fleet pods too).
  • The certificate sync container ignored the stop signal, delaying pod termination and drains by about 30 s.

Added

  • With managed.replicas of 2 or more, a PodDisruptionBudget (maxUnavailable: 1) and topologySpreadConstraints per Gateway.
  • Chart values: managed.externalTrafficPolicy (empty keeps the previous behaviour), managed.allocateLoadBalancerNodePorts, managed.readinessProbe (every 2 s, out after 2 failures by default), managed.livenessProbe, managed.preStopSeconds.
  • Rule sets are sent to a Gateway's pods concurrently.
  • Expected gaps per topology and recommendations (L2, BGP, NodePort with your own LB; Local vs Cluster) in the README and docs/en/DESIGN.md.

Changed

  • The controller gains pods/status patch and poddisruptionbudgets permissions (the chart's ClusterRole, and the Roles with watchNamespaces).
  • Pod termination grace is preStop + 15 s (30 s by default).

rproxy stays at rproxy-api v0.4.0 (image ghcr.io/max3584/rproxy-gateway/rproxy:0.4.0).

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 07 Oct 17:30
8b1f1cf

rproxy-gateway の最初のリリース。Kubernetes の Gateway API のリソースを rproxy のルールにして、rproxy の制御 API で反映するコントローラ。

追加

  • Gateway API v1.6:Gateway、HTTPRoute、GRPCRoute、TLSRoute(Passthrough / Terminate)、TCPRoute、UDPRoute、ReferenceGrant、ListenerSet、BackendTLSPolicy。
    • conformance(v1.6.3)は、GATEWAY-HTTP・GRPC・TLS・TCP・UDP の 5 つのプロファイルで core がすべて通る。名乗っている extended の機能(HTTPRoute の拡張、static addresses、infrastructure、クライアント証明書の検証など)もすべて通る。
    • 結果は docs/CONFORMANCE.md に。
  • 2 つの動かし方
    • managed(既定):Gateway ごとに、Gateway の namespace に rproxy の Deployment と Service を作る。Gateway ごとに制御 API の証明書とトークンを分ける。
    • fleet:先に置いた rproxy の DaemonSet(hostNetwork)がすべての Gateway を受け持つ。1 つの信頼の範囲のためのもの。
  • コントローラの冗長化:Lease でリーダーを選ぶ。chart の既定は 2 レプリカ。
  • Ingress・Traefik の CRD からの移行(--migrate-to):Ingress と IngressRoute・IngressRouteTCP・IngressRouteUDP・Middleware・TLSOption を、Gateway のルールセットに読み込む。
  • rproxy の CRD:RproxyMiddleware(ExtensionRef で使う rproxy のミドルウェア)、RproxyPolicy(L4 の制限・帯域・GeoIP など)、RproxyRule(rproxy のルールそのもの)。
  • 安全側の既定
    • rproxy の Pod は Kubernetes の API を使わない。証明書はマウントした Secret で受け取る。
    • spec.addresses・ExternalName の Service・移行でのほかの namespace への参照は、どれも既定で使えない。
    • Gateway ごとに NetworkPolicy を作る。
    • --watch-namespaces で権限を namespace ごとの Role に絞れる。
    • 詳しくは docs/SECURITY.md。
  • 配布物
    • Helm chart:oci://ghcr.io/max3584/charts/rproxy-gateway
    • イメージ:ghcr.io/max3584/rproxy-gateway:0.4.0(コントローラ)、ghcr.io/max3584/rproxy-gateway/rproxy:0.4.0(rproxy)

変更

  • rproxy v0.4.0 以降が要る(ルールセットと、Gateway API 向けの機能のため)。
  • TCPRoute・UDPRoute と HTTPRoute の retry は、Gateway API の experimental channel の CRD(experimental-install.yaml)が要る。standard の CRD では、これらのリソースと retry の欄がない。

入れ方

kubectl apply --server-side -f https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.6.3/experimental-install.yaml
helm install rproxy-gateway oci://ghcr.io/max3584/charts/rproxy-gateway -n rproxy-gateway-system --create-namespace

rproxy-api: rproxy-api v0.4.0 · UI: TCP-UDP-rproxy-ui v0.4.0


The first release of rproxy-gateway: a controller that turns Kubernetes Gateway API resources into rproxy rules and applies them through rproxy's control API.

Added

  • Gateway API v1.6: Gateway, HTTPRoute, GRPCRoute, TLSRoute (Passthrough / Terminate), TCPRoute, UDPRoute, ReferenceGrant, ListenerSet, BackendTLSPolicy.
    • Conformance (v1.6.3) passes every core test in the five profiles GATEWAY-HTTP, GRPC, TLS, TCP and UDP. Every claimed extended feature passes too (HTTPRoute extensions, static addresses, infrastructure, client certificate validation, and more).
    • Results are in docs/en/CONFORMANCE.md.
  • Two ways to run
    • managed (default): one rproxy Deployment and Service per Gateway, in the Gateway's namespace, each with its own control API certificate and token.
    • fleet: an rproxy DaemonSet deployed beforehand (hostNetwork) serves every Gateway. It is for one trust domain.
  • A highly available controller: replicas elect a leader with a Lease (2 replicas by default in the chart).
  • Migration from Ingress and Traefik CRDs (--migrate-to): Ingress, IngressRoute, IngressRouteTCP, IngressRouteUDP, Middleware and TLSOption are read into a Gateway's rule set.
  • rproxy's CRDs: RproxyMiddleware (rproxy middlewares used through ExtensionRef), RproxyPolicy (L4 limits, bandwidth, GeoIP, and more), RproxyRule (rproxy rules verbatim).
  • Safe defaults
    • rproxy pods do not use the Kubernetes API; certificates come as a mounted Secret.
    • spec.addresses, ExternalName Services and cross-namespace references in migration are all off by default.
    • A NetworkPolicy is made per Gateway.
    • --watch-namespaces narrows the controller's permissions to per-namespace Roles.
    • Details are in docs/en/SECURITY.md.
  • Artifacts
    • Helm chart: oci://ghcr.io/max3584/charts/rproxy-gateway
    • Images: ghcr.io/max3584/rproxy-gateway:0.4.0 (controller), ghcr.io/max3584/rproxy-gateway/rproxy:0.4.0 (rproxy)

Changed

  • Requires rproxy v0.4.0 or later (rule sets and the Gateway API features).
  • TCPRoute, UDPRoute and HTTPRoute retries need Gateway API's experimental channel CRDs (experimental-install.yaml); the standard CRDs lack those resources and the retry field.

Installing

kubectl apply --server-side -f https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.6.3/experimental-install.yaml
helm install rproxy-gateway oci://ghcr.io/max3584/charts/rproxy-gateway -n rproxy-gateway-system --create-namespace

rproxy-api: rproxy-api v0.4.0 · UI: TCP-UDP-rproxy-ui v0.4.0