Repository navigation
Releases: max3584/rproxy-gateway
Release list
v0.4.7
修正
- Gateway API v1.0・v1.1 の CRD でも動くようになりました(#63):これらの CRD では GatewayClass の
status.supportedFeaturesの形が v1.2 以降と違い、API サーバが status を丸ごと断っていました。GatewayClass が Accepted にならず、何も動きませんでした。今は断られたらsupportedFeaturesを外して書き直します。- v1.0 では、Gateway ごとの RproxyGatewayParameters(Gateway の
infrastructure.parametersRef、v1.1 から)は使えません。GatewayClass の parametersRef は使えます。 - v1.1 では GRPCRoute がまだ動きません(#61)。
- v1.0 では、Gateway ごとの RproxyGatewayParameters(Gateway の
変更
- 対応する版(README の「対応する版」):Gateway API の CRD は v1.0 から、Kubernetes は chart の範囲(1.29 以上)の最新(1.37.1)まで確かめています。互換性テストは毎週、その時点の最新の Kubernetes・Gateway API まで自動で回ります。
rproxy: rproxy-api v0.4.5 · UI: TCP-UDP-rproxy-ui v0.4.2
Fixed
- Gateway API v1.0 and v1.1 CRDs work (#63): their GatewayClass
status.supportedFeatureshas a different shape from v1.2 on, and the API server refused the whole status, so the GatewayClass was never Accepted and nothing worked. A refused status is now written again withoutsupportedFeatures.- On v1.0, per-Gateway RproxyGatewayParameters (Gateway
infrastructure.parametersRef, from v1.1) are not available; the GatewayClass parametersRef is. - On v1.1, GRPCRoute does not work yet (#61).
- On v1.0, per-Gateway RproxyGatewayParameters (Gateway
Changed
- Supported versions (README "Supported versions"): Gateway API CRDs from v1.0, and Kubernetes across the chart's range (1.29 and later) up to the newest (1.37.1). The compatibility run goes every week up to the newest Kubernetes and Gateway API released at that time.
rproxy: rproxy-api v0.4.5 · UI: TCP-UDP-rproxy-ui v0.4.2
v0.4.6
追加
- 古い Gateway API の CRD に対応(#58):Gateway API v1.2〜v1.5 の CRD(TCPRoute・UDPRoute が v1alpha2 だけ、v1.4 の TLSRoute が v1alpha3、ReferenceGrant が v1beta1 など)も見つけて扱います。前は v1 か推奨の版がない種類を見落としていました。対応する Kubernetes と Gateway API の版は README の「対応する版」の表にあります(Kubernetes 1.29〜1.37、Gateway API v1.2〜v1.7)。
- rproxy は rproxy-api v0.4.5 になりました(イメージ
ghcr.io/max3584/rproxy-gateway/rproxy:0.4.5)。UDP のセッションのメモリが 1 セッションあたり約 58 KiB から約 12 KiB に減ります。
修正
- UDP の転送先が ICMP の到達不能を返したとき、その転送先に気づくようになりました(rproxy-api v0.4.5)。
rproxy: rproxy-api v0.4.5 · UI: TCP-UDP-rproxy-ui v0.4.2
Added
- Older Gateway API CRDs (#58): resources from Gateway API v1.2 to v1.5 CRDs are found and handled too (TCPRoute and UDPRoute only as v1alpha2, TLSRoute as v1alpha3 in v1.4, ReferenceGrant as v1beta1, and so on). Before, kinds without v1 or a recommended version were missed. Supported Kubernetes and Gateway API versions are in the README "Supported versions" table (Kubernetes 1.29 to 1.37, Gateway API v1.2 to v1.7).
- rproxy is now rproxy-api v0.4.5 (image
ghcr.io/max3584/rproxy-gateway/rproxy:0.4.5): UDP session memory goes from about 58 KiB to about 12 KiB per session.
Fixed
- A UDP backend answering with ICMP port unreachable is now noticed (rproxy-api v0.4.5).
rproxy: rproxy-api v0.4.5 · UI: TCP-UDP-rproxy-ui v0.4.2
v0.4.5
追加
- Gateway API の機能を足しました(conformance の GATEWAY-HTTP の extended は 58/58)。
- fleet で、Gateway ごとのアドレスで待ち受けられるようになりました(#47)。
fleet.listen: addressesのとき、spec.addresses(addressCIDRsの内)を持つ Gateway はそのアドレスで待ち受けるので、同じポートを別のアドレスの Gateway で使えます。アドレスはプラットフォーム(keepalived・kube-vip・MetalLB など)が用意します(docs/PLATFORM.md)。 - 送り先の障害に早く気づくようにしました(#50・#55)。
- 受け身のヘルスチェックを既定で有効にしました(HTTP:gateway の失敗 3 回、L4:1 回で外し、10 秒から最大 1 分)。
- 送り先への接続のタイムアウトの既定を 1 秒にしました。
- HTTPRoute の規則に
timeoutsがないとき、応答の時間切れの既定を 30 秒にしました(応答ヘッダが届くまでの時間。ダウンロード・SSE・WebSocket は切りません。GRPCRoute には付けません)。chart のbackends.*で変えられます。 - EndpointSlice は ready の宛先を使い、ready が 1 つもないときだけ終了中の宛先を使います。
- RproxyPolicy に
connectTimeout・responseTimeoutを足しました。
- プラットフォームの設定の文書 docs/PLATFORM.md(日英):MetalLB・kube-vip・Cilium・クラウドの LB・NodePort と HAProxy・fleet とノードの keepalived・ClusterIP の設定例と、構成ごとの途切れの目安。
- rproxy を rproxy-api v0.4.3 にしました(イメージ
ghcr.io/max3584/rproxy-gateway/rproxy:0.4.3)。
変更
- v0.4.4 の組み込みの VIP(
fleet.vip)を外しました(#54)。既定で切っていて、1 日だけ出していた機能のため、パッチで外します。アドレスはプラットフォームに任せてください(docs/PLATFORM.md に移り方と片付けの手順)。fleet.vipを設定したままのhelm upgradeは、案内のエラーで止まります。 - rproxy の CRD を v1beta1 にしました(#52)。保存する版は v1beta1 で、v1alpha1 も同じ形で受け付けます(非推奨)。今のオブジェクトはそのまま使えます。保存の版の移し方は docs/DESIGN-v0.4.x.md の 11.4。新しい CRD は
helm upgradeの前に入れてください。 - 受け身のヘルスチェック・接続のタイムアウト・応答の時間切れの既定は、今ある Gateway にも付きます(接続を切らずに変わります)。RproxyPolicy や HTTPRoute の
timeoutsがあれば、そちらが勝ちます。 - fleet の Gateway どうしのポートの取り合いは、古い Gateway が持ちます(後の Gateway のリスナーは
PortUnavailable)。
rproxy: rproxy-api v0.4.3 · UI: TCP-UDP-rproxy-ui v0.4.2
Added
- More Gateway API features (GATEWAY-HTTP extended now 58/58 in conformance).
- 421 for misdirected requests across HTTPS listeners on one port (
GatewayHTTPSListenerDetectMisdirectedRequests, #48). - backendRef filters
CORS,RequestRedirectandRequestMirror(#49). - HTTPRoute
ExternalAuth(HTTP and gRPC, forwardBody, also on backendRefs; #51). Gateway API v1.6.3 has no conformance test for it, so it does not appear in the report.
- 421 for misdirected requests across HTTPS listeners on one port (
- fleet listens on each Gateway's own addresses (#47): with
fleet.listen: addresses, a Gateway withspec.addresses(withinaddressCIDRs) listens on them, so Gateways on different addresses can share a port. The platform (keepalived, kube-vip, MetalLB, …) provides the addresses (docs/en/PLATFORM.md). - Backend failures are noticed sooner (#50, #55).
- Passive health checks are on by default (HTTP: out after 3 gateway errors, L4: after 1; 10 s doubling up to 1 min).
- Backend connect timeout defaults to 1 s.
- Without
timeoutson an HTTPRoute rule, a 30 s response timeout applies (time to response headers; downloads, SSE and WebSockets are not cut; not set on GRPCRoute). Change it with the chart'sbackends.*. - EndpointSlices: ready endpoints are used; terminating ones only when none is ready.
- RproxyPolicy gains
connectTimeoutandresponseTimeout.
- Platform guide docs/en/PLATFORM.md: examples for MetalLB, kube-vip, Cilium, cloud LBs, NodePort with HAProxy, fleet with keepalived on the nodes, and ClusterIP, with expected gaps per setup.
- rproxy is now rproxy-api v0.4.3 (image
ghcr.io/max3584/rproxy-gateway/rproxy:0.4.3).
Changed
- The built-in VIP of v0.4.4 (
fleet.vip) is removed (#54). It was off by default and shipped for one day, so it goes in a patch; leave addresses to the platform (migration and cleanup in docs/en/PLATFORM.md).helm upgradewithfleet.vipstill set stops with a pointer to the docs. - rproxy CRDs are v1beta1 (#52): v1beta1 is the storage version and v1alpha1 is still served with the same schema (deprecated); existing objects keep working. Storage migration is in docs/en/DESIGN-v0.4.x.md 11.4. Install the new CRDs before
helm upgrade. - The passive health check, connect timeout and response timeout defaults apply to existing Gateways too (changed live, connections kept). RproxyPolicy or HTTPRoute
timeoutswin when set. - Port conflicts between fleet Gateways go to the older Gateway (the newer listener gets
PortUnavailable).
rproxy: rproxy-api v0.4.3 · UI: TCP-UDP-rproxy-ui v0.4.2
v0.4.4
追加
- fleet の rproxy の Pod が VIP を直接持てるようになりました(#43・#44)。chart の
fleet.vip(既定は off)。- Pod ごとの
vipコンテナ(rproxy-gateway vip)が、VIP ごとに Kubernetes の Lease でリーダーを選び、自分のノードに VIP を付けて gratuitous ARP(IPv6 は unsolicited NA)で知らせます。 - VIP を持つのは、rproxy が準備を終え(
/readyz)、コントローラがルールを当て終えた Pod だけです。rproxy が止まり始めたとき・Pod の終了・ノードの cordon では、先に VIP を外してから Lease を空けます。計画した移動(Pod の削除・入れ替え・drain)は 1 秒未満で移ります(受け入れテストで 0.1〜1.2 秒の途切れ)。 - Kubernetes の API サーバに届かないときは、既定で VIP を持ち続けます(
hold、releaseも選べます)。ほかの機械が同じ VIP を告げたら手放します。 - Lease の既定:期限 3 秒・更新 1 秒・やり直し 0.5 秒。
- VIP は管理者が
fleet.vip.addressesに並べたものだけで、Gateway のspec.addressesはその中から選びます(addressCIDRsの外や、Service・ノードと重なるものは使いません)。持ち主のいない VIP を使う Gateway はProgrammed: False(AddressNotUsable)。 - Kustomize の例
config/samples/fleet-vip。
- Pod ごとの
- rproxy を rproxy-api v0.4.2 にしました(イメージ
ghcr.io/max3584/rproxy-gateway/rproxy:0.4.2)(#45)。
変更
- rproxy v0.4.2 はトークンファイルを自分で読み直すので、UI を有効・無効にしても Pod を入れ替えません。fleet でも手での
rollout restartは要りません。UI の一覧には、UI のトークンを受け付けると確かめた Pod だけを載せます。 - VIP を使うとき、
vipコンテナはNET_ADMIN・NET_RAWと、自分の Pod・ノードを読む権限、Lease の権限を持ちます。fleet の namespace の PodSecurity はprivilegedが要ります(docs/SECURITY.md)。VIP を使わない入れ方は変わりません。
rproxy: rproxy-api v0.4.2 · UI: TCP-UDP-rproxy-ui v0.4.2
Added
- fleet rproxy pods can hold VIPs directly (#43, #44), chart
fleet.vip(off by default).- A
vipcontainer per pod (rproxy-gateway vip) elects a leader per VIP with a Kubernetes Lease, adds the VIP on its node and announces it with gratuitous ARP (unsolicited NA for IPv6). - Only a pod whose rproxy is ready (
/readyz) and has its rule sets applied holds a VIP. When rproxy starts stopping, the pod terminates or the node is cordoned, the VIP is removed first and then the Lease released. Planned moves (pod deletion, rollout, drain) hand over in under a second (0.1–1.2 s gaps in the acceptance test). - If the Kubernetes API server is unreachable the VIP is kept by default (
hold;releaseis available). Another machine announcing the same VIP makes it let go. - Lease defaults: duration 3 s, renew 1 s, retry 0.5 s.
- VIPs are only those an admin lists in
fleet.vip.addresses; a Gateway'sspec.addressespicks from them (never outsideaddressCIDRs, nor overlapping Services or nodes). A Gateway on a VIP without a holder getsProgrammed: False(AddressNotUsable). - Kustomize example
config/samples/fleet-vip.
- A
- rproxy is now rproxy-api v0.4.2 (image
ghcr.io/max3584/rproxy-gateway/rproxy:0.4.2) (#45).
Changed
- rproxy v0.4.2 re-reads its token file, so enabling or disabling the UI no longer rolls pods, and fleet no longer needs a manual
rollout restart. The UI list only includes pods confirmed to accept the UI token. - With VIPs, the
vipcontainer hasNET_ADMIN,NET_RAW, read access to its own pod and node, and Lease permissions; the fleet namespace needs theprivilegedPodSecurity level (docs/en/SECURITY.md). Installs without VIPs are unchanged.
rproxy: rproxy-api v0.4.2 · UI: TCP-UDP-rproxy-ui v0.4.2
v0.4.3
追加
- UI(TCP-UDP-rproxy-ui v0.4.2)から Kubernetes の rproxy を見られるようになりました(#41)。
- chart の
ui.namespace(--ui-namespace)を設定すると、その namespace に Secretrproxy-ui-discovery(rproxy の Pod の一覧・CA・読むだけのトークン)を書きます。中身が変わったときだけ更新し、見せる Gateway がなくなれば消します。 - 見せるのは、
ui.namespaceがあり、Gateway の parameters でui.visibleが false でないものだけです。 - トークンは
rules:read・metrics:readだけで、書き込みは rproxy が 403 で断ります。 - 一覧には、トークンを受け付けられる Pod だけを載せます(Ready・ルールを当て終えた・終了中でない・今のトークンで起動した Pod)。
- 見せる Gateway の NetworkPolicy に、UI の Pod(
ui.podSelector、既定app.kubernetes.io/name: rproxy-ui・app.kubernetes.io/component: ui)から制御 API への許可を足します。Secret の権限は UI の namespace の Role だけです。
- chart の
変更
- UI を有効・無効にしたとき、Gateway を見せる・隠すときに、その Gateway の rproxy の Pod が 1 回入れ替わります(rproxy がトークンファイルを起動時に読むため。2 つ以上なら途切れは 1 秒未満)。fleet は、UI のトークンを足したあとに DaemonSet を
rollout restartしてください。 ui.namespaceを外したときは、前の namespace のrproxy-ui-discoveryを手で消してください。
rproxy: rproxy-api v0.4.1 · UI: TCP-UDP-rproxy-ui v0.4.2
Added
- The UI (TCP-UDP-rproxy-ui v0.4.2) can show Kubernetes rproxy (#41).
- With the chart's
ui.namespace(--ui-namespace), the controller writes Secretrproxy-ui-discovery(rproxy pods, CA, a read-only token) into that namespace, updates it only on change, and removes it when no Gateway is shown. - Shown only when
ui.namespaceis set and the Gateway's parameters do not setui.visible: false. - The token has only
rules:readandmetrics:read; rproxy refuses writes with 403. - Only pods that accept the token are listed (Ready, rule set applied, not terminating, started with the current token).
- Shown Gateways' NetworkPolicy lets the UI pods (
ui.podSelector, defaultapp.kubernetes.io/name: rproxy-uiandapp.kubernetes.io/component: ui) reach the control API. Secret permissions are a Role in the UI namespace only.
- With the chart's
Changed
- Enabling or disabling the UI, or showing or hiding a Gateway, rolls that Gateway's rproxy pods once (rproxy reads its token file at start; under a second of gap with 2+ replicas). For fleet,
rollout restartthe DaemonSet after adding the UI token. - After removing
ui.namespace, delete the old namespace'srproxy-ui-discoveryby hand.
rproxy: rproxy-api v0.4.1 · UI: TCP-UDP-rproxy-ui v0.4.2
v0.4.2
追加
- Gateway ごとに managed の rproxy の形を変えられるようになりました(#36)。新しい CRD
RproxyGatewayParameters(短縮名rpgwp)。- GatewayClass の
parametersRef(コントローラの namespace のもの)で既定を、Gateway のspec.infrastructure.parametersRef(同じ namespace のもの)で上書きを指定します。 - replicas・resources・PDB・topologySpread・probe・停止の時間などを Gateway ごとに変えられます。nodeSelector・tolerations・affinity・priorityClass・Service の種類などは、クラスの
policyで許したときだけ利用者が変えられます。イメージと環境変数はクラスだけが決めます。 - 誤りは
Accepted: False(InvalidParameters、項目の名前つき)。すでに動いている rproxy は、参照が誤りになっても最後の正しい形のまま動かし続けます。 - namespace の admin に parameters を編集する権限を足す ClusterRole(
rbac.aggregateToAdmin)。
- GatewayClass の
- Kustomize で入れられるようになりました(#37)。
- リリースに
install.yaml・install-fleet.yaml・crds.yamlを添付します。 - リポジトリの
config/(default・fleet・crd)を Kustomize の土台として使えます。config/samples/に overlay の例があります。 - chart のコントローラの設定は ConfigMap(
envFrom)から読むようにしました。chart の値の書き方は変わりません。
- リリースに
- rproxy を止めるとき、接続を流し終えてから止めます(#39)。rproxy は rproxy-api v0.4.1 になりました(イメージ
ghcr.io/max3584/rproxy-gateway/rproxy:0.4.1)。- managed:止まり始めてから 15 秒は受け付けを続け(delay)、そのあと今の接続の終わりを 25 秒まで待ちます(drain)。値は
managed.shutdownか parameters のrproxy.shutdown。 - fleet:delay 5 秒・drain 25 秒(
fleet.shutdown)。前に置くロードバランサや VIP のヘルスチェックは/readyzに向けてください。
- managed:止まり始めてから 15 秒は受け付けを続け(delay)、そのあと今の接続の終わりを 25 秒まで待ちます(drain)。値は
変更
- managed の rproxy の readiness は
/readyzを見ます(止まり始めるとすぐ宛先から外れます)。止める前の待ち(preStop)は既定で付けません。比べた結果、MetalLB の L2 とLocalではこの形が最も途切れが短くなりました(Pod の削除・入れ替え・drain で 0.2〜1.2 秒)。managed.preStopSecondsを指定している環境は、その値を今までどおり使います。- Pod の終了の猶予は delay + drain + 5 秒(既定 45 秒)です。
- rproxy-api v0.4.0 のイメージを使っているときは、v0.4.1 の形(preStop 15 秒、
/healthz)のままです。
- Gateway からの
parametersRefは、受け付けなかった v0.4.1 までと違い、使えるようになりました。fleet モードではInvalidParametersです。 - 新しい CRD を使うときは、
helm upgradeの前に CRD を入れてください(helm upgradeは新しい CRD を入れません)。
rproxy: rproxy-api v0.4.1
Added
- Per-Gateway shape of managed rproxy (#36): a new CRD
RproxyGatewayParameters(short namerpgwp).- Defaults through the GatewayClass
parametersRef(in the controller's namespace), overrides through the Gateway'sspec.infrastructure.parametersRef(same namespace). - Replicas, resources, PDB, topology spread, probes, shutdown timing and more per Gateway. nodeSelector, tolerations, affinity, priorityClass, Service type and the like are open to tenants only when the class
policyallows them; the image and environment are class-only. - Errors set
Accepted: False(InvalidParameters, naming the field). A running rproxy keeps its last good shape when its reference turns invalid. - A ClusterRole aggregated to namespace admins for editing parameters (
rbac.aggregateToAdmin).
- Defaults through the GatewayClass
- Install with Kustomize (#37).
- Releases attach
install.yaml,install-fleet.yamlandcrds.yaml. config/in the repository (default, fleet, crd) works as a Kustomize base; overlay examples are inconfig/samples/.- The chart's controller settings now come from a ConfigMap (
envFrom); chart values are unchanged.
- Releases attach
- rproxy drains connections before stopping (#39). rproxy is now rproxy-api v0.4.1 (image
ghcr.io/max3584/rproxy-gateway/rproxy:0.4.1).- managed: keeps accepting for 15 s after stopping starts (delay), then waits up to 25 s for current connections (drain). Set with
managed.shutdownorrproxy.shutdownin parameters. - fleet: delay 5 s, drain 25 s (
fleet.shutdown). Point health checks of load balancers or VIPs in front at/readyz.
- managed: keeps accepting for 15 s after stopping starts (delay), then waits up to 25 s for current connections (drain). Set with
Changed
- managed rproxy readiness uses
/readyz(taken out of endpoints as soon as stopping starts), and no preStop by default. Compared variants showed this gives the shortest gaps with MetalLB L2 andLocal(0.2–1.2 s on pod deletion, rollout and drain).- Installs that set
managed.preStopSecondskeep that value. - Pod termination grace is delay + drain + 5 s (45 s by default).
- With an rproxy-api v0.4.0 image, pods keep the v0.4.1 shape (preStop 15 s,
/healthz).
- Installs that set
- A Gateway's
parametersRef, refused up to v0.4.1, is now used; in fleet mode it getsInvalidParameters. - Install the new CRD before
helm upgrade(helm upgradedoes not install new CRDs).
rproxy: rproxy-api v0.4.1
v0.4.1
修正
- rproxy を 2 つ以上動かしているとき、Pod の削除や入れ替えで 10〜15 秒すべての通信が止まっていたのを直しました。 外部の入口を受け持つノードの Pod を消したときや
rollout restartでも、途切れは 1 秒未満になります(MetalLB の L2・externalTrafficPolicy: Localで 0.2〜0.3 秒)。- rproxy を止める前に待つようにしました(preStop、既定 15 秒、
managed.preStopSeconds)。そのあいだに入口が別のノードに移ります。入れ替えは新しい Pod が準備できてから古い Pod を止めます。 - コントローラがルールを入れ終えてから、Pod が通信を受けるようにしました(readinessGate
rproxy.max3584.net/ruleset-applied。fleet の Pod も同じ)。
- rproxy を止める前に待つようにしました(preStop、既定 15 秒、
- 証明書を配るコンテナが止まる合図を無視していて、Pod の終了と drain が 30 秒ほど遅れていたのを直しました。
追加
managed.replicasが 2 以上のとき、Gateway ごとに PodDisruptionBudget(maxUnavailable: 1)と、Pod をノードに散らす指定(topologySpreadConstraints)を作ります。- chart の値:
managed.externalTrafficPolicy(空なら今までどおり)、managed.allocateLoadBalancerNodePorts、managed.readinessProbe(既定 2 秒ごと・2 回失敗で外す)、managed.livenessProbe、managed.preStopSeconds。 - 1 つの Gateway の Pod へのルールの反映を、並べて送るようにしました。
- 構成ごとの止まる時間の目安と勧め(L2・BGP・NodePort と自前の LB、Local と Cluster)を README と docs/DESIGN.md に書きました。
変更
- コントローラに
pods/statusの patch とpoddisruptionbudgetsの権限を足しました(chart の ClusterRole と、watchNamespacesのときの Role)。 - Pod の終了の猶予は preStop + 15 秒になります(既定 30 秒)。
rproxy は rproxy-api v0.4.0 のままです(イメージ ghcr.io/max3584/rproxy-gateway/rproxy:0.4.0)。
Fixed
- With two or more rproxy replicas, deleting or restarting a pod stopped all traffic for 10–15 s. Deleting the pod on the node announcing the address, or
rollout restart, now gaps for under a second (0.2–0.3 s with MetalLB L2 andexternalTrafficPolicy: Local).- rproxy now waits before stopping (preStop, 15 s by default,
managed.preStopSeconds) so the address moves to another node first; a rollout stops an old pod only after a new one is ready. - Pods receive traffic only after the controller has applied their rule set (readinessGate
rproxy.max3584.net/ruleset-applied; fleet pods too).
- rproxy now waits before stopping (preStop, 15 s by default,
- The certificate sync container ignored the stop signal, delaying pod termination and drains by about 30 s.
Added
- With
managed.replicasof 2 or more, a PodDisruptionBudget (maxUnavailable: 1) and topologySpreadConstraints per Gateway. - Chart values:
managed.externalTrafficPolicy(empty keeps the previous behaviour),managed.allocateLoadBalancerNodePorts,managed.readinessProbe(every 2 s, out after 2 failures by default),managed.livenessProbe,managed.preStopSeconds. - Rule sets are sent to a Gateway's pods concurrently.
- Expected gaps per topology and recommendations (L2, BGP, NodePort with your own LB; Local vs Cluster) in the README and docs/en/DESIGN.md.
Changed
- The controller gains
pods/statuspatch andpoddisruptionbudgetspermissions (the chart's ClusterRole, and the Roles withwatchNamespaces). - Pod termination grace is preStop + 15 s (30 s by default).
rproxy stays at rproxy-api v0.4.0 (image ghcr.io/max3584/rproxy-gateway/rproxy:0.4.0).
v0.4.0
rproxy-gateway の最初のリリース。Kubernetes の Gateway API のリソースを rproxy のルールにして、rproxy の制御 API で反映するコントローラ。
追加
- Gateway API v1.6:Gateway、HTTPRoute、GRPCRoute、TLSRoute(Passthrough / Terminate)、TCPRoute、UDPRoute、ReferenceGrant、ListenerSet、BackendTLSPolicy。
- conformance(v1.6.3)は、GATEWAY-HTTP・GRPC・TLS・TCP・UDP の 5 つのプロファイルで core がすべて通る。名乗っている extended の機能(HTTPRoute の拡張、static addresses、infrastructure、クライアント証明書の検証など)もすべて通る。
- 結果は docs/CONFORMANCE.md に。
- 2 つの動かし方
- managed(既定):Gateway ごとに、Gateway の namespace に rproxy の Deployment と Service を作る。Gateway ごとに制御 API の証明書とトークンを分ける。
- fleet:先に置いた rproxy の DaemonSet(hostNetwork)がすべての Gateway を受け持つ。1 つの信頼の範囲のためのもの。
- コントローラの冗長化:Lease でリーダーを選ぶ。chart の既定は 2 レプリカ。
- Ingress・Traefik の CRD からの移行(
--migrate-to):Ingress と IngressRoute・IngressRouteTCP・IngressRouteUDP・Middleware・TLSOption を、Gateway のルールセットに読み込む。 - rproxy の CRD:RproxyMiddleware(ExtensionRef で使う rproxy のミドルウェア)、RproxyPolicy(L4 の制限・帯域・GeoIP など)、RproxyRule(rproxy のルールそのもの)。
- 安全側の既定
- rproxy の Pod は Kubernetes の API を使わない。証明書はマウントした Secret で受け取る。
spec.addresses・ExternalName の Service・移行でのほかの namespace への参照は、どれも既定で使えない。- Gateway ごとに NetworkPolicy を作る。
--watch-namespacesで権限を namespace ごとの Role に絞れる。- 詳しくは docs/SECURITY.md。
- 配布物
- Helm chart:
oci://ghcr.io/max3584/charts/rproxy-gateway - イメージ:
ghcr.io/max3584/rproxy-gateway:0.4.0(コントローラ)、ghcr.io/max3584/rproxy-gateway/rproxy:0.4.0(rproxy)
- Helm chart:
変更
- rproxy v0.4.0 以降が要る(ルールセットと、Gateway API 向けの機能のため)。
- TCPRoute・UDPRoute と HTTPRoute の retry は、Gateway API の experimental channel の CRD(
experimental-install.yaml)が要る。standard の CRD では、これらのリソースと retry の欄がない。
入れ方
kubectl apply --server-side -f https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.6.3/experimental-install.yaml
helm install rproxy-gateway oci://ghcr.io/max3584/charts/rproxy-gateway -n rproxy-gateway-system --create-namespacerproxy-api: rproxy-api v0.4.0 · UI: TCP-UDP-rproxy-ui v0.4.0
The first release of rproxy-gateway: a controller that turns Kubernetes Gateway API resources into rproxy rules and applies them through rproxy's control API.
Added
- Gateway API v1.6: Gateway, HTTPRoute, GRPCRoute, TLSRoute (Passthrough / Terminate), TCPRoute, UDPRoute, ReferenceGrant, ListenerSet, BackendTLSPolicy.
- Conformance (v1.6.3) passes every core test in the five profiles GATEWAY-HTTP, GRPC, TLS, TCP and UDP. Every claimed extended feature passes too (HTTPRoute extensions, static addresses, infrastructure, client certificate validation, and more).
- Results are in docs/en/CONFORMANCE.md.
- Two ways to run
- managed (default): one rproxy Deployment and Service per Gateway, in the Gateway's namespace, each with its own control API certificate and token.
- fleet: an rproxy DaemonSet deployed beforehand (hostNetwork) serves every Gateway. It is for one trust domain.
- A highly available controller: replicas elect a leader with a Lease (2 replicas by default in the chart).
- Migration from Ingress and Traefik CRDs (
--migrate-to): Ingress, IngressRoute, IngressRouteTCP, IngressRouteUDP, Middleware and TLSOption are read into a Gateway's rule set. - rproxy's CRDs: RproxyMiddleware (rproxy middlewares used through ExtensionRef), RproxyPolicy (L4 limits, bandwidth, GeoIP, and more), RproxyRule (rproxy rules verbatim).
- Safe defaults
- rproxy pods do not use the Kubernetes API; certificates come as a mounted Secret.
spec.addresses, ExternalName Services and cross-namespace references in migration are all off by default.- A NetworkPolicy is made per Gateway.
--watch-namespacesnarrows the controller's permissions to per-namespace Roles.- Details are in docs/en/SECURITY.md.
- Artifacts
- Helm chart:
oci://ghcr.io/max3584/charts/rproxy-gateway - Images:
ghcr.io/max3584/rproxy-gateway:0.4.0(controller),ghcr.io/max3584/rproxy-gateway/rproxy:0.4.0(rproxy)
- Helm chart:
Changed
- Requires rproxy v0.4.0 or later (rule sets and the Gateway API features).
- TCPRoute, UDPRoute and HTTPRoute retries need Gateway API's experimental channel CRDs (
experimental-install.yaml); the standard CRDs lack those resources and the retry field.
Installing
kubectl apply --server-side -f https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.6.3/experimental-install.yaml
helm install rproxy-gateway oci://ghcr.io/max3584/charts/rproxy-gateway -n rproxy-gateway-system --create-namespacerproxy-api: rproxy-api v0.4.0 · UI: TCP-UDP-rproxy-ui v0.4.0