Skip to content

v0.4.5

Choose a tag to compare

@github-actions github-actions released this 09 Oct 06:34
· 33 commits to main since this release
904ce74

追加

  • Gateway API の機能を足しました(conformance の GATEWAY-HTTP の extended は 58/58)。
    • 同じポートの HTTPS のリスナーの名前違いのリクエストに 421(GatewayHTTPSListenerDetectMisdirectedRequests、#48)。
    • backendRef の CORS・RequestRedirect・RequestMirror のフィルタ(#49)。
    • HTTPRoute の ExternalAuth フィルタ(HTTP・gRPC、forwardBody、backendRef の上でも。#51)。Gateway API v1.6.3 にはこの機能の conformance の試験がないので、レポートには出ません。
  • fleet で、Gateway ごとのアドレスで待ち受けられるようになりました(#47)。fleet.listen: addresses のとき、spec.addresses(addressCIDRs の内)を持つ Gateway はそのアドレスで待ち受けるので、同じポートを別のアドレスの Gateway で使えます。アドレスはプラットフォーム(keepalived・kube-vip・MetalLB など)が用意します(docs/PLATFORM.md)。
  • 送り先の障害に早く気づくようにしました(#50・#55)。
    • 受け身のヘルスチェックを既定で有効にしました(HTTP:gateway の失敗 3 回、L4:1 回で外し、10 秒から最大 1 分)。
    • 送り先への接続のタイムアウトの既定を 1 秒にしました。
    • HTTPRoute の規則に timeouts がないとき、応答の時間切れの既定を 30 秒にしました(応答ヘッダが届くまでの時間。ダウンロード・SSE・WebSocket は切りません。GRPCRoute には付けません)。chart の backends.* で変えられます。
    • EndpointSlice は ready の宛先を使い、ready が 1 つもないときだけ終了中の宛先を使います。
    • RproxyPolicy に connectTimeout・responseTimeout を足しました。
  • プラットフォームの設定の文書 docs/PLATFORM.md(日英):MetalLB・kube-vip・Cilium・クラウドの LB・NodePort と HAProxy・fleet とノードの keepalived・ClusterIP の設定例と、構成ごとの途切れの目安。
  • rproxy を rproxy-api v0.4.3 にしました(イメージ ghcr.io/max3584/rproxy-gateway/rproxy:0.4.3)。

変更

  • v0.4.4 の組み込みの VIP(fleet.vip)を外しました(#54)。既定で切っていて、1 日だけ出していた機能のため、パッチで外します。アドレスはプラットフォームに任せてください(docs/PLATFORM.md に移り方と片付けの手順)。fleet.vip を設定したままの helm upgrade は、案内のエラーで止まります。
  • rproxy の CRD を v1beta1 にしました(#52)。保存する版は v1beta1 で、v1alpha1 も同じ形で受け付けます(非推奨)。今のオブジェクトはそのまま使えます。保存の版の移し方は docs/DESIGN-v0.4.x.md の 11.4。新しい CRD は helm upgrade の前に入れてください。
  • 受け身のヘルスチェック・接続のタイムアウト・応答の時間切れの既定は、今ある Gateway にも付きます(接続を切らずに変わります)。RproxyPolicy や HTTPRoute の timeouts があれば、そちらが勝ちます。
  • fleet の Gateway どうしのポートの取り合いは、古い Gateway が持ちます(後の Gateway のリスナーは PortUnavailable)。

rproxy: rproxy-api v0.4.3 · UI: TCP-UDP-rproxy-ui v0.4.2


Added

  • More Gateway API features (GATEWAY-HTTP extended now 58/58 in conformance).
    • 421 for misdirected requests across HTTPS listeners on one port (GatewayHTTPSListenerDetectMisdirectedRequests, #48).
    • backendRef filters CORS, RequestRedirect and RequestMirror (#49).
    • HTTPRoute ExternalAuth (HTTP and gRPC, forwardBody, also on backendRefs; #51). Gateway API v1.6.3 has no conformance test for it, so it does not appear in the report.
  • fleet listens on each Gateway's own addresses (#47): with fleet.listen: addresses, a Gateway with spec.addresses (within addressCIDRs) listens on them, so Gateways on different addresses can share a port. The platform (keepalived, kube-vip, MetalLB, …) provides the addresses (docs/en/PLATFORM.md).
  • Backend failures are noticed sooner (#50, #55).
    • Passive health checks are on by default (HTTP: out after 3 gateway errors, L4: after 1; 10 s doubling up to 1 min).
    • Backend connect timeout defaults to 1 s.
    • Without timeouts on an HTTPRoute rule, a 30 s response timeout applies (time to response headers; downloads, SSE and WebSockets are not cut; not set on GRPCRoute). Change it with the chart's backends.*.
    • EndpointSlices: ready endpoints are used; terminating ones only when none is ready.
    • RproxyPolicy gains connectTimeout and responseTimeout.
  • Platform guide docs/en/PLATFORM.md: examples for MetalLB, kube-vip, Cilium, cloud LBs, NodePort with HAProxy, fleet with keepalived on the nodes, and ClusterIP, with expected gaps per setup.
  • rproxy is now rproxy-api v0.4.3 (image ghcr.io/max3584/rproxy-gateway/rproxy:0.4.3).

Changed

  • The built-in VIP of v0.4.4 (fleet.vip) is removed (#54). It was off by default and shipped for one day, so it goes in a patch; leave addresses to the platform (migration and cleanup in docs/en/PLATFORM.md). helm upgrade with fleet.vip still set stops with a pointer to the docs.
  • rproxy CRDs are v1beta1 (#52): v1beta1 is the storage version and v1alpha1 is still served with the same schema (deprecated); existing objects keep working. Storage migration is in docs/en/DESIGN-v0.4.x.md 11.4. Install the new CRDs before helm upgrade.
  • The passive health check, connect timeout and response timeout defaults apply to existing Gateways too (changed live, connections kept). RproxyPolicy or HTTPRoute timeouts win when set.
  • Port conflicts between fleet Gateways go to the older Gateway (the newer listener gets PortUnavailable).

rproxy: rproxy-api v0.4.3 · UI: TCP-UDP-rproxy-ui v0.4.2