fix(platform): front the felis-api internal face on its own ClusterIP Service
The login limbo pod dials FELIS_API_BASE_URL = felis-api.<ns>.svc:8081 (the internal face, service-token auth) to mint bind codes and poll link status, but the only Service named felis-api is the external NodePort face and declares only port 443. A Service answers only on its declared ports, so felis-api:8081 had no backend and every login-pod internal call silently failed to connect. Render a separate ClusterIP Service felis-api-internal for port 8081 and repoint InternalAPIBaseURL at it. A second port on the NodePort Service is not an option: Type=NodePort allocates a node port for every declared port with no per-port opt-out, so it would publish the no-Zero-Trust internal face on every node's external IP. A distinct ClusterIP Service keeps 8081 in-cluster only, reachable by the login pod via DNS and by the on-node break-glass console via the ClusterIP (exported as APIInternalServiceName / APIInternalPort). Manifest-level fix; the live packet path is pending real-cluster verification.
This commit is contained in:
4 files changed
+111
-14
No files matched your search
@@ -131,11 +131,16 @@ set them by hand:
|
||||
via a `secretKeyRef`, keyed off the reserved `login` name. Until the token is
|
||||
present the plugin fail-safes to readiness-only, so the gate is never broken — it
|
||||
simply does not authenticate yet.
|
||||
- **Service:** the login pod dials `FELIS_API_BASE_URL`, which resolves to the
|
||||
ClusterIP Service `felis-api-internal` (control namespace) that fronts the api
|
||||
pod's internal port 8081. That Service is deliberately separate from the external
|
||||
NodePort `felis-api` (443) so the no-Zero-Trust internal face is never published on
|
||||
a node's external IP.
|
||||
- **NetworkPolicy:** none is required today — neither the minecraft-namespace egress
|
||||
nor the control-namespace ingress is policy-locked, so the login pod's call to the
|
||||
API internal port is already reachable. If a future deployment adds a minecraft
|
||||
egress lock or a control-namespace ingress fence, it must also open the
|
||||
login-pod → felis-api internal-port (8081) path.
|
||||
API internal port is reachable. If a future deployment adds a minecraft egress lock
|
||||
or a control-namespace ingress fence, it must also open the login-pod →
|
||||
felis-api-internal (8081) path.
|
||||
|
||||
The Velocity default-landing and waiting-park wiring is printed by `felis setup`
|
||||
and enforces the invariant: fresh connections hit `login` first; nothing falls
|
||||
|
||||
Reference in new issue
Block a user