From 3fdb3d032efe00d3b5a1a012c051a680f1a4ae22 Mon Sep 17 00:00:00 2001 From: Minseong Choi Date: Thu, 2 Jul 2026 19:37:11 +0900 Subject: [PATCH] feat(platform): internal API base-URL helper and single-sourced token secret InternalAPIBaseURL builds the felis-api internal-face DNS from SAAPI and the internal port for cross-namespace callers (the login limbo). The service-token Secret name/key now reference the shared naming constants so the Deployment wiring and the operator's login-pod injection cannot drift. --- internal/platform/workloads.go | 20 ++++++++++++++++++-- 1 file changed, 18 insertions(+), 2 deletions(-) diff --git a/internal/platform/workloads.go b/internal/platform/workloads.go index 5c0e36a..f7583d2 100644 --- a/internal/platform/workloads.go +++ b/internal/platform/workloads.go @@ -3,6 +3,7 @@ package platform import ( "fmt" + "felis.lolicon.best/internal/naming" appsv1 "k8s.io/api/apps/v1" batchv1 "k8s.io/api/batch/v1" corev1 "k8s.io/api/core/v1" @@ -51,8 +52,10 @@ const ( configMountPath = "/etc/felis" configFilePath = "/etc/felis/felis.toml" felisBinaryPath = "/usr/local/bin/felis" - serviceTokenSecretName = "felis-service-token" - serviceTokenSecretKey = "token" + // Single-sourced with the operator, which injects the same Secret into the + // login system server's pod (see internal/naming). + serviceTokenSecretName = naming.ServiceTokenSecretName + serviceTokenSecretKey = naming.ServiceTokenSecretKey // Ports, single-sourced with the entrypoints (cmd/felis). The api external // port must match server.listen in felis.toml (default 0.0.0.0:8080); that @@ -99,6 +102,19 @@ const ( nonRootUID int64 = 1000 ) +// InternalAPIBaseURL returns the in-cluster base URL of the felis-api INTERNAL +// face for a caller in another namespace — specifically the login system server, +// which dials it with the service token to mint bind codes and poll link status. +// It single-sources the Service name (SAAPI, in the control namespace) and the +// internal port with the Deployment/Service above, so a rename or port change here +// can never drift from what the login pod is told to call. Cross-namespace DNS is +// always resolvable; reachability additionally depends on there being no fence in +// the way (today neither the minecraft-ns egress nor the control-ns ingress is +// policy-locked, so the path is open — see internal/platform/netpol.go). +func InternalAPIBaseURL(controlNamespace string) string { + return fmt.Sprintf("http://%s.%s.svc.cluster.local:%d", SAAPI, controlNamespace, apiInternalPort) +} + // Workloads renders the running control-plane: the felis-api Deployment, the // felis-operator Deployment, and the in-cluster registry (Deployment + Service + // PVC), plus the reaper CronJob when reaperEnabled(p). FelisImage is required —