Unverified Commit 3fdb3d03 authored by Minseong Choi's avatar Minseong Choi 💬
Browse files

feat(platform): internal API base-URL helper and single-sourced token secret

InternalAPIBaseURL builds the felis-api internal-face DNS from SAAPI and the internal port for cross-namespace callers (the login limbo). The service-token Secret name/key now reference the shared naming constants so the Deployment wiring and the operator's login-pod injection cannot drift.
parent dc23cb54
Loading
Loading
Loading
Loading
+18 −2
Changes for internal/platform/workloads.go: 18 added lines, 2 removed lines.
Original line number Diff line number Diff line
@@ -3,6 +3,7 @@ package platform
import (
	"fmt"

	"felis.lolicon.best/internal/naming"
	appsv1 "k8s.io/api/apps/v1"
	batchv1 "k8s.io/api/batch/v1"
	corev1 "k8s.io/api/core/v1"
@@ -51,8 +52,10 @@ const (
	configMountPath        = "/etc/felis"
	configFilePath         = "/etc/felis/felis.toml"
	felisBinaryPath        = "/usr/local/bin/felis"
	serviceTokenSecretName = "felis-service-token"
	serviceTokenSecretKey  = "token"
	// Single-sourced with the operator, which injects the same Secret into the
	// login system server's pod (see internal/naming).
	serviceTokenSecretName = naming.ServiceTokenSecretName
	serviceTokenSecretKey  = naming.ServiceTokenSecretKey

	// Ports, single-sourced with the entrypoints (cmd/felis). The api external
	// port must match server.listen in felis.toml (default 0.0.0.0:8080); that
@@ -99,6 +102,19 @@ const (
	nonRootUID int64 = 1000
)

// InternalAPIBaseURL returns the in-cluster base URL of the felis-api INTERNAL
// face for a caller in another namespace — specifically the login system server,
// which dials it with the service token to mint bind codes and poll link status.
// It single-sources the Service name (SAAPI, in the control namespace) and the
// internal port with the Deployment/Service above, so a rename or port change here
// can never drift from what the login pod is told to call. Cross-namespace DNS is
// always resolvable; reachability additionally depends on there being no fence in
// the way (today neither the minecraft-ns egress nor the control-ns ingress is
// policy-locked, so the path is open — see internal/platform/netpol.go).
func InternalAPIBaseURL(controlNamespace string) string {
	return fmt.Sprintf("http://%s.%s.svc.cluster.local:%d", SAAPI, controlNamespace, apiInternalPort)
}

// Workloads renders the running control-plane: the felis-api Deployment, the
// felis-operator Deployment, and the in-cluster registry (Deployment + Service +
// PVC), plus the reaper CronJob when reaperEnabled(p). FelisImage is required —