feat(platform): internal API base-URL helper and single-sourced token secret

InternalAPIBaseURL builds the felis-api internal-face DNS from SAAPI and the internal port for cross-namespace callers (the login limbo). The service-token Secret name/key now reference the shared naming constants so the Deployment wiring and the operator's login-pod injection cannot drift.
This commit is contained in:
flyemoji committed 2026-07-02 19:38:37 +09:00
1 parent dc23cb54d2
commit 3fdb3d032e
1 file changed
+18 -2
+18 -2
View File
@@ -3,6 +3,7 @@ package platform
import ( import (
"fmt" "fmt"
"felis.lolicon.best/internal/naming"
appsv1 "k8s.io/api/apps/v1" appsv1 "k8s.io/api/apps/v1"
batchv1 "k8s.io/api/batch/v1" batchv1 "k8s.io/api/batch/v1"
corev1 "k8s.io/api/core/v1" corev1 "k8s.io/api/core/v1"
@@ -51,8 +52,10 @@ const (
configMountPath = "/etc/felis" configMountPath = "/etc/felis"
configFilePath = "/etc/felis/felis.toml" configFilePath = "/etc/felis/felis.toml"
felisBinaryPath = "/usr/local/bin/felis" felisBinaryPath = "/usr/local/bin/felis"
serviceTokenSecretName = "felis-service-token" // Single-sourced with the operator, which injects the same Secret into the
serviceTokenSecretKey = "token" // login system server's pod (see internal/naming).
serviceTokenSecretName = naming.ServiceTokenSecretName
serviceTokenSecretKey = naming.ServiceTokenSecretKey
// Ports, single-sourced with the entrypoints (cmd/felis). The api external // Ports, single-sourced with the entrypoints (cmd/felis). The api external
// port must match server.listen in felis.toml (default 0.0.0.0:8080); that // port must match server.listen in felis.toml (default 0.0.0.0:8080); that
@@ -99,6 +102,19 @@ const (
nonRootUID int64 = 1000 nonRootUID int64 = 1000
) )
// InternalAPIBaseURL returns the in-cluster base URL of the felis-api INTERNAL
// face for a caller in another namespace — specifically the login system server,
// which dials it with the service token to mint bind codes and poll link status.
// It single-sources the Service name (SAAPI, in the control namespace) and the
// internal port with the Deployment/Service above, so a rename or port change here
// can never drift from what the login pod is told to call. Cross-namespace DNS is
// always resolvable; reachability additionally depends on there being no fence in
// the way (today neither the minecraft-ns egress nor the control-ns ingress is
// policy-locked, so the path is open — see internal/platform/netpol.go).
func InternalAPIBaseURL(controlNamespace string) string {
return fmt.Sprintf("http://%s.%s.svc.cluster.local:%d", SAAPI, controlNamespace, apiInternalPort)
}
// Workloads renders the running control-plane: the felis-api Deployment, the // Workloads renders the running control-plane: the felis-api Deployment, the
// felis-operator Deployment, and the in-cluster registry (Deployment + Service + // felis-operator Deployment, and the in-cluster registry (Deployment + Service +
// PVC), plus the reaper CronJob when reaperEnabled(p). FelisImage is required — // PVC), plus the reaper CronJob when reaperEnabled(p). FelisImage is required —