feat(platform): internal API base-URL helper and single-sourced token secret
InternalAPIBaseURL builds the felis-api internal-face DNS from SAAPI and the internal port for cross-namespace callers (the login limbo). The service-token Secret name/key now reference the shared naming constants so the Deployment wiring and the operator's login-pod injection cannot drift.
This commit is contained in:
1 file changed
+18
-2
@@ -3,6 +3,7 @@ package platform
|
|||||||
import (
|
import (
|
||||||
"fmt"
|
"fmt"
|
||||||
|
|
||||||
|
"felis.lolicon.best/internal/naming"
|
||||||
appsv1 "k8s.io/api/apps/v1"
|
appsv1 "k8s.io/api/apps/v1"
|
||||||
batchv1 "k8s.io/api/batch/v1"
|
batchv1 "k8s.io/api/batch/v1"
|
||||||
corev1 "k8s.io/api/core/v1"
|
corev1 "k8s.io/api/core/v1"
|
||||||
@@ -51,8 +52,10 @@ const (
|
|||||||
configMountPath = "/etc/felis"
|
configMountPath = "/etc/felis"
|
||||||
configFilePath = "/etc/felis/felis.toml"
|
configFilePath = "/etc/felis/felis.toml"
|
||||||
felisBinaryPath = "/usr/local/bin/felis"
|
felisBinaryPath = "/usr/local/bin/felis"
|
||||||
serviceTokenSecretName = "felis-service-token"
|
// Single-sourced with the operator, which injects the same Secret into the
|
||||||
serviceTokenSecretKey = "token"
|
// login system server's pod (see internal/naming).
|
||||||
|
serviceTokenSecretName = naming.ServiceTokenSecretName
|
||||||
|
serviceTokenSecretKey = naming.ServiceTokenSecretKey
|
||||||
|
|
||||||
// Ports, single-sourced with the entrypoints (cmd/felis). The api external
|
// Ports, single-sourced with the entrypoints (cmd/felis). The api external
|
||||||
// port must match server.listen in felis.toml (default 0.0.0.0:8080); that
|
// port must match server.listen in felis.toml (default 0.0.0.0:8080); that
|
||||||
@@ -99,6 +102,19 @@ const (
|
|||||||
nonRootUID int64 = 1000
|
nonRootUID int64 = 1000
|
||||||
)
|
)
|
||||||
|
|
||||||
|
// InternalAPIBaseURL returns the in-cluster base URL of the felis-api INTERNAL
|
||||||
|
// face for a caller in another namespace — specifically the login system server,
|
||||||
|
// which dials it with the service token to mint bind codes and poll link status.
|
||||||
|
// It single-sources the Service name (SAAPI, in the control namespace) and the
|
||||||
|
// internal port with the Deployment/Service above, so a rename or port change here
|
||||||
|
// can never drift from what the login pod is told to call. Cross-namespace DNS is
|
||||||
|
// always resolvable; reachability additionally depends on there being no fence in
|
||||||
|
// the way (today neither the minecraft-ns egress nor the control-ns ingress is
|
||||||
|
// policy-locked, so the path is open — see internal/platform/netpol.go).
|
||||||
|
func InternalAPIBaseURL(controlNamespace string) string {
|
||||||
|
return fmt.Sprintf("http://%s.%s.svc.cluster.local:%d", SAAPI, controlNamespace, apiInternalPort)
|
||||||
|
}
|
||||||
|
|
||||||
// Workloads renders the running control-plane: the felis-api Deployment, the
|
// Workloads renders the running control-plane: the felis-api Deployment, the
|
||||||
// felis-operator Deployment, and the in-cluster registry (Deployment + Service +
|
// felis-operator Deployment, and the in-cluster registry (Deployment + Service +
|
||||||
// PVC), plus the reaper CronJob when reaperEnabled(p). FelisImage is required —
|
// PVC), plus the reaper CronJob when reaperEnabled(p). FelisImage is required —
|
||||||
|
|||||||
Reference in new issue
Block a user