feat(platform): internal API base-URL helper and single-sourced token secret
InternalAPIBaseURL builds the felis-api internal-face DNS from SAAPI and the internal port for cross-namespace callers (the login limbo). The service-token Secret name/key now reference the shared naming constants so the Deployment wiring and the operator's login-pod injection cannot drift.
This commit is contained in:
1 file changed
+18
-2
@@ -3,6 +3,7 @@ package platform
|
||||
import (
|
||||
"fmt"
|
||||
|
||||
"felis.lolicon.best/internal/naming"
|
||||
appsv1 "k8s.io/api/apps/v1"
|
||||
batchv1 "k8s.io/api/batch/v1"
|
||||
corev1 "k8s.io/api/core/v1"
|
||||
@@ -51,8 +52,10 @@ const (
|
||||
configMountPath = "/etc/felis"
|
||||
configFilePath = "/etc/felis/felis.toml"
|
||||
felisBinaryPath = "/usr/local/bin/felis"
|
||||
serviceTokenSecretName = "felis-service-token"
|
||||
serviceTokenSecretKey = "token"
|
||||
// Single-sourced with the operator, which injects the same Secret into the
|
||||
// login system server's pod (see internal/naming).
|
||||
serviceTokenSecretName = naming.ServiceTokenSecretName
|
||||
serviceTokenSecretKey = naming.ServiceTokenSecretKey
|
||||
|
||||
// Ports, single-sourced with the entrypoints (cmd/felis). The api external
|
||||
// port must match server.listen in felis.toml (default 0.0.0.0:8080); that
|
||||
@@ -99,6 +102,19 @@ const (
|
||||
nonRootUID int64 = 1000
|
||||
)
|
||||
|
||||
// InternalAPIBaseURL returns the in-cluster base URL of the felis-api INTERNAL
|
||||
// face for a caller in another namespace — specifically the login system server,
|
||||
// which dials it with the service token to mint bind codes and poll link status.
|
||||
// It single-sources the Service name (SAAPI, in the control namespace) and the
|
||||
// internal port with the Deployment/Service above, so a rename or port change here
|
||||
// can never drift from what the login pod is told to call. Cross-namespace DNS is
|
||||
// always resolvable; reachability additionally depends on there being no fence in
|
||||
// the way (today neither the minecraft-ns egress nor the control-ns ingress is
|
||||
// policy-locked, so the path is open — see internal/platform/netpol.go).
|
||||
func InternalAPIBaseURL(controlNamespace string) string {
|
||||
return fmt.Sprintf("http://%s.%s.svc.cluster.local:%d", SAAPI, controlNamespace, apiInternalPort)
|
||||
}
|
||||
|
||||
// Workloads renders the running control-plane: the felis-api Deployment, the
|
||||
// felis-operator Deployment, and the in-cluster registry (Deployment + Service +
|
||||
// PVC), plus the reaper CronJob when reaperEnabled(p). FelisImage is required —
|
||||
|
||||
Reference in new issue
Block a user