7a1e8351a7
https://ghp.unkin.net/ 308-loops onto itself. The traefik gateway terminates TLS and forwards cleartext to the ghp Service port 80 -> container :8080, but :8080 was `GHP_SERVER_HTTP_LISTEN` — ghp's http->https **308 redirect** listener. So ghp bounced every request back to https, the gateway re-forwarded it to :8080, and it looped forever. ## Root cause (confirmed against ghp source) `internal/server/server.go` `Run()` picks the serving mode: ```go hasTLS := s.cfg.Server.HTTPSListen != "" || (systemd socket + certs) if hasTLS { return s.serveTLS(...) } // app on HTTPSListen (TLS); HTTPListen = 308 redirect; Listen IGNORED return s.servePlain(...) // app (full handler: mgmt UI + API) on Listen, cleartext ``` It is **strictly either/or**. `serveTLS` serves the app on `HTTPSListen` and gives `HTTPListen` only `httpsRedirectHandler()` (`redirect.go`: `http.StatusPermanentRedirect` = 308). `servePlain` serves the same full handler on `Listen` in cleartext (`createListener()` uses `cfg.Server.Listen`). The mgmt UI is the same `handler` in both modes, so it IS served on the plain `Listen` port. Behind a TLS-terminating gateway that forwards cleartext to :8080, ghp therefore has to run in **plain mode**. Keeping `GHP_SERVER_HTTPS_LISTEN` would keep `hasTLS` true, leave `GHP_SERVER_LISTEN` ignored, and nothing would serve cleartext on :8080. ## Change - **configmap**: drop `GHP_SERVER_HTTPS_LISTEN` and `GHP_SERVER_HTTP_LISTEN`; set `GHP_SERVER_LISTEN: ":8080"` so :8080 SERVES the app; add `GHP_SERVER_TRUST_PROXY_HEADERS: "true"` so ghp trusts the gateway's `X-Forwarded-*`/`Forwarded` for scheme/host (`GHP_SERVER_BASE_URL` already set). - **deployment + vmservicescrape**: the metrics server only wraps TLS when `hasTLS` is true (`Run()` gates `loadTLSConfig` on `hasTLS`); in plain mode it is cleartext, so the `/metrics` liveness/readiness probes and the VMServiceScrape switch from HTTPS/https to HTTP/http. Service, HTTPRoute and Gateway are unchanged. configmap+deployment carry the stakater reloader annotation, so pods roll on the change. ## Deviation from the brief The brief said to keep `GHP_SERVER_HTTPS_LISTEN: ":8443"`. Source shows that is incompatible with serving cleartext on :8080 (the two modes are mutually exclusive), so this drops it. The unused `GHP_TLS_CERT_FILE`/`KEY_FILE`, the `tls` volume, and containerPort 8443 are left in place (harmless) for an easy revert to TLS mode. The alternative — gateway -> Service 443 -> :8443 with a BackendTLSPolicy — is the bigger change flagged in the brief and is NOT taken here. Validated: `kustomize build apps/overlays/au-syd1/ghp` clean, kubeconform 0 invalid/0 errors, pre-commit clean. Not applied. --------- Co-authored-by: unkin-agent <agent@unkin.net> Reviewed-on: #361 Co-authored-by: Unkin Agent <unkin-agent@unkin.net> Co-committed-by: Unkin Agent <unkin-agent@unkin.net>
152 lines
4.7 KiB
YAML
152 lines
4.7 KiB
YAML
---
|
|
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: ghp
|
|
namespace: ghp
|
|
annotations:
|
|
# Wave 2: serve only after the wave-1 migrate Job completes.
|
|
argocd.argoproj.io/sync-wave: "2"
|
|
configmap.reloader.stakater.com/auto: "true"
|
|
secret.reloader.stakater.com/reload: "ghp-github-app,ghp-app,ghp-tls,postgres-app"
|
|
spec:
|
|
replicas: 2
|
|
selector:
|
|
matchLabels:
|
|
app: ghp
|
|
strategy:
|
|
rollingUpdate:
|
|
maxUnavailable: 1
|
|
type: RollingUpdate
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app: ghp
|
|
spec:
|
|
serviceAccountName: default
|
|
automountServiceAccountToken: true
|
|
securityContext:
|
|
runAsNonRoot: true
|
|
runAsUser: 65532
|
|
runAsGroup: 65532
|
|
fsGroup: 65532
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
containers:
|
|
- name: ghp
|
|
image: ghcr.io/goodtune/ghp:0.20.0
|
|
imagePullPolicy: IfNotPresent
|
|
# Drop the image's default --migrate so replicas never race migrations;
|
|
# schema is applied by the wave-1 migrate hook Job instead.
|
|
command: ["/ghp", "serve"]
|
|
ports:
|
|
- containerPort: 8443
|
|
name: https
|
|
protocol: TCP
|
|
- containerPort: 8080
|
|
name: http
|
|
protocol: TCP
|
|
- containerPort: 9136
|
|
name: metrics
|
|
protocol: TCP
|
|
envFrom:
|
|
- configMapRef:
|
|
name: ghp-env
|
|
optional: false
|
|
env:
|
|
# DSN assembled from the CNPG-generated postgres-app Secret; $(VAR)
|
|
# expansion resolves the two env entries defined above it.
|
|
- name: GHP_DB_USER
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: postgres-app
|
|
key: username
|
|
- name: GHP_DB_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: postgres-app
|
|
key: password
|
|
- name: GHP_DATABASE_DSN
|
|
value: "postgres://$(GHP_DB_USER):$(GHP_DB_PASSWORD)@postgres-rw.ghp.svc:5432/ghp?sslmode=require"
|
|
- name: GHP_GITHUB_APP_ID
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: ghp-github-app
|
|
key: app_id
|
|
- name: GHP_GITHUB_CLIENT_ID
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: ghp-github-app
|
|
key: client_id
|
|
- name: GHP_GITHUB_CLIENT_SECRET
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: ghp-github-app
|
|
key: client_secret
|
|
- name: GHP_ENCRYPTION_KEY
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: ghp-app
|
|
key: encryption_key
|
|
volumeMounts:
|
|
- name: github-app
|
|
mountPath: /etc/ghp/github-app
|
|
readOnly: true
|
|
- name: tls
|
|
mountPath: /etc/ghp/tls
|
|
readOnly: true
|
|
- name: tmp
|
|
mountPath: /tmp
|
|
livenessProbe:
|
|
failureThreshold: 3
|
|
httpGet:
|
|
path: /metrics
|
|
port: metrics
|
|
# Plain HTTP: ghp only serves metrics over TLS in TLS mode
|
|
# (hasTLS). In reverse-proxy/plain mode the metrics server is
|
|
# cleartext, so probe with HTTP.
|
|
scheme: HTTP
|
|
initialDelaySeconds: 30
|
|
periodSeconds: 30
|
|
successThreshold: 1
|
|
timeoutSeconds: 5
|
|
readinessProbe:
|
|
failureThreshold: 3
|
|
httpGet:
|
|
path: /metrics
|
|
port: metrics
|
|
# Plain HTTP: ghp only serves metrics over TLS in TLS mode
|
|
# (hasTLS). In reverse-proxy/plain mode the metrics server is
|
|
# cleartext, so probe with HTTP.
|
|
scheme: HTTP
|
|
initialDelaySeconds: 10
|
|
periodSeconds: 5
|
|
successThreshold: 1
|
|
timeoutSeconds: 5
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
readOnlyRootFilesystem: true
|
|
capabilities:
|
|
drop:
|
|
- ALL
|
|
resources:
|
|
limits:
|
|
cpu: "2"
|
|
memory: 2Gi
|
|
requests:
|
|
cpu: "1"
|
|
memory: 512Mi
|
|
volumes:
|
|
- name: github-app
|
|
secret:
|
|
secretName: ghp-github-app
|
|
- name: tls
|
|
secret:
|
|
secretName: ghp-tls
|
|
# Writable scratch: root FS is read-only. Disk-backed (not memory medium)
|
|
# so codeload tarball staging doesn't count against the pod memory limit.
|
|
- name: tmp
|
|
emptyDir:
|
|
sizeLimit: 2Gi
|
|
restartPolicy: Always
|