apache / apache/openwhisk-deploy-kube
EKS deployment does not accept https requests, only http
- Dominant language
- Shell
- Stars
- 309
- Forks
- 231
- PR merge metrics
- No merged PRs in 30d
Description
## Steps to reproduce the issue
1. Create EKS cluster: `eksctl create cluster --name test-cluster-1 --region eu-central-1 --node-type t2.large --nodes 1`
2. Label nodes: `kubectl label nodes --all openwhisk-role=invoker`
3. Install Helm chart: `helm install owdev openwhisk-deploy-kube/helm/openwhisk -n openwhisk --create-namespace -f mycluster.yaml`
4. Setup WSK CLI as the [docs ](https://github.com/apache/openwhisk-deploy-kube#configure-the-wsk-cli) say, using the load balancer's DNS: `wsk -i property set --apihost https://:443`
5. Run WSK command: `wsk list -v`
## Observations
* Output of `wsk list -v`:

* Load balancer's info from AWS Console:

* Api calls work when setting up the WSK CLI using http instead of https.
### mycluster.yaml
```yaml
k8s:
persistence:
enabled: false
whisk:
ingress:
type: LoadBalancer
annotations:
service.beta.kubernetes.io/aws-load-balancer-internal: 0.0.0.0/0
service.beta.kubernetes.io/aws-load-balancer-ssl-cert: arn:aws:iam::XXXXXXXXXXXX:server-certificate/ow-self-signed
whisk:
ingress:
awsSSL: "true"
type: LoadBalancer
annotations:
service.beta.kubernetes.io/aws-load-balancer-backend-protocol: http
service.beta.kubernetes.io/aws-load-balancer-ssl-ports: https-api
service.beta.kubernetes.io/aws-load-balancer-ssl-cert: arn:aws:acm:eu-central-1:XXXXXXXXXXXX:certificate/YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY # AWS Certificate Manager (ow-self-signed).
```
## Reason of interest
I want to use the OpenWhisk deployment as an endpoint for *AWS EventBridge*, but currently it is only possible to add *API Destinations* that use https endpoints.
Contributor guide
Research direction
The payload names no repository files or tests. Start by reproducing the issue with the listed eksctl, Helm, and WSK commands, then inspect the Helm ingress configuration and AWS LoadBalancer annotations shown in mycluster.yaml. Done means the deployed EKS endpoint accepts the WSK CLI request over HTTPS as well as HTTP.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, helm, kubernetes, shell
- Domain
- api, cloud, infrastructure, networking
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100