dotnet / dotnet/yarp

Yarp namespaced Ingress Controller support

Open
#2,964 0 comments 0 reactions 0 assignees View on GitHub
Kubernetes Ingress Controller Type: Idea
Dominant language
C#
Stars
9.6k
Forks
933
Avg merge
12d 18h
Merged PRs (30d)
2

Description

### What should we add or change to make your life better?

Hi there,

I followed [ingress-controller.yaml](https://github.com/dotnet/yarp/blob/main/samples/KubernetesIngress.Sample/Combined/ingress-controller.yaml) to set up Yarp Ingress Controlelr for applications. I'm wondering if Yarp is possible to support **namespaced** Ingress Controller like https://developer.konghq.com/kubernetes-ingress-controller/workspaces/?

I looked at the Yarp Ingress Controller implementation. Currently the implementation uses apis such as `ListIngressForAllNamespacesWithHttpMessagesAsync()` to list a kind of resources in all namespaces. I think the main change involves invoking C# [KubernetesClient](https://github.com/kubernetes-client/csharp) to list a give namespaced resource such as `ListNamespacedPod("default")`.

I am also aware of the current design considerations. One approach is to employ `fieldSelector` to selectively get resources from a given namespace. What's more, my feature request could complicate the implementation where reading more than one namespace resource is required.

### Why is this important to you?

I'm using the Yarp Ingress Controller as a replacement for Kong Ingress Controller. In my environment, each namespace runs an isolated application.

I prefer to avoid using `clusterrole` and `clusterrolebinding` and let each Yarp read only the namespace I specify.

I regard this Issue as a place to have a broad discussion. I really appreciate any feedback!

### Testing

I tried to get around by creating a `ServiceAccount` and using a `RoleBinding` to bind the `ClusterRole`. But it didn't work. See the error logs:

> yarp-ingress-c99b49c49-99nvn System.AggregateException: One or more hosted services failed to stop. (Operation returned an invalid status code 'Forbidden', response body {"kind":"Status","apiVersion":"v1","metadata":{},"status":"Failure","message":"endpoints is forbidden: User \"system:serviceaccount:dev:restrict-yarp\" cannot list resource \"endpoints\" in API group \"\" at the cluster scope: Azure does not have opinion for this user.","reason":"Forbidden","details":{"kind":"endpoints"},"code":403}
> yarp-ingress-c99b49c49-99nvn ) (Operation returned an invalid status code 'Forbidden', response body {"kind":"Status","apiVersion":"v1","metadata":{},"status":"Failure","message":"services is forbidden: User \"system:serviceaccount:dev:restrict-yarp\" cannot list resource \"services\" in API group \"\" at the cluster scope: Azure does not have opinion for this user.","reason":"Forbidden","details":{"kind":"services"},"code":403}

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.