Skip to content

gateway: five statements in the TenantGateway package describe the code incorrectly, one of them in the CRD #4207

Description

Describe the bug

Five statements in the TenantGateway package describe the code incorrectly. Each is a phrase or a single string, none has logic behind it, and they are collected here so they can be corrected as one change rather than one at a time.

  1. internal/controller/tenantgateway/renderers.go and packages/extra/gateway/README.md say that dns01 and existingSecret serve the tenant from one terminate listener for *.<apex>. Two render: https for *.<apex> and https-apex for <apex>, and hostnameCovers needs the leading dot so *.<apex> does not intersect an entry whose hostname equals the apex. The refusal those modes carry is correct; the mechanism stated for it is not, and it is the mechanism the next reader will reason from when the Cilium pin moves.

  2. packages/extra/gateway/README.md says spec.apex arrives verbatim from the namespace.cozystack.io/host label. The chart reads _namespace.host from the cozystack-values Secret. A comment in renderers.go already says the tenant chart writes both from the same computed host, so the two disagree in one package.

  3. The tlsPassthroughListeners godoc says nothing is routed until a TLSRoute attaches by sectionName. A TLSRoute with no sectionName in the publishing tenant's namespace is lent a native-port listener's hostname and is routed. This one ships into the CRD description and reaches every cluster through kubectl explain, so it is the one worth correcting first.

  4. renderGateway's godoc says a hostname is "owned by an HTTPRoute" where the code tests claimed. In this file "owner" means the winner of the hostname race, and the two are decided separately.

  5. describeWithdrawn renders the port-mismatch cause as "<hostname> (port N, answered on another port)". When the offending HTTPRoute is the only claimant of that hostname no terminate listener is rendered at all, so nothing answers the name on any port and the parenthetical asserts a listener that does not exist. The actionable half, which port was wrong, stays correct.

Environment

  • Cozystack main, after the TLS-passthrough listener work lands

Expected behaviour

The package's prose, its godoc and its status messages describe what the code does, particularly the godoc that ships into the CRD.

Additional context

Surfaced while reviewing #3342 and disclosed in that thread rather than fixed there, to keep a reviewed head stable. Items 1 to 4 are phrase edits; item 5 is one string.

Checklist

  • I have checked the documentation
  • I have searched for similar issues
  • I have included all required information
  • I have provided clear steps to reproduce
  • I have included relevant logs

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/networkingIssues or PRs related to networking (ingress, gateway, vpn, metallb, kube-ovn)kind/bugCategorizes issue or PR as related to a bugpriority/backlogGeneral backlog priority. Lower than priority/important-longtermtriage/acceptedIndicates an issue is ready to be actively worked on

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions