Describe the bug
Five statements in the TenantGateway package describe the code incorrectly. Each is a phrase or a single string, none has logic behind it, and they are collected here so they can be corrected as one change rather than one at a time.
-
internal/controller/tenantgateway/renderers.go and packages/extra/gateway/README.md say that dns01 and existingSecret serve the tenant from one terminate listener for *.<apex>. Two render: https for *.<apex> and https-apex for <apex>, and hostnameCovers needs the leading dot so *.<apex> does not intersect an entry whose hostname equals the apex. The refusal those modes carry is correct; the mechanism stated for it is not, and it is the mechanism the next reader will reason from when the Cilium pin moves.
-
packages/extra/gateway/README.md says spec.apex arrives verbatim from the namespace.cozystack.io/host label. The chart reads _namespace.host from the cozystack-values Secret. A comment in renderers.go already says the tenant chart writes both from the same computed host, so the two disagree in one package.
-
The tlsPassthroughListeners godoc says nothing is routed until a TLSRoute attaches by sectionName. A TLSRoute with no sectionName in the publishing tenant's namespace is lent a native-port listener's hostname and is routed. This one ships into the CRD description and reaches every cluster through kubectl explain, so it is the one worth correcting first.
-
renderGateway's godoc says a hostname is "owned by an HTTPRoute" where the code tests claimed. In this file "owner" means the winner of the hostname race, and the two are decided separately.
-
describeWithdrawn renders the port-mismatch cause as "<hostname> (port N, answered on another port)". When the offending HTTPRoute is the only claimant of that hostname no terminate listener is rendered at all, so nothing answers the name on any port and the parenthetical asserts a listener that does not exist. The actionable half, which port was wrong, stays correct.
Environment
- Cozystack main, after the TLS-passthrough listener work lands
Expected behaviour
The package's prose, its godoc and its status messages describe what the code does, particularly the godoc that ships into the CRD.
Additional context
Surfaced while reviewing #3342 and disclosed in that thread rather than fixed there, to keep a reviewed head stable. Items 1 to 4 are phrase edits; item 5 is one string.
Checklist
Describe the bug
Five statements in the TenantGateway package describe the code incorrectly. Each is a phrase or a single string, none has logic behind it, and they are collected here so they can be corrected as one change rather than one at a time.
internal/controller/tenantgateway/renderers.goandpackages/extra/gateway/README.mdsay thatdns01andexistingSecretserve the tenant from one terminate listener for*.<apex>. Two render:httpsfor*.<apex>andhttps-apexfor<apex>, andhostnameCoversneeds the leading dot so*.<apex>does not intersect an entry whose hostname equals the apex. The refusal those modes carry is correct; the mechanism stated for it is not, and it is the mechanism the next reader will reason from when the Cilium pin moves.packages/extra/gateway/README.mdsaysspec.apexarrives verbatim from thenamespace.cozystack.io/hostlabel. The chart reads_namespace.hostfrom thecozystack-valuesSecret. A comment inrenderers.goalready says the tenant chart writes both from the same computed host, so the two disagree in one package.The
tlsPassthroughListenersgodoc says nothing is routed until a TLSRoute attaches bysectionName. A TLSRoute with nosectionNamein the publishing tenant's namespace is lent a native-port listener's hostname and is routed. This one ships into the CRD description and reaches every cluster throughkubectl explain, so it is the one worth correcting first.renderGateway's godoc says a hostname is "owned by an HTTPRoute" where the code testsclaimed. In this file "owner" means the winner of the hostname race, and the two are decided separately.describeWithdrawnrenders the port-mismatch cause as"<hostname> (port N, answered on another port)". When the offending HTTPRoute is the only claimant of that hostname no terminate listener is rendered at all, so nothing answers the name on any port and the parenthetical asserts a listener that does not exist. The actionable half, which port was wrong, stays correct.Environment
Expected behaviour
The package's prose, its godoc and its status messages describe what the code does, particularly the godoc that ships into the CRD.
Additional context
Surfaced while reviewing #3342 and disclosed in that thread rather than fixed there, to keep a reviewed head stable. Items 1 to 4 are phrase edits; item 5 is one string.
Checklist