Documentation
¶
Overview ¶
Package ingressmanifest builds YAML for the host-based platform UI Ingress.
Index ¶
Constants ¶
const ( // PlatformIngressName is the Kubernetes Ingress resource name for the dashboard. PlatformIngressName = "mcp-platform-ui" // PlatformObservabilityIngressName is the admin-gated platform Ingress for Grafana. PlatformObservabilityIngressName = "mcp-platform-observability" // PlatformAnalyticsIngressName is the public Ingress for analytics-api. PlatformAnalyticsIngressName = "mcp-platform-analytics" // PlatformHTTPRedirectIngressName is the HTTP-only redirect Ingress resource name. PlatformHTTPRedirectIngressName = "mcp-platform-ui-http" // PlatformTLSSecretName is the TLS secret name used when TLS is enabled. PlatformTLSSecretName = "mcp-platform-tls" // #nosec G101 -- Kubernetes Secret name, not a credential. )
Variables ¶
This section is empty.
Functions ¶
func RenderPlatformUIIngress ¶
func RenderPlatformUIIngress(host, issuerName string, tlsEnabled bool, platformNamespace, observabilityNamespace string) string
RenderPlatformUIIngress emits Ingresses for platform.<domain>. The UI, platform-api, and runtime-api Ingress is created in platformNamespace. Grafana and analytics-api routes are created in observabilityNamespace, beside those Services. Server-side UI auth still uses API_UPSTREAM against platform-api. The observability Ingress uses the repo-managed sentinel-admin-auth@file Traefik middleware so Grafana is reachable from admin UI links without exposing it raw on the public platform host. Prometheus stays internal as Grafana's metrics datasource and is not exposed as a direct public route.
When issuerName is set, only the platform Ingress gets a TLS section and cert-manager annotation. Ingress-shim then creates one Certificate named mcp-platform-tls in platformNamespace. The observability Ingress does not name a Secret and does not request a Certificate: a TLS Secret cannot be mounted across namespaces, and a second Certificate would open another ACME order for the same hostname. Traefik serves that host from the certificate loaded by the platform Ingress. An HTTP Ingress on the web entrypoint sends plain requests to the UI, which redirects to HTTPS. The prod overlay disables Traefik's entrypoint redirect so HTTP-01 challenges keep working.
Types ¶
type APIPath ¶
APIPath describes a Traefik/Kubernetes ingress route for /api/v1 split services.
func ObservabilityAPIPaths ¶
func ObservabilityAPIPaths() []APIPath
ObservabilityAPIPaths returns observability-namespace ingress rules.
func PlatformAPIPaths ¶
func PlatformAPIPaths() []APIPath
PlatformAPIPaths returns platform-namespace ingress rules, most-specific first.