fix(deploy): disable ingress ssl-redirect (edge terminates TLS, ingress is HTTP-only)

This commit is contained in:
Josh Belke 2026-06-02 01:45:18 -04:00
commit 6e1da5aa61
4 changed files with 11 additions and 6 deletions

View file

@ -5,7 +5,7 @@ description: >-
for the RAID-K8-ILAB cluster, served at holocron.r2d2.office.ilab.zone.
type: application
# Chart version tracks packaging; appVersion tracks the holocron-frontend image.
version: 0.2.0
version: 0.2.1
appVersion: "1.0.0"
keywords:
- holocron

1
deploy/holocron/Untitled Normal file
View file

@ -0,0 +1 @@
nginx.ingress.kubernetes.io/ssl-redirect

View file

@ -37,6 +37,10 @@ ingress:
className: nginx
host: holocron.r2d2.office.ilab.zone
annotations:
# The office edge terminates TLS and proxies to this ingress over HTTP.
# Disable the ingress's own HTTP->HTTPS redirect so it doesn't 308 the
# edge's plain-HTTP requests (the ingress has no TLS block of its own).
nginx.ingress.kubernetes.io/ssl-redirect: "false"
# WebSocket upgrade + long-lived connection on /ws.
nginx.ingress.kubernetes.io/proxy-read-timeout: "3600"
nginx.ingress.kubernetes.io/proxy-send-timeout: "3600"

View file

@ -31,8 +31,8 @@ imagePullSecrets: []
# Frontend container ports (server.cjs).
ports:
http: 3001 # Express HTTP + REST API + static SPA, /health probe
ws: 9002 # WebSocket bridge (MQTT -> browser); routed at /ws by the ingress
http: 3001 # Express HTTP + REST API + static SPA, /health probe
ws: 9002 # WebSocket bridge (MQTT -> browser); routed at /ws by the ingress
# Runtime configuration injected as env (non-secret) via a ConfigMap.
config:
@ -40,10 +40,10 @@ config:
# MQTT broker the bridge connects to. Default points at the in-cluster
# mosquitto deployed by this chart (see mqtt.* below). Override to target an
# external broker.
MQTT_BROKER: "" # empty -> derived from mqtt.enabled (see _helpers/configmap)
MQTT_BROKER: "" # empty -> derived from mqtt.enabled (see _helpers/configmap)
MQTT_TOPIC_PREFIX: "r2d2/holocron"
# Public WebSocket URL handed to the browser. Must be reachable from clients.
WS_PUBLIC_URL: "" # e.g. wss://holocron.r2d2.office.ilab.zone/ws
WS_PUBLIC_URL: "" # e.g. wss://holocron.r2d2.office.ilab.zone/ws
# Restrict CORS to the embedding/public origins in production. Empty -> same-origin only.
CORS_ORIGIN: ""
MAX_MESSAGE_BYTES: "524288"
@ -76,7 +76,7 @@ ingress:
annotations: {}
# Single public host. "/" -> http (SPA + API), "/ws" -> websocket bridge.
host: holocron.r2d2.office.ilab.zone
tls: [] # TLS is terminated at the office edge; ingress stays HTTP (port 80).
tls: [] # TLS is terminated at the office edge; ingress stays HTTP (port 80).
resources:
requests: