feat(helm): add TLSRoute passthrough support for gateway api (#6169)

Add an optional TLS passthrough listener to the Gateway API support. When gatewayApi.listeners.tls.enabled is true, the Gateway gets a TLS listener with tls.mode: Passthrough and a TLSRoute is rendered to the RustFS service so TLS terminates at the backend (end-to-end encryption).

Refs rustfs/rustfs#3862.
This commit is contained in:
hector
2026-08-18 01:21:15 +08:00
committed by GitHub
parent 59b7d13095
commit beb6e1383e
4 changed files with 47 additions and 0 deletions
@@ -26,5 +26,15 @@ spec:
- name: {{ include "rustfs.fullname" $ }}-tls
kind: Secret
{{- end }}
{{- if .tls.enabled }}
- name: {{ .tls.name }}
port: {{ .tls.port }}
protocol: TLS
tls:
mode: Passthrough
allowedRoutes:
namespaces:
from: Same
{{- end }}
{{- end }}
{{- end }}
@@ -0,0 +1,25 @@
{{- if and .Values.gatewayApi.enabled .Values.gatewayApi.listeners.tls.enabled }}
apiVersion: gateway.networking.k8s.io/v1
kind: TLSRoute
metadata:
name: {{ include "rustfs.fullname" . }}-tlsroute
namespace: {{ .Release.Namespace }}
spec:
parentRefs:
{{- if .Values.gatewayApi.existingGateway.name }}
- name: {{ .Values.gatewayApi.existingGateway.name }}
{{- if .Values.gatewayApi.existingGateway.namespace }}
namespace: {{ .Values.gatewayApi.existingGateway.namespace }}
{{- end }}
sectionName: {{ .Values.gatewayApi.listeners.tls.name }}
{{- else }}
- name: {{ include "rustfs.fullname" $ }}-gateway
sectionName: {{ .Values.gatewayApi.listeners.tls.name }}
{{- end }}
hostnames:
- {{ .Values.gatewayApi.hostname }}
rules:
- backendRefs:
- name: {{ include "rustfs.fullname" . }}-svc
port: {{ .Values.gatewayApi.listeners.tls.backendPort | default .Values.service.console.port }}
{{- end }}
+6
View File
@@ -369,6 +369,12 @@ gatewayApi:
https:
name: websecure
port: 8443
tls: # Optional TLS passthrough listener; renders a TLSRoute so TLS terminates at the RustFS backend.
enabled: false
name: tls
port: 443
# Service port that terminates TLS on the backend; defaults to the console port.
backendPort: null
hostname: example.rustfs.com
httpToHttpsRedirect: true
existingGateway: