Repository navigation
Conversation
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
|
Thank you for the doc, leaving some diagrams that might help with discussions: Discussed this with @kon-angelo and @dimityrmirchev, our opinion is that option 3 fits the best in a k8s environment specifically. Existing k8s clusters have their networking configured using k8s primitives, so having a proxy being created by During a talk with @drew and @johntmyers, we came to the conclusion that |
Signed-off-by: Taylor Mutch <taylormutch@gmail.com>
Signed-off-by: Taylor Mutch <taylormutch@gmail.com>
Signed-off-by: Taylor Mutch <taylormutch@gmail.com>
|
Picking this RFC up from @drew, I'll be pushing an update to this branch that includes the feedback from @rrhubenov and the community call. |
Signed-off-by: Taylor Mutch <taylormutch@gmail.com>



Summary
RFC 0017 proposes a dedicated application listener on supervisors so sandbox HTTP and WebSocket traffic can bypass the gateway and its control connection. This lets operators scale application ingress and configure its access policies separately from gateway management.
The gateway continues to manage service declarations and publishes supervisor-advertised routes through authenticated discovery. Operators can integrate existing ingress with that discovery or use the optional
openshell-sandbox-proxyas a reference implementation.Design
Validation
Related issue
Closes #4266
Related work