Skip to content

Add Gateway API support for SolrCloud external addressability - #843

Open
chinmoysahu wants to merge 15 commits into
apache:mainfrom
chinmoysahu:gtw-ingress-support
Open

Add Gateway API support for SolrCloud external addressability#843
chinmoysahu wants to merge 15 commits into
apache:mainfrom
chinmoysahu:gtw-ingress-support

Conversation

@chinmoysahu

Copy link
Copy Markdown

Summary

This PR adds support for the Kubernetes Gateway API as a new external addressability method for SolrCloud instances. Gateway API is the successor to the Ingress API and provides a more flexible, vendor-neutral way to manage ingress traffic in Kubernetes.

Features

Gateway API Integration

  • New addressability method: spec.solrAddressability.external.method: Gateway
  • Automatic HTTPRoute management for common and per-node services
  • Cross-namespace Gateway references with optional listener targeting via sectionName
  • Custom labels and annotations for HTTPRoute resources

BackendTLSPolicy Support

  • Automatic TLS policy creation for secure backend connections when spec.solrTLS is enabled
  • Flexible CA configuration: CA certificate references (ConfigMap/Secret) or well-known CAs
  • Per-service policies for common and individual node services

API Changes

New Types (api/v1beta1/solrcloud_types.go):

  • SolrGatewayOptions, GatewayParentReference, SolrBackendTLSPolicy, GatewayCertificateReference

New Utility Functions (controllers/util/):

  • gateway_util.go: HTTPRoute generation and management
  • gateway_util_backendtls.go: BackendTLSPolicy generation and management

RBAC: Added permissions for httproutes and backendtlspolicies in gateway.networking.k8s.io API group

Documentation

  • docs/solr-cloud/gateway-api.md: Comprehensive usage guide with configuration examples, BackendTLSPolicy setup, and Gateway implementation support matrix (Envoy Gateway, kgateway, NGINX Gateway Fabric, etc.)
  • docs/solr-cloud/README.md: Added Gateway API reference

Dependency Updates

Gateway API v1.4.0+ is required to use the stable v1 API for BackendTLSPolicy (GA). This upgrade forced Go 1.24.0+ (required by Gateway API v1.4.0), which cascaded to Kubernetes libraries (v0.34.1) and controller-runtime (v0.22.1).

CRD Changes: Extensive changes in config/crd/bases/*.yaml include new Gateway API fields plus upstream schema updates from Kubernetes library upgrades (deprecation notices, field descriptions, etc.). These are auto-generated by controller-gen.

References:

Example Configuration

apiVersion: solr.apache.org/v1beta1
kind: SolrCloud
metadata:
  name: example
  namespace: solr-ns
spec:
  replicas: 3
  solrImage:
    tag: "9.7.0"
  solrTLS:
    pkcs12Secret:
      name: solr-tls-cert
      key: keystore.p12
  solrAddressability:
    external:
      method: Gateway
      domainName: solr.example.com
      useExternalAddress: true
      gateway:
        parentRefs:
        - name: my-gateway
          namespace: gateway-ns
          sectionName: https
        backendTLSPolicy:
          caCertificateRefs:
          - name: solr-ca-cert

Testing

E2E Tests (tests/e2e/solrcloud_gateway_test.go):

  • HTTPRoute and BackendTLSPolicy lifecycle management
  • CA certificate configuration switching
  • Resource cleanup and orphan handling

Manual Testing:

  • ✅ Tested with kgateway on Kubernetes 1.32
  • ✅ Verified with both NGINX Ingress and Gateway modes to ensure backward compatibility
  • ✅ Verified cross-namespace Gateway references
  • ✅ Confirmed TLS backend connections with BackendTLSPolicy

Compatibility

  • Gateway API: v1.4.0+ required (BackendTLSPolicy GA support)
  • Kubernetes: 1.23+ (Gateway API CRDs must be installed)
  • Backward compatible: Existing Ingress and other addressability methods unchanged
  • Breaking changes: None

Migration Path

  1. Install Gateway API CRDs (v1.4.0+)
  2. Deploy a Gateway resource
  3. Update SolrCloud spec to use method: Gateway
  4. Operator automatically creates HTTPRoute resources

chinmoysahu and others added 13 commits June 3, 2026 14:59
Implements Kubernetes Gateway API as a new external addressability method,
enabling HTTPRoute-based routing for SolrCloud services.

- Add Gateway API types and controller logic
- Generate HTTPRoutes for common and per-node services
- Add RBAC for HTTPRoute and BackendTLSPolicy
- Update CRDs, Helm charts, and documentation
- Add E2E tests following existing Ingress test patterns
- Add comprehensive cleanup logic for BackendTLSPolicy resources:
  * Delete common policy when hideCommon=true
  * Delete node policies when hideNodes=true
  * Delete all policies when BackendTLSPolicy config removed
  * Delete all policies when method changes from Gateway
- Remove focused test markers (FIt, FContext, FDescribe)
- Improve variable naming: hostname -> fqdn for clarity
- Enhance SolrBackendTLSPolicy documentation with validation constraints
Allows users to append extra alias hostnames to the common HTTPRoute
beyond the auto-generated ones from domainName/additionalDomainNames.
This is additive (not an override) to maintain consistency with
status.externalCommonAddress and BackendTLSPolicy references.
…BackendTLSPolicy validation, doc fixes

- Make Gateway API HTTPRoute watch conditional (--gateway-api flag) to avoid
  envtest failures when Gateway API CRDs are not installed
- Fix hideNodes cleanup: delete all node HTTPRoutes when hideNodes=true,
  not just orphaned ones from scale-down
- Add validation: BackendTLSPolicy requires spec.solrTLS to be configured
- Fix license header typo in gateway-api.md
- Fix BackendTLSPolicy version reference (v1alpha3 -> v1)
- Clarify headless service documentation
@HoustonPutman

Copy link
Copy Markdown
Contributor

Ok, I've merged main in, so we should be up-to-date. I'll do some real reviewing soon. Thanks for getting this setup!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants