fix: update gRPC service configuration to use CmsServerBaseUrl resolver
Build and Deploy to Kubernetes / build-and-deploy (push) Failing after 2m34s
Build and Deploy to Kubernetes / build-and-deploy (push) Failing after 2m34s
- Replace direct access to configuration for GwUrl with CmsServerBaseUrl.Resolve in AddGrpcServices and TokenNotificationService. - Ensure proper error handling for missing GwUrl and add support for optional bypass of public TLS using CmsInternalBaseUrl. - Adjust channel credentials based on whether the base URL is HTTPS or not.
This commit is contained in:
@@ -0,0 +1,59 @@
|
||||
---
|
||||
# FrontOffice (Blazor Server) — staging. Server-side gRPC/SignalR to CMS: set CmsInternalBaseUrl to the
|
||||
# in-cluster Service URL so TLS is not terminated on a broken public chain (PartialChain).
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: frontoffice
|
||||
namespace: default
|
||||
labels:
|
||||
app: frontoffice
|
||||
environment: staging
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: frontoffice
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: frontoffice
|
||||
spec:
|
||||
containers:
|
||||
- name: frontoffice
|
||||
image: 194.5.195.53:30080/admin/frontoffice:latest
|
||||
imagePullPolicy: Always
|
||||
ports:
|
||||
- containerPort: 80
|
||||
name: http
|
||||
env:
|
||||
- name: ASPNETCORE_ENVIRONMENT
|
||||
value: "Staging"
|
||||
- name: CmsInternalBaseUrl
|
||||
value: "http://cms-svc:8080"
|
||||
resources:
|
||||
requests:
|
||||
memory: "256Mi"
|
||||
cpu: "250m"
|
||||
limits:
|
||||
memory: "512Mi"
|
||||
cpu: "500m"
|
||||
imagePullSecrets:
|
||||
- name: gitea-registry-secret
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: frontoffice-svc
|
||||
namespace: default
|
||||
labels:
|
||||
app: frontoffice
|
||||
spec:
|
||||
selector:
|
||||
app: frontoffice
|
||||
ports:
|
||||
- port: 80
|
||||
targetPort: 80
|
||||
name: http
|
||||
type: ClusterIP
|
||||
@@ -100,7 +100,9 @@ public static class ConfigureServices
|
||||
|
||||
public static IServiceCollection AddGrpcServices(this IServiceCollection services, IConfiguration configuration)
|
||||
{
|
||||
var baseUrl = configuration["GwUrl"];
|
||||
var baseUrl = CmsServerBaseUrl.Resolve(configuration)
|
||||
?? throw new InvalidOperationException(
|
||||
"GwUrl is required. Optionally set CmsInternalBaseUrl (e.g. http://cms-svc:8080 on Kubernetes) to bypass public TLS for server-side gRPC.");
|
||||
|
||||
// Register optimized HttpClient for gRPC
|
||||
services.AddScoped(sp =>
|
||||
@@ -158,6 +160,7 @@ public static class ConfigureServices
|
||||
var httpClient = sp.GetRequiredService<HttpClient>();
|
||||
var localStorage = sp.GetRequiredService<ILocalStorageService>();
|
||||
var baseUrl = httpClient.BaseAddress?.ToString() ?? throw new InvalidOperationException("Base URL not configured");
|
||||
var isHttps = baseUrl.StartsWith("https://", StringComparison.OrdinalIgnoreCase);
|
||||
|
||||
var credentials = CallCredentials.FromInterceptor(async (context, metadata) =>
|
||||
{
|
||||
@@ -177,10 +180,14 @@ public static class ConfigureServices
|
||||
}
|
||||
});
|
||||
|
||||
var channelCredentials = isHttps
|
||||
? ChannelCredentials.Create(new SslCredentials(), credentials)
|
||||
: ChannelCredentials.Create(ChannelCredentials.Insecure, credentials);
|
||||
|
||||
var channel = GrpcChannel.ForAddress(baseUrl, new GrpcChannelOptions
|
||||
{
|
||||
UnsafeUseInsecureChannelCallCredentials = true,
|
||||
Credentials = ChannelCredentials.Create(new SslCredentials(), credentials),
|
||||
UnsafeUseInsecureChannelCallCredentials = !isHttps,
|
||||
Credentials = channelCredentials,
|
||||
HttpClient = httpClient,
|
||||
MaxReceiveMessageSize = 1000 * 1024 * 1024, // 1 GB
|
||||
MaxSendMessageSize = 1000 * 1024 * 1024 // 1 GB
|
||||
|
||||
@@ -0,0 +1,18 @@
|
||||
using Microsoft.Extensions.Configuration;
|
||||
|
||||
namespace FrontOffice.Main.Utilities;
|
||||
|
||||
/// <summary>
|
||||
/// Server-side base URL for CMS (gRPC-Web, SignalR). Prefer in-cluster HTTP when FrontOffice runs on Kubernetes
|
||||
/// next to CMS to avoid public ingress TLS chain issues (e.g. PartialChain).
|
||||
/// </summary>
|
||||
public static class CmsServerBaseUrl
|
||||
{
|
||||
public static string? Resolve(IConfiguration configuration)
|
||||
{
|
||||
var internalUrl = configuration["CmsInternalBaseUrl"];
|
||||
if (!string.IsNullOrWhiteSpace(internalUrl))
|
||||
return internalUrl.TrimEnd('/');
|
||||
return configuration["GwUrl"]?.TrimEnd('/');
|
||||
}
|
||||
}
|
||||
@@ -69,7 +69,7 @@ public class TokenNotificationService : IAsyncDisposable
|
||||
return;
|
||||
}
|
||||
|
||||
var gwUrl = _configuration["GwUrl"]?.TrimEnd('/') ?? "https://localhost:5002";
|
||||
var gwUrl = CmsServerBaseUrl.Resolve(_configuration) ?? "https://localhost:5002";
|
||||
var hubPath = _configuration["SignalR:HubPath"] ?? "/hubs/token-relay";
|
||||
var hubUrl = $"{gwUrl}{hubPath}";
|
||||
|
||||
|
||||
Reference in New Issue
Block a user