fix: update gRPC service configuration to use CmsServerBaseUrl resolver
Build and Deploy to Kubernetes / build-and-deploy (push) Failing after 2m34s
Build and Deploy to Kubernetes / build-and-deploy (push) Failing after 2m34s
- Replace direct access to configuration for GwUrl with CmsServerBaseUrl.Resolve in AddGrpcServices and TokenNotificationService. - Ensure proper error handling for missing GwUrl and add support for optional bypass of public TLS using CmsInternalBaseUrl. - Adjust channel credentials based on whether the base URL is HTTPS or not.
This commit is contained in:
@@ -0,0 +1,59 @@
|
|||||||
|
---
|
||||||
|
# FrontOffice (Blazor Server) — staging. Server-side gRPC/SignalR to CMS: set CmsInternalBaseUrl to the
|
||||||
|
# in-cluster Service URL so TLS is not terminated on a broken public chain (PartialChain).
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: frontoffice
|
||||||
|
namespace: default
|
||||||
|
labels:
|
||||||
|
app: frontoffice
|
||||||
|
environment: staging
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: frontoffice
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: frontoffice
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: frontoffice
|
||||||
|
image: 194.5.195.53:30080/admin/frontoffice:latest
|
||||||
|
imagePullPolicy: Always
|
||||||
|
ports:
|
||||||
|
- containerPort: 80
|
||||||
|
name: http
|
||||||
|
env:
|
||||||
|
- name: ASPNETCORE_ENVIRONMENT
|
||||||
|
value: "Staging"
|
||||||
|
- name: CmsInternalBaseUrl
|
||||||
|
value: "http://cms-svc:8080"
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: "256Mi"
|
||||||
|
cpu: "250m"
|
||||||
|
limits:
|
||||||
|
memory: "512Mi"
|
||||||
|
cpu: "500m"
|
||||||
|
imagePullSecrets:
|
||||||
|
- name: gitea-registry-secret
|
||||||
|
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: frontoffice-svc
|
||||||
|
namespace: default
|
||||||
|
labels:
|
||||||
|
app: frontoffice
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: frontoffice
|
||||||
|
ports:
|
||||||
|
- port: 80
|
||||||
|
targetPort: 80
|
||||||
|
name: http
|
||||||
|
type: ClusterIP
|
||||||
@@ -100,7 +100,9 @@ public static class ConfigureServices
|
|||||||
|
|
||||||
public static IServiceCollection AddGrpcServices(this IServiceCollection services, IConfiguration configuration)
|
public static IServiceCollection AddGrpcServices(this IServiceCollection services, IConfiguration configuration)
|
||||||
{
|
{
|
||||||
var baseUrl = configuration["GwUrl"];
|
var baseUrl = CmsServerBaseUrl.Resolve(configuration)
|
||||||
|
?? throw new InvalidOperationException(
|
||||||
|
"GwUrl is required. Optionally set CmsInternalBaseUrl (e.g. http://cms-svc:8080 on Kubernetes) to bypass public TLS for server-side gRPC.");
|
||||||
|
|
||||||
// Register optimized HttpClient for gRPC
|
// Register optimized HttpClient for gRPC
|
||||||
services.AddScoped(sp =>
|
services.AddScoped(sp =>
|
||||||
@@ -158,6 +160,7 @@ public static class ConfigureServices
|
|||||||
var httpClient = sp.GetRequiredService<HttpClient>();
|
var httpClient = sp.GetRequiredService<HttpClient>();
|
||||||
var localStorage = sp.GetRequiredService<ILocalStorageService>();
|
var localStorage = sp.GetRequiredService<ILocalStorageService>();
|
||||||
var baseUrl = httpClient.BaseAddress?.ToString() ?? throw new InvalidOperationException("Base URL not configured");
|
var baseUrl = httpClient.BaseAddress?.ToString() ?? throw new InvalidOperationException("Base URL not configured");
|
||||||
|
var isHttps = baseUrl.StartsWith("https://", StringComparison.OrdinalIgnoreCase);
|
||||||
|
|
||||||
var credentials = CallCredentials.FromInterceptor(async (context, metadata) =>
|
var credentials = CallCredentials.FromInterceptor(async (context, metadata) =>
|
||||||
{
|
{
|
||||||
@@ -177,10 +180,14 @@ public static class ConfigureServices
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
var channelCredentials = isHttps
|
||||||
|
? ChannelCredentials.Create(new SslCredentials(), credentials)
|
||||||
|
: ChannelCredentials.Create(ChannelCredentials.Insecure, credentials);
|
||||||
|
|
||||||
var channel = GrpcChannel.ForAddress(baseUrl, new GrpcChannelOptions
|
var channel = GrpcChannel.ForAddress(baseUrl, new GrpcChannelOptions
|
||||||
{
|
{
|
||||||
UnsafeUseInsecureChannelCallCredentials = true,
|
UnsafeUseInsecureChannelCallCredentials = !isHttps,
|
||||||
Credentials = ChannelCredentials.Create(new SslCredentials(), credentials),
|
Credentials = channelCredentials,
|
||||||
HttpClient = httpClient,
|
HttpClient = httpClient,
|
||||||
MaxReceiveMessageSize = 1000 * 1024 * 1024, // 1 GB
|
MaxReceiveMessageSize = 1000 * 1024 * 1024, // 1 GB
|
||||||
MaxSendMessageSize = 1000 * 1024 * 1024 // 1 GB
|
MaxSendMessageSize = 1000 * 1024 * 1024 // 1 GB
|
||||||
|
|||||||
@@ -0,0 +1,18 @@
|
|||||||
|
using Microsoft.Extensions.Configuration;
|
||||||
|
|
||||||
|
namespace FrontOffice.Main.Utilities;
|
||||||
|
|
||||||
|
/// <summary>
|
||||||
|
/// Server-side base URL for CMS (gRPC-Web, SignalR). Prefer in-cluster HTTP when FrontOffice runs on Kubernetes
|
||||||
|
/// next to CMS to avoid public ingress TLS chain issues (e.g. PartialChain).
|
||||||
|
/// </summary>
|
||||||
|
public static class CmsServerBaseUrl
|
||||||
|
{
|
||||||
|
public static string? Resolve(IConfiguration configuration)
|
||||||
|
{
|
||||||
|
var internalUrl = configuration["CmsInternalBaseUrl"];
|
||||||
|
if (!string.IsNullOrWhiteSpace(internalUrl))
|
||||||
|
return internalUrl.TrimEnd('/');
|
||||||
|
return configuration["GwUrl"]?.TrimEnd('/');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -69,7 +69,7 @@ public class TokenNotificationService : IAsyncDisposable
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
var gwUrl = _configuration["GwUrl"]?.TrimEnd('/') ?? "https://localhost:5002";
|
var gwUrl = CmsServerBaseUrl.Resolve(_configuration) ?? "https://localhost:5002";
|
||||||
var hubPath = _configuration["SignalR:HubPath"] ?? "/hubs/token-relay";
|
var hubPath = _configuration["SignalR:HubPath"] ?? "/hubs/token-relay";
|
||||||
var hubUrl = $"{gwUrl}{hubPath}";
|
var hubUrl = $"{gwUrl}{hubPath}";
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user