fix: update gRPC service configuration to use CmsServerBaseUrl resolver
Build and Deploy to Kubernetes / build-and-deploy (push) Failing after 2m34s

- Replace direct access to configuration for GwUrl with CmsServerBaseUrl.Resolve in AddGrpcServices and TokenNotificationService.
- Ensure proper error handling for missing GwUrl and add support for optional bypass of public TLS using CmsInternalBaseUrl.
- Adjust channel credentials based on whether the base URL is HTTPS or not.
This commit is contained in:
masoodafar-web
2026-05-13 22:05:04 +03:30
parent 231da2cbaa
commit ae5ab1492e
4 changed files with 88 additions and 4 deletions
+59
View File
@@ -0,0 +1,59 @@
---
# FrontOffice (Blazor Server) — staging. Server-side gRPC/SignalR to CMS: set CmsInternalBaseUrl to the
# in-cluster Service URL so TLS is not terminated on a broken public chain (PartialChain).
apiVersion: apps/v1
kind: Deployment
metadata:
name: frontoffice
namespace: default
labels:
app: frontoffice
environment: staging
spec:
replicas: 1
selector:
matchLabels:
app: frontoffice
template:
metadata:
labels:
app: frontoffice
spec:
containers:
- name: frontoffice
image: 194.5.195.53:30080/admin/frontoffice:latest
imagePullPolicy: Always
ports:
- containerPort: 80
name: http
env:
- name: ASPNETCORE_ENVIRONMENT
value: "Staging"
- name: CmsInternalBaseUrl
value: "http://cms-svc:8080"
resources:
requests:
memory: "256Mi"
cpu: "250m"
limits:
memory: "512Mi"
cpu: "500m"
imagePullSecrets:
- name: gitea-registry-secret
---
apiVersion: v1
kind: Service
metadata:
name: frontoffice-svc
namespace: default
labels:
app: frontoffice
spec:
selector:
app: frontoffice
ports:
- port: 80
targetPort: 80
name: http
type: ClusterIP
+10 -3
View File
@@ -100,7 +100,9 @@ public static class ConfigureServices
public static IServiceCollection AddGrpcServices(this IServiceCollection services, IConfiguration configuration) public static IServiceCollection AddGrpcServices(this IServiceCollection services, IConfiguration configuration)
{ {
var baseUrl = configuration["GwUrl"]; var baseUrl = CmsServerBaseUrl.Resolve(configuration)
?? throw new InvalidOperationException(
"GwUrl is required. Optionally set CmsInternalBaseUrl (e.g. http://cms-svc:8080 on Kubernetes) to bypass public TLS for server-side gRPC.");
// Register optimized HttpClient for gRPC // Register optimized HttpClient for gRPC
services.AddScoped(sp => services.AddScoped(sp =>
@@ -158,6 +160,7 @@ public static class ConfigureServices
var httpClient = sp.GetRequiredService<HttpClient>(); var httpClient = sp.GetRequiredService<HttpClient>();
var localStorage = sp.GetRequiredService<ILocalStorageService>(); var localStorage = sp.GetRequiredService<ILocalStorageService>();
var baseUrl = httpClient.BaseAddress?.ToString() ?? throw new InvalidOperationException("Base URL not configured"); var baseUrl = httpClient.BaseAddress?.ToString() ?? throw new InvalidOperationException("Base URL not configured");
var isHttps = baseUrl.StartsWith("https://", StringComparison.OrdinalIgnoreCase);
var credentials = CallCredentials.FromInterceptor(async (context, metadata) => var credentials = CallCredentials.FromInterceptor(async (context, metadata) =>
{ {
@@ -177,10 +180,14 @@ public static class ConfigureServices
} }
}); });
var channelCredentials = isHttps
? ChannelCredentials.Create(new SslCredentials(), credentials)
: ChannelCredentials.Create(ChannelCredentials.Insecure, credentials);
var channel = GrpcChannel.ForAddress(baseUrl, new GrpcChannelOptions var channel = GrpcChannel.ForAddress(baseUrl, new GrpcChannelOptions
{ {
UnsafeUseInsecureChannelCallCredentials = true, UnsafeUseInsecureChannelCallCredentials = !isHttps,
Credentials = ChannelCredentials.Create(new SslCredentials(), credentials), Credentials = channelCredentials,
HttpClient = httpClient, HttpClient = httpClient,
MaxReceiveMessageSize = 1000 * 1024 * 1024, // 1 GB MaxReceiveMessageSize = 1000 * 1024 * 1024, // 1 GB
MaxSendMessageSize = 1000 * 1024 * 1024 // 1 GB MaxSendMessageSize = 1000 * 1024 * 1024 // 1 GB
@@ -0,0 +1,18 @@
using Microsoft.Extensions.Configuration;
namespace FrontOffice.Main.Utilities;
/// <summary>
/// Server-side base URL for CMS (gRPC-Web, SignalR). Prefer in-cluster HTTP when FrontOffice runs on Kubernetes
/// next to CMS to avoid public ingress TLS chain issues (e.g. PartialChain).
/// </summary>
public static class CmsServerBaseUrl
{
public static string? Resolve(IConfiguration configuration)
{
var internalUrl = configuration["CmsInternalBaseUrl"];
if (!string.IsNullOrWhiteSpace(internalUrl))
return internalUrl.TrimEnd('/');
return configuration["GwUrl"]?.TrimEnd('/');
}
}
@@ -69,7 +69,7 @@ public class TokenNotificationService : IAsyncDisposable
return; return;
} }
var gwUrl = _configuration["GwUrl"]?.TrimEnd('/') ?? "https://localhost:5002"; var gwUrl = CmsServerBaseUrl.Resolve(_configuration) ?? "https://localhost:5002";
var hubPath = _configuration["SignalR:HubPath"] ?? "/hubs/token-relay"; var hubPath = _configuration["SignalR:HubPath"] ?? "/hubs/token-relay";
var hubUrl = $"{gwUrl}{hubPath}"; var hubUrl = $"{gwUrl}{hubPath}";