7 Commits
Author SHA1 Message Date
Philip Laine 080f00d090 Refactor proxy to use upgrade handler and add specific path handlers
This fixes issues with streaming requests and also makes sure that only specific paths are forwarded to the API server.
2026-06-15 13:24:45 +02:00
Philip Laine f68a36a867 Cache peers and ensure updates are single flight 2026-06-11 14:56:19 +02:00
Hannu Teulahti cd03662096 Preserve connection-upgrade headers for kubectl streaming
The request rewriter applies a header allowlist and deletes everything
else, including Connection, Upgrade, and the Sec-Websocket-* headers.
net/http/httputil's ReverseProxy reads the upgrade type from the
rewritten outbound header, finds none, and forwards a plain request, so
the API server rejects it with "Upgrade request required". This breaks
kubectl exec/attach/port-forward/cp over both WebSocket and SPDY.

Allow the Sec-Websocket-* negotiation headers (not hop-by-hop, so the
proxy does not restore them) and reconstruct Connection/Upgrade from the
inbound request. Reconstructing rather than allowlisting the client's
Connection header keeps a client from naming proxy-set headers
(Authorization, Impersonate-*) as hop-by-hop to have them stripped.
2026-06-11 15:37:03 +03:00
Philip Laine b5e147bd72 Update license to AGPL 3 2026-06-11 13:29:04 +02:00
Philip Laine ce5986ccc2 Check peers before proxy and expand unit tests 2026-06-11 12:29:55 +02:00
Philip Laine 0caff618b7 Improve test coverage 2026-06-01 15:22:46 +02:00
Philip LaineandShyam 819166cb0b Add initial API server proxy
Co-authored-by: Shyam <shyam0904a@users.noreply.github.com>
2026-05-26 10:53:36 +02:00