Commit Graph
6 Commits
Author SHA1 Message Date
Philip Laine f68a36a867 Cache peers and ensure updates are single flight 2026-06-11 14:56:19 +02:00
Hannu Teulahti cd03662096 Preserve connection-upgrade headers for kubectl streaming
The request rewriter applies a header allowlist and deletes everything
else, including Connection, Upgrade, and the Sec-Websocket-* headers.
net/http/httputil's ReverseProxy reads the upgrade type from the
rewritten outbound header, finds none, and forwards a plain request, so
the API server rejects it with "Upgrade request required". This breaks
kubectl exec/attach/port-forward/cp over both WebSocket and SPDY.

Allow the Sec-Websocket-* negotiation headers (not hop-by-hop, so the
proxy does not restore them) and reconstruct Connection/Upgrade from the
inbound request. Reconstructing rather than allowlisting the client's
Connection header keeps a client from naming proxy-set headers
(Authorization, Impersonate-*) as hop-by-hop to have them stripped.
2026-06-11 15:37:03 +03:00
Philip Laine b5e147bd72 Update license to AGPL 3 2026-06-11 13:29:04 +02:00
Philip Laine ce5986ccc2 Check peers before proxy and expand unit tests 2026-06-11 12:29:55 +02:00
Philip Laine 0caff618b7 Improve test coverage 2026-06-01 15:22:46 +02:00
Philip LaineandShyam 819166cb0b Add initial API server proxy
Co-authored-by: Shyam <shyam0904a@users.noreply.github.com>
2026-05-26 10:53:36 +02:00