Commit Graph
1 Commits
Author SHA1 Message Date
Hannu Teulahti cd03662096 Preserve connection-upgrade headers for kubectl streaming
The request rewriter applies a header allowlist and deletes everything
else, including Connection, Upgrade, and the Sec-Websocket-* headers.
net/http/httputil's ReverseProxy reads the upgrade type from the
rewritten outbound header, finds none, and forwards a plain request, so
the API server rejects it with "Upgrade request required". This breaks
kubectl exec/attach/port-forward/cp over both WebSocket and SPDY.

Allow the Sec-Websocket-* negotiation headers (not hop-by-hop, so the
proxy does not restore them) and reconstruct Connection/Upgrade from the
inbound request. Reconstructing rather than allowlisting the client's
Connection header keeps a client from naming proxy-set headers
(Authorization, Impersonate-*) as hop-by-hop to have them stripped.
2026-06-11 15:37:03 +03:00