API Gateway Chart Values Reference

This reference lists the API Gateway values the Axual Governance Helm chart exposes: the image and pull secrets, the server TLS bundle, the application configuration sections, and the ingress and OpenShift Route options.

Type

Reference

Goal

Look up an API Gateway chart value while writing the Axual Governance values file.

Audience

Platform Operator deploying the API Gateway that fronts Axual Governance.

When to use

While configuring the API Gateway, alongside the procedure that installs Axual Governance.

Contents

The sections below cover each area in this reference:

About API Gateway

API Gateway is a reverse proxy built with Spring Cloud Gateway. It routes each request to a backend microservice based on the request path.

API Gateway Configuration

The API Gateway needs the three mandatory sections described under Application Configuration, plus the image, TLS and exposure values below. Replace every <VALUE> placeholder with your own value before installing.

For the full list of configuration options, see the Configuration section of the API Gateway page.

API Gateway Repository Configuration

You can override registry, tag, and pullPolicy for the API Gateway pod. By default these values come from the Axual Governance chart. You can also override imagePullSecrets; if you leave it unset, the API Gateway pod uses global.imagePullSecrets.

values.yaml
api-gateway:

  image:
    registry: "registry.axual.io"
    pullPolicy: "Always"
    tag: "0.4.1"

  imagePullSecrets:
    - name: axualdockercred

Server Security Configuration

To secure incoming connections with SSL, point the API Gateway at existing Kubernetes Secrets that hold the Privacy Enhanced Mail (PEM) certificates.

values.yaml
api-gateway:

  env:
    - name: SPRING_SSL_BUNDLE_PEM_API-GATEWAY_KEYSTORE_CERTIFICATE
      valueFrom:
        secretKeyRef:
          # key identifying the server-certificate within the k8s-secret
          key: <server-certificate-name>
          name: <k8s-secret-name>
    - name: SPRING_SSL_BUNDLE_PEM_API-GATEWAY_KEYSTORE_PRIVATE_KEY
      valueFrom:
        secretKeyRef:
          # key identifying the server-key within the k8s-secret
          key: <server-key-name>
          name: <k8s-secret-name>

  config:
    server:
      ssl:
        enabled: true
        # name referring to the bundle-pem
        bundle: "api-gateway"

Application Configuration

API Gateway is a Spring application, so it reads its settings from an application.yml file. Whatever you put under config is injected into a ConfigMap and mounted as that file. The first three subsections below are mandatory on every installation; the fourth applies once the Metrics Exposer backend is enabled.

Gateway Endpoints

These values say where each backend microservice is reachable. Disable the optional backends your installation does not run.

Use the service name of each component as your installation names it.
values.yaml
api-gateway:

  config:
    gateway:
      endpoints:
        # Mandatory Backend service
        platformManager:
          enabled: true
          url: "http://<platform-manager-service-name>"
        # Optional Backend service
        organizationManager:
          enabled: true
          url: "http://<organization-manager-service-name>"
        # Optional Backend service
        topicBrowse:
          enabled: true
          url: "http://<topic-browse-service-name>"
        # Optional Backend service
        metricsExposer:
          enabled: false
          url: "http://<metrics-exposer-service-name>"
        # Optional Backend service
        metricsExposerApiDocs:
          enabled: false
          url: "http://<metrics-exposer-service-name>"
        # Mandatory Frontend service
        platformUi:
          enabled: true
          url: "http://<platform-ui-service-name>"
        # Mandatory Backend service
        keycloak:
          enabled: true
          url: "http://<keycloak-http-service-name>"

Local and SSO Authentication Configurations

These values define the two sets of security restrictions the API Gateway applies, depending on the endpoint being called:

  • Local authentication covers users who signed up with an email address and authenticate against the local realm to reach the Platform Manager endpoints.

  • Single Sign-On (SSO) authentication covers users who authenticate with their organisation identity, such as Active Directory or Lightweight Directory Access Protocol (LDAP).

values.yaml
api-gateway:

  config:
    # This defines the Local Realm for user registration
    local:
      auth:
        # Endpoint of the Local Authentication Server Issuer URI (e.g. https://idp.example.com ).
        # This endpoint is never called. It is used to compare the iss claim of the JWT token.
        issuerUrlForValidation: https://platform.<domain>/auth/realms/local
        # Endpoint of the Local Authentication Server JWK Set URI (e.g. https://idp.example.com/.well-known/jwks.json ).
        # Used for signing up new tenants.
        jwkSetUri: http://keycloak-http/auth/realms/local/protocol/openid-connect/certs

    # Keycloak Authentication Server
    sso:
      keycloak:
        # URL of Keycloak to be accessed outside the cluster
        advertisedBaseUrl: https://platform.<domain>
        # URL of Keycloak to be accessed within the cluster
        internalBaseUrl: http://keycloak-http
        # Allow accessing Keycloak without TLS chain validation
        useInsecureTrustManager: false

Permission and Topic Browse Config APIs

These values say where the permission API and the browse-config resource are reachable. Both paths are fixed, so only the Platform Manager service name changes.

Adjust only the service name of the Platform Manager, as your installation names it.
values.yaml
api-gateway:

  config:
    # Service Name of Platform Manager
    # the path `/api/auth` is fixed
    permissions-api:
      url: "http://<platform-manager-service-name>/api/auth"
    # Service Name of Platform Manager
    # the path `/api/stream_configs/{id}/browse-config` is fixed
    topic-browse-config-api:
      url: "http://<platform-manager-service-name>/api/stream_configs/{id}/browse-config"

Metrics Exposer Configuration

These values are mandatory once the Metrics Exposer backend is enabled in the API Gateway. The API Gateway intercepts every request to Metrics Exposer (/api/metrics/**) and calls this Platform Manager API to enrich the request before forwarding it.

Adjust only the service name of the Platform Manager, as your installation names it.
values.yaml
api-gateway:
  config:
    # Service Name of Platform Manager
    # the path `/api/monitoring_information` is fixed
    metrics-exposer-config-api:
      url: "http://<platform-manager-service-name>/api/monitoring_information"

Credentials Secret: secrets and existingSecretName

API Gateway reads a second configuration file, secrets.yml, from a Kubernetes Secret. It takes the same structure as config, is loaded after it, and overrides any key the two share. existingSecretName names an existing Secret holding a secrets.yml key. When it is "", the chart creates the Secret from secrets. For the procedure, see How to Store Component Credentials in a Kubernetes Secret.

API Gateway reads no Axual credential from config, and its TLS certificates come from PEM Secrets, as shown in Server Security Configuration. The one credential key that belongs in secrets.yml, when you set it, is:

  • management.opentelemetry.tracing.export.otlp.headers.<NAME>, for example an authorization header for the OpenTelemetry collector

Ingress Configuration

The API Gateway Helm chart can create an Ingress that exposes it outside the Kubernetes cluster. Self-Service only works for users once the API Gateway is reachable from outside, so this is normally enabled.

values.yaml
api-gateway:

  ingress:
    # -- Enable creation of the Ingress resource to expose this service.
    enabled: true
    # -- The name of the IngressClass cluster resource.
    # The associated IngressClass defines which controller will implement the resource.
    className: ""
    # -- Annotations to add to the Ingress resource.
    annotations: {}
    hosts:
      - # -- The fully qualified domain name of a network host.
        host: "<hostDomainName>"
        paths:
          - # -- Matched against the path of an incoming request.
            path: "/"
            # -- Determines the interpretation of the Path matching.
            # Can be one of the following values: `Exact`, `Prefix`, `ImplementationSpecific`.
            pathType: "ImplementationSpecific"
    # -- TLS configuration for this Ingress.
    tls: []
    #  - secretName: chart-example-tls
    #    hosts:
    #      - <hostDomainName>

Route Configuration

On OpenShift, the API Gateway Helm chart can create a Route instead of an Ingress. The same reasoning applies: Self-Service only works for users once the API Gateway is reachable from outside the cluster.

values.yaml
api-gateway:

  route:
    # -- Enable creation of an OpenShift Route resource to expose this service.
    enabled: true
    # -- Annotations to add to the Route.
    annotations: {}
    # -- Labels to add to the route.
    labels: {}
    # -- An alias/DNS that points to the service. Optional. If not specified a route name will typically be automatically chosen.
    host: ""
    # -- subdomain is a DNS subdomain that is requested within the ingress controller's domain (as a subdomain). If host is set this field is ignored.
    subdomain: ""
    # -- Path that the router watches for, to route traffic for to the service.
    path: "/"
    tls:
      # -- The Certificate Authority certificate contents.
      caCertificate: ""
      # -- Certificate contents. This should be a single serving certificate, not a certificate chain. Do not include a CA certificate.
      certificate: ""
      # -- Key file contents.
      key: ""
      # -- Indicates termination type. One of: `edge`, `passthrough`, or `reencrypt`.
      termination: "passthrough"
      # --The CA certificate of the final destination. When using reencrypt termination this file should be provided
      # in order to have routers use it for health checks on the secure connection.
      destinationCACertificate: ""