Repository navigation
feat(proxy): plumb tls_domains (dynamic domain source) into deploy.yml + kamal proxy domains CLI - #17
Merged
Merged
Conversation
…l + kamal proxy domains CLI ## Summary Gem-side plumbing for zoolutions/dash-proxy#21. New proxy.tls_domains keys (source, interval, batch_size) emit --tls-domains-source, --tls-domains-interval=<n>s and --tls-domains-batch-size via Proxy#deploy_options; host-less ssl: true is allowed when a source is set (the proxy serves host-less TLS from the dynamic set). When load balancing, the flags are stripped from the per-app deploy alongside host/tls and re-added by the Loadbalancer config, so TLS + domain source land on the LB tier. New kamal proxy domains <refresh|list|stats> passthrough targets the LB container when load balancing, all proxy hosts otherwise. Tokens are documented as env vars (proxy.run.options.env), never deploy flags. No MINIMUM_VERSION bump - that waits for the proxy release shipping kamal-proxy#21 (proxy-before-gem ordering). ## Test Coverage - flag emission incl. s-suffixed interval, absence when unset, source-only - validator: source format (path/http(s) URL, required), interval positive integer, batch_size integer 1..25, empty-hash rejection, unknown keys - host-less ssl allowed with tls_domains.source - LB deploy command propagates the flags; per-app deploy strips them - domains CLI: proxy-hosts fan-out, LB dispatch, LB-on-proxy-host container name, stats whitelist pin, unknown subcommand message ## Verification - [x] bundle exec rubocop --parallel passes (182 files, no offenses) - [x] unit suite: 909 runs, only the two known Apple-Silicon builder failures (reproduced on pristine dash with these changes stashed) Refs #15
54 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Gem-side plumbing for zoolutions/dash-proxy#21 (dynamic domain source for automatic TLS):
proxy.tls_domainsindeploy.yml(source,interval,batch_size) emitted as--tls-domains-source,--tls-domains-interval=<n>s,--tls-domains-batch-sizeviaProxy#deploy_options(lib/kamal/configuration/proxy.rb)lib/kamal/configuration/validator/proxy.rb):sourcemust be a/-path or http(s) URL and is required whentls_domainsis set;intervalpositive integer;batch_size1..25. Host-lessssl: trueis now allowed whentls_domains.sourceis set (mirrors the loadbalancer bypass — the proxy serves host-less TLS from the dynamic set)host/tls(TLS terminates at the LB);Kamal::Configuration::Loadbalancer#deploy_optionsre-adds them, so the flags reach the LB tier (wm3 topology)kamal proxy domains <refresh|list|stats>passthrough (docker exec <container> kamal-proxy domains ...), targeting the LB host/container when load balancing, all proxy hosts otherwiselib/kamal/configuration/docs/proxy.yml): new keys documented (this also feeds the schema validator); poll/refresh tokens documented asKAMAL_PROXY_DOMAINS_TOKEN/KAMAL_PROXY_REFRESH_TOKENenv vars viaproxy.run.options.env— never deploy flagsNo
MINIMUM_VERSIONbump — per the issue, that waits for the proxy release that ships kamal-proxy#21.An adversarial multi-agent review of the diff (4 lenses, every finding verified by live reproduction/mutation testing) produced 6 confirmed findings; 5 fixed in this PR:
tls_domains: {}no longer silently disables the feature (validator guard was.present?, which skips empty hashes)interval/batch_sizeinteger checks hardened in the semantic validator (previously the type guarantee rested solely on the docs example staying an Integer; drift would have raised an uncaughtArgumentError)domainsunder LB-on-proxy-host (auto-activation default — container resolves tokamal-proxy), multi-host fan-out pin fordomains refresh,statswhitelist pin (mutation-tested green before)Accepted as consistent-by-design (not fixed): a role-level
tls_domainssnippet that only overridesintervalfails validation before the deep-merge with the global proxy config — identical to upstream's existingssl/host validate-before-merge behavior (a role snippet with onlyssl: truefails the same way). Workaround: restatesourceat the role level.Closes #15
Test plan
s-suffixed interval, absent when unset, source-only variant (test/configuration/proxy_test.rb)interval0/-300,batch_size0/26; accepts http/https URLs, batch_size 1/25; rejectstls_domainswithoutsourceand unknown keysssl: trueallowed withtls_domains.sourcetest/commands/loadbalancer_test.rb)domains refreshon proxy hosts,domains listagainst the LB container when load balancing, unknown subcommand message (test/cli/proxy_test.rb); command builders for both containersbundle exec rubocop --parallel— no offensesdashwith these changes stashed)