Service redirection
Describes Hibernator chart 0.12.44
A hibernated service has no pods, so a caller gets a refused connection. Service
redirection puts a small TCP proxy, the satellite, in place of the pods, and the caller
lands on the Hibernator wake page. Every value named here is in the table in
configuration.md, under config.serviceRedirection.
How it works
Section titled “How it works”The satellite takes over the selector of the original pods, so Kubernetes keeps routing the service to it. The controller creates the satellite when the service hibernates and deletes it on wake.
A browser does not get the wake page on the address of the satellite. Caddy answers the
page request with a 302 to config.externalUrl and carries the URL that the visitor
asked for. The wake page loads once, and after the wake it sends the visitor back to that
URL. troubleshooting.md
has the rule and its exemptions.
Turn it on
Section titled “Turn it on”Service redirection is opt-in twice. config.serviceRedirection.enabled is false by
default. When it is true, only the services that you name get a satellite:
config: serviceRedirection: enabled: true services: - namespace: staging name: my-app port: https # service port name or number; the satellite listens on its targetPort proto: https # optional; autodetected from the port when emptyYou can also name a service with an annotation on the Service itself:
hibernator.io/redirect-when-hibernating: "true". The annotation also needs
config.serviceRedirection.enabled: true.
annotations.md describes it and
its two companions for the port and the protocol.
HTTPS services
Section titled “HTTPS services”The satellite does not end TLS. For a service with proto: https, it sends the TLS
connection of the caller to the HTTPS port of the Hibernator frontend. Autodetection
selects https for the ports 443 and 8443.
The certificate that the caller gets depends on tls.enabled:
true: the frontend serves the certificate from the secrettls.secretName, for each hostname.false, the default: the frontend serves a certificate forhibernator.internalfrom the internal CA of Caddy. Only a caller that does not verify the certificate accepts it, for example an ingress that sends to an HTTPS backend without verification.
A browser does not accept the certificate from the internal CA. If browsers connect to
the service directly, set tls.enabled: true. Supply a certificate that is valid for each
hostname of the service.