Skip to content

Service redirection

Describes Hibernator chart 0.12.44

A hibernated service has no pods, so a caller gets a refused connection. Service redirection puts a small TCP proxy, the satellite, in place of the pods, and the caller lands on the Hibernator wake page. Every value named here is in the table in configuration.md, under config.serviceRedirection.

The satellite takes over the selector of the original pods, so Kubernetes keeps routing the service to it. The controller creates the satellite when the service hibernates and deletes it on wake.

A browser does not get the wake page on the address of the satellite. Caddy answers the page request with a 302 to config.externalUrl and carries the URL that the visitor asked for. The wake page loads once, and after the wake it sends the visitor back to that URL. troubleshooting.md has the rule and its exemptions.

Service redirection is opt-in twice. config.serviceRedirection.enabled is false by default. When it is true, only the services that you name get a satellite:

config:
serviceRedirection:
enabled: true
services:
- namespace: staging
name: my-app
port: https # service port name or number; the satellite listens on its targetPort
proto: https # optional; autodetected from the port when empty

You can also name a service with an annotation on the Service itself: hibernator.io/redirect-when-hibernating: "true". The annotation also needs config.serviceRedirection.enabled: true. annotations.md describes it and its two companions for the port and the protocol.

The satellite does not end TLS. For a service with proto: https, it sends the TLS connection of the caller to the HTTPS port of the Hibernator frontend. Autodetection selects https for the ports 443 and 8443.

The certificate that the caller gets depends on tls.enabled:

  • true: the frontend serves the certificate from the secret tls.secretName, for each hostname.
  • false, the default: the frontend serves a certificate for hibernator.internal from the internal CA of Caddy. Only a caller that does not verify the certificate accepts it, for example an ingress that sends to an HTTPS backend without verification.

A browser does not accept the certificate from the internal CA. If browsers connect to the service directly, set tls.enabled: true. Supply a certificate that is valid for each hostname of the service.