Repository navigation
radar-hub: accept an http localhost publicURL again (1.9.1-rc.1) - #56
Conversation
The web Service always has the plain-http port, so port-forward to it works. The notes forward http URLs to that port; http stays refused on 0.0.0.0 and [::].
PR Summary by QodoRestore HTTP localhost port-forward installs for radar-hub
AI Description
Diagram
High-Level Assessment
Files changed (5)
|
Code Review by Qodo
1. Invites forward HTTP to HTTPS
|
Chart 1.9.0 refuses
hub.publicURL=http://localhost:<port>when nothing fronts the hub:The premise is wrong. The web Service always has the plain-http port 80, and
kubectl port-forward svc/radar-hub-web 18080:80opens the hub. 1.8.0 installed this way, and radar-e2e does, so every radar-e2e job has failed athelm installsince 1.9.0.What changes:
0.0.0.0and[::], where port-forward listens on every interface and sign-in would travel in plain text.http://URL to the Service port namedhttp, and show the "accept the self-signed certificate" step only for https.web.tls.selfSignedrequirement in port-forward mode stays. Its message now gives the real reason: other clusters reach the hub only through the self-signed listener, and the hub addsinsecureSkipVerifyto their install commands only when it is on.Version: staged as 1.9.1-rc.1 on Hub 1.9.0. Hub 1.9.1 carries the matching fix to the port-forward command in invites and emails (it has the same https-only assumption), and its release promotes this chart to 1.9.1. Until then, the rc with an http URL prints correct install notes, but the hub's invites still say
:443.Tests:
tests/render-matrix.shpasses, with new cases for http on localhost / 127.0.0.1 / [::1], refusals for http on 0.0.0.0 and [::] and a non-http scheme, and the notes' http target.helm unittestpasses. radar-e2erun.shinstalls this chart withhttp://localhost:18080and its cluster connects.Note
Medium Risk
Changes install-time URL validation and port-forward instructions; allowing plain http is limited to loopback hosts but still affects how operators expose the hub locally.
Overview
Re-enables
http://loopbackhub.publicURLfor kubectl port-forward after 1.9.0 incorrectly required https and broke installs (e.g. radar-e2e).Validation in
secret.yamlno longer rejects all plain-http localhost URLs. Port-forward mode now requireshttporhttps; http is blocked only for0.0.0.0and[::]so sign-in is not exposed on every interface. Theweb.tls.selfSignedguard for loopback without Ingress/LB remains, with clearer messaging about agents and self-signed TLS.Install notes (
NOTES.txt) pick the web Service target from the URL scheme: https → tls port; http → named porthttp, and the self-signed certificate hint appears only for https.values.yamldocuments both localhost forms (https recommended). Chart version is 1.9.1-rc.1;render-matrix.shadds render/refuse and NOTES assertions for the new behavior.Reviewed by Cursor Bugbot for commit 4b1fced. Bugbot is set up for automated code reviews on this repo. Configure here.