Relay pods for external TCP targets #12
Labels
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
carvers/silta#12
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
Some backends live outside the cluster but inside its VNet - e.g. the Azure Flexible Server netzlive-1p-netzlive-1.postgres.database.azure.com (no public access, private DNS in the cluster VNet). silta can only target svc/ and pod/, so these are unreachable: port-forward needs a pod that listens, and none does. Today people bounce through an ephemeral socat pod (the n-script's remote-postgres), which leaks the pod on any exit that is not a clean return or SIGINT.
Feature
A third target type that names the external endpoint directly:
On the first connection to such a forward, silta ensures a relay pod exists in the namespace and then forwards to it like a pod/ target. The relay is an alpine/socat listener that connects to the external host:port.
Lifecycle
Naming
Example: silta-aav-3f9c2e, or pg-netzlive-aav-3f9c2e with pod_name = "pg-netzlive".
Labels on the pod: silta/target=host:port for listing and sweeping.
Notes