Skip to content

[codex] Allow api-rs to reach iron-proxy management#649

Open
Zygimantass wants to merge 2 commits into
mainfrom
codex/allow-iron-proxy-management-egress
Open

[codex] Allow api-rs to reach iron-proxy management#649
Zygimantass wants to merge 2 commits into
mainfrom
codex/allow-iron-proxy-management-egress

Conversation

@Zygimantass

Copy link
Copy Markdown
Member

Summary

  • Allow api-rs egress to the per-sandbox iron-proxy management port from the Helm NetworkPolicy.
  • Keep the port value wired through ironProxy.service.managementPort instead of hardcoding 9092.

Root Cause

The per-sandbox proxy NetworkPolicy admits api-rs ingress on the management port, and the proxy exposes /v1/status and /v1/sync, but the api-rs NetworkPolicy only allowed egress to proxy pods on the HTTP proxy and Postgres ports. With default-deny egress enabled, api-rs management calls timed out and fell back to the fixed reassign delay.

Validation

  • helm lint contrib/chart
  • helm template centaur contrib/chart -f /Users/magelinskaas/tempoxyz/prd-centaur-infra/clusters/centaur-na/argocd/values/centaur.yaml rendered centaur-api-rs iron-proxy egress ports as 8080,9092,5432.

@Zygimantass Zygimantass marked this pull request as ready for review June 17, 2026 21:59
@Zygimantass Zygimantass enabled auto-merge (squash) June 17, 2026 21:59
@Zygimantass Zygimantass disabled auto-merge June 17, 2026 22:01
@Zygimantass Zygimantass enabled auto-merge (squash) June 17, 2026 22:01
@Zygimantass Zygimantass disabled auto-merge June 17, 2026 22:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant