Skip to content

feat(helm): support agentgateway ingress #2469

Description

@danehans

User Story

As a Kubernetes operator using agentgateway, I want OpenShell to create a dedicated Gateway so that I can use agentgateway without deploying Envoy Gateway or maintaining separate ingress manifests.

Problem Statement

OpenShell documents and tests Envoy Gateway as its Kubernetes Gateway API implementation. Agentgateway is not covered by the chart or Kubernetes E2E suite, and its generated proxy Service conflicts with OpenShell's Service when both use the chart's default name.

Impact / Why This Matters

Agentgateway operators must maintain custom Gateway and GRPCRoute manifests and cannot rely on OpenShell's CI coverage. The naming conflict also makes a straightforward GatewayClass override fail.

Proposed Design

Keep the chart controller-neutral while supporting the existing chart-owned Gateway model with agentgateway.

  • Let the OpenShell release create a dedicated agentgateway Gateway and GRPCRoute.
  • Require a Gateway name distinct from the OpenShell Service, such as openshell-ingress.
  • Preserve the existing Envoy Gateway defaults and behavior.
  • Generalize Kubernetes E2E gateway selection so the same harness can test Envoy or agentgateway.
  • Cover plaintext, HA, frontend TLS termination, and backend TLS re-encryption.
  • Document TLS termination, OIDC identity, BackendTLSPolicy behavior, and the naming constraint.
  • Keep agentgateway controllers and CRDs outside the OpenShell chart.
  • Defer shared, platform-managed Gateway attachment and ListenerSet support to feat(helm): support shared agentgateway Gateway #3715.

Acceptance Criteria

  • The chart can create a dedicated agentgateway Gateway with a non-conflicting name.
  • The chart rejects an agentgateway Gateway name that conflicts with the OpenShell Service.
  • Existing Envoy Gateway values and behavior remain compatible.
  • Helm tests cover dedicated HTTP and HTTPS listeners, certificate validation, and the naming constraint.
  • Kubernetes E2E covers plaintext, HA, frontend TLS, and backend TLS re-encryption with agentgateway.
  • Documentation covers installation, TLS and OIDC boundaries, BackendTLSPolicy, and troubleshooting.
  • The OpenShell chart does not install or own agentgateway cluster infrastructure.

Alternatives Considered

  • Documentation-only class override: rejected because it does not prevent the Service name collision or provide runtime coverage.
  • Bundling agentgateway with the OpenShell chart: rejected because cluster-scoped CRDs and controller lifecycle should remain platform-owned.
  • A shared, platform-managed Gateway: deferred to feat(helm): support shared agentgateway Gateway #3715 to keep the initial integration aligned with the existing Envoy topology.
  • TLS/TCP passthrough: deferred because it loses gRPC-aware routing and expands the chart surface.

Agent Investigation

Revalidated against OpenShell main at 924486805, agentgateway v1.5.0, and Gateway API v1.6.2.

  • The existing Gateway and GRPCRoute templates are portable to agentgateway.
  • Agentgateway names its proxy Service after the Gateway, requiring a name distinct from the OpenShell Service.
  • PR feat(helm): add BackendTLSPolicy support #2728 added standard BackendTLSPolicy support, which this integration reuses and validates.
  • PR feat(helm): add agentgateway ingress support #3714 generalizes Kubernetes E2E gateway selection for Envoy and agentgateway.
  • Branch conformance validates dedicated frontend TLS and backend TLS re-encryption.

Checklist

  • I have reviewed existing issues and the architecture docs
  • This is a design proposal, not a please-build-this request

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:clusterRelated to running OpenShell on k3s/dockertest:e2e-kubernetesRequires Kubernetes end-to-end coveragetopic:compatibilityCompatibility-related work

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions