This is unreleased documentation for SUSE® Storage 1.13 (Dev).

Create an HTTPRoute with Gateway API

If you install SUSE Storage on a Kubernetes cluster with kubectl or Helm, you can use Gateway API HTTPRoute as a modern alternative to Ingress for exposing the SUSE Storage UI to external traffic.

Gateway API is the successor to Ingress, offering more expressive routing capabilities and a standardized approach across different implementations.

Prerequisites

  1. Gateway API CRDs installed in your cluster:

    kubectl apply -f https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.2.0/standard-install.yaml
  2. A Gateway controller running in your cluster (for example, Istio, Envoy Gateway, Cilium, NGINX Gateway Fabric, Traefik, and others).

  3. At least one Gateway resource deployed and configured.

Helm values configuration

The following Helm values control HTTPRoute generation:

Key Type Default Description

httproute.enabled

bool

false

Enables HTTPRoute generation for the SUSE Storage UI.

httproute.parentRefs

list

[]

List of Gateway references specifying which Gateway(s) should handle this route.

httproute.hostnames

list

[]

List of hostnames bound to the HTTPRoute.

httproute.filters

list

[]

List of Gateway API filters to attach to the HTTPRoute rule for the SUSE Storage UI.

httproute.path

string

"/"

The routing path used to access the SUSE Storage UI.

httproute.pathType

string

"PathPrefix"

The path match type. Valid options are "Exact", "PathPrefix", or "RegularExpression".

httproute.annotations

object

{}

Key-value annotations to apply to the HTTPRoute resource.

Basic installation

Install SUSE Storage with HTTPRoute enabled:

helm install longhorn longhorn/longhorn \
  --namespace longhorn-system \
  --create-namespace \
  --set "httproute.enabled=true" \
  --set "httproute.parentRefs[0].name=my-gateway" \
  --set "httproute.parentRefs[0].namespace=default" \
  --set "httproute.hostnames[0]=longhorn.example.com"

Advanced configuration

For more complex setups, create a values file:

httproute:
  enabled: true
  parentRefs:
    - name: primary-gateway
      namespace: gateway-system
    - name: secondary-gateway
      namespace: gateway-system
      sectionName: https  # Target specific listener
  hostnames:
    - longhorn.example.com
    - longhorn.example.org
  path: /longhorn
  pathType: PathPrefix
  annotations:
    custom-annotation: "value"

Install with the values file:

helm install longhorn longhorn/longhorn \
  --namespace longhorn-system \
  --create-namespace \
  --values values.yaml

Secure access to the SUSE Storage UI with basic auth integration

To enable authenticated access to the SUSE Storage UI, reference an existing authentication proxy or middleware resource through the HTTPRoute filters field.

The following example assumes a Traefik Middleware resource providing basic authentication is already configured:

httproute:
  enabled: true
  parentRefs:
    - name: primary-gateway
      namespace: gateway-system
    - name: secondary-gateway
      namespace: gateway-system
      sectionName: https  # Target specific listener
  hostnames:
    - longhorn.example.com
    - longhorn.example.org
  filters:
    - type: ExtensionRef
      extensionRef:
        group: traefik.io
        kind: Middleware
        name: oauth-forwardauth
  path: /longhorn
  pathType: PathPrefix
  annotations:
    custom-annotation: "value"

filters is optional for a standard HTTPRoute. Any referenced resource must be configured separately and exist before the HTTPRoute is created.

Install SUSE Storage using the same values file:

helm install longhorn longhorn/longhorn \
  --namespace longhorn-system \
  --create-namespace \
  --values values.yaml

Verification

  1. Verify that the HTTPRoute was created:

    kubectl get httproute -n longhorn-system
  2. Check HTTPRoute details:

    kubectl describe httproute longhorn-httproute -n longhorn-system
  3. Verify that the route is accepted by the Gateway:

    kubectl get httproute longhorn-httproute -n longhorn-system -o jsonpath='{.status.parents[*].conditions}'

    The output should show Accepted: True and ResolvedRefs: True.

  4. Access the SUSE Storage UI through your Gateway external IP address or hostname.