Skip to content

feat(helm): make gatewayClassName configurable in control and observability planes - #3915

Merged
NomadXD merged 2 commits into
openchoreo:mainfrom
kavix:feat/configurable-gateway-class
Jun 22, 2026
Merged

NomadXD merged 2 commits into
openchoreo:mainfrom
kavix:feat/configurable-gateway-class

Conversation

@kavix

@kavix kavix commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Purpose

Currently, only the openchoreo-data-plane Helm chart exposes a templated gatewayClassName, allowing users to swap the default kgateway implementation. The openchoreo-control-plane and openchoreo-observability-plane charts had hardcoded gatewayClassName: kgateway.
This PR makes gateways modular across the whole platform by supporting a templated gatewayClassName in the control plane and observability plane, enabling users to run OpenChoreo on top of a service mesh like Istio or with a CNI like Cilium.

Approach

  • Updated templates/gateway/gateway.yaml in both openchoreo-control-plane and openchoreo-observability-plane to template the gatewayClassName field with a fallback to "kgateway".
  • Added gatewayClassName property to values.yaml and values.schema.json for both planes.

Related Issues

Fixes #3700

Checklist

  • Tests added or updated (unit, integration, etc.) (N/A - Helm chart changes)
  • Samples updated (if applicable)
  • Added backport/<release-branch> label if this should be backported (e.g., backport/release-v1.0)

Remarks

N/A

@kavix
kavix force-pushed the feat/configurable-gateway-class branch from 7c29af3 to 02651f7 Compare June 18, 2026 20:24
@coderabbitai

coderabbitai Bot commented Jun 18, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: f49aff00-f15d-4103-a2b4-7f8ab5c7c7c8

📥 Commits

Reviewing files that changed from the base of the PR and between 379c829 and 02651f7.

📒 Files selected for processing (6)
  • install/helm/openchoreo-control-plane/templates/gateway/gateway.yaml
  • install/helm/openchoreo-control-plane/values.schema.json
  • install/helm/openchoreo-control-plane/values.yaml
  • install/helm/openchoreo-observability-plane/templates/gateway/gateway.yaml
  • install/helm/openchoreo-observability-plane/values.schema.json
  • install/helm/openchoreo-observability-plane/values.yaml

📝 Walkthrough

File Changes by Folder

  • install/helm/: 6 files (100% of changes)
    • Control plane: 3 files (gateway.yaml, values.yaml, values.schema.json)
    • Observability plane: 3 files (gateway.yaml, values.yaml, values.schema.json)
    • Data plane: Reference implementation (no changes)
    • Workflow plane: No gateway templates (out of scope)

Total scope: 6 files changed, ~27 lines added/6 lines modified

API/CRD Surface Changes

None. This PR is purely a Helm values/template configuration change with zero impact to Kubernetes CRD or API surface. The Gateway resource itself (v1 from gateway.networking.k8s.io) is unchanged; only the templated field value source is externalized. Compatibility risk: Low — fully backward compatible as all changes default to "kgateway", preserving existing deployments.

Tests

No tests added. The PR modifies Helm templates and values files but introduces no unit tests, integration tests, or Helm test suites. Critical paths lacking test coverage:

  • Helm deployment with custom gatewayClassName values (e.g., istio, cilium)
  • Validation that non-existent GatewayClass names fail gracefully
  • Multi-plane consistency when using different gateway implementations

Risk Hotspots

Minimal risk profile:

  • ✅ No RBAC/AuthZ changes: No role, rolebinding, or permission modifications
  • ✅ No secret/credentials handling: Configuration is plaintext string value
  • ✅ No reconciliation logic: No controller-side changes; Helm-only configuration
  • ✅ No upgrade path risks: Default fallback to kgateway ensures safe upgrades from older releases
  • ⚠️ Validation gap: No schema validation prevents invalid GatewayClass names; misconfiguration silently propagates to Gateway CR (caught only at cluster reconciliation)

Walkthrough

Both the openchoreo-control-plane and openchoreo-observability-plane Helm charts replace the hardcoded gatewayClassName: kgateway in their Gateway CR templates with a configurable .Values.gateway.gatewayClassName (defaulting to "kgateway"). Each chart gains a corresponding values.yaml entry and JSON schema property.

Changes

Configurable gatewayClassName across control and observability planes

Layer / File(s) Summary
Control plane: gatewayClassName value, schema, and template
install/helm/openchoreo-control-plane/values.yaml, install/helm/openchoreo-control-plane/values.schema.json, install/helm/openchoreo-control-plane/templates/gateway/gateway.yaml
Adds gatewayClassName under clusterGateway.gateway in values with a kgateway default, registers the field in the JSON schema, and wires .Values.gateway.gatewayClassName into the Gateway CR template replacing the hardcoded value.
Observability plane: gatewayClassName value, schema, and template
install/helm/openchoreo-observability-plane/values.yaml, install/helm/openchoreo-observability-plane/values.schema.json, install/helm/openchoreo-observability-plane/templates/gateway/gateway.yaml
Adds gatewayClassName under gateway in values with a kgateway default, registers the field in the JSON schema, and wires .Values.gateway.gatewayClassName into the Gateway CR template replacing the hardcoded value.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Suggested reviewers

  • sameerajayasoma
  • ChathurangaKCD
  • isala404
  • mevan-karu
  • VajiraPrabuddhaka
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately summarizes the main change: making gatewayClassName configurable in both control and observability plane Helm charts.
Description check ✅ Passed The description is well-structured and covers all required sections: Purpose, Approach, Related Issues, and Checklist. It clearly explains the problem and solution.
Linked Issues check ✅ Passed The PR fully addresses issue #3700 by making gatewayClassName configurable in both control and observability planes with a kgateway default fallback.
Out of Scope Changes check ✅ Passed All changes directly support the core objective of making gatewayClassName configurable. Template files, schema definitions, and values files are all appropriately modified.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@codecov

codecov Bot commented Jun 18, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@LakshanSS LakshanSS left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@NomadXD
NomadXD merged commit e9574f7 into openchoreo:main Jun 22, 2026
14 checks passed
NomadXD added a commit to NomadXD/openchoreo that referenced this pull request Jul 2, 2026
The control-plane and observability-plane charts rendered kgateway-specific
TrafficPolicy resources (gateway.kgateway.dev/v1alpha1) unconditionally, gated
only on the component and gateway being enabled. Since gateway.gatewayClassName
is templatable (control plane and observability plane via openchoreo#3915; the data plane
already supported it), a non-kgateway GatewayClass (e.g. Istio, Cilium) would
still get these kgateway CRDs — inert at best, and a failed helm install/upgrade
when the kgateway CRDs are not installed.

Gate each TrafficPolicy template on gatewayClassName == "kgateway", using the
same default fallback as the gateway.yaml templates.

Fixes openchoreo#4068

Signed-off-by: Lahiru De Silva <[email protected]>
NomadXD pushed a commit that referenced this pull request Jul 7, 2026
Gate all kgateway-specific TrafficPolicy resources in the control-plane and observability-plane Helm charts on gateway.gatewayClassName being "kgateway". This prevents installation and upgrade failures on non-kgateway configurations where KGateway CRDs are not present.

Closes #4068
Refs #3915

Signed-off-by: kavix <[email protected]>
kavix added a commit to kavix/openchoreo that referenced this pull request Jul 7, 2026
Add a default HTTPListenerPolicy targeting the default-gateway in the data-plane Helm chart. Enable it by default, gated on gatewayClassName being 'kgateway'. This allows workloads with Websocket endpoints to function correctly out of the box without requiring manual cluster-wide operations.

Also, remove the manual HTTPListenerPolicy creation steps from the doclet and echo-websocket-service sample READMEs.

Refs openchoreo#4068, openchoreo#3915

Signed-off-by: kavix <[email protected]>
NomadXD pushed a commit that referenced this pull request Jul 8, 2026
* feat(helm): enable WebSocket upgrades by default on KGateway

Add a default HTTPListenerPolicy targeting the default-gateway in the data-plane Helm chart. Enable it by default, gated on gatewayClassName being 'kgateway'. This allows workloads with Websocket endpoints to function correctly out of the box without requiring manual cluster-wide operations.

Also, remove the manual HTTPListenerPolicy creation steps from the doclet and echo-websocket-service sample READMEs.

Refs #4068, #3915

Signed-off-by: kavix <[email protected]>

* feat(helm): scope HTTPListenerPolicy name per deployment

Signed-off-by: kavix <[email protected]>

---------

Signed-off-by: kavix <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Make gatewayClassName configurable across all plane Helm charts

4 participants