Skip to content

feat(helm): enable WebSocket upgrades by default on KGateway - #4076

Closed
kavix wants to merge 1 commit into
openchoreo:mainfrom
kavix:feat/enable-websockets-by-default
Closed

kavix wants to merge 1 commit into
openchoreo:mainfrom
kavix:feat/enable-websockets-by-default

Conversation

@kavix

@kavix kavix commented Jul 3, 2026

Copy link
Copy Markdown
Contributor

Purpose

Websocket is a first-class workload endpoint type in OpenChoreo, but connections failed out of the box because KGateway (based on Envoy) disables WebSocket upgrades by default. Enabling upgrades requires an HTTPListenerPolicy (gateway.kgateway.dev/v1alpha1) on the Gateway listener.

This PR deploys a default HTTPListenerPolicy in the data-plane Helm chart so that WebSocket upgrades work out-of-the-box for all users without manual cluster-wide operations.

Approach

  1. Added a new template install/helm/openchoreo-data-plane/templates/gateway/httplistenerpolicy.yaml which creates an HTTPListenerPolicy targeting the default gateway (gateway-default) with WebSocket upgrades enabled.
  2. Gated the generation on gateway.enabled and gateway.gatewayClassName == "kgateway" to align with the KGateway-specific CRD availability and prevent installation failures on non-KGateway configurations.
  3. Added the gateway.httpListenerPolicy configuration under gateway in values.yaml and values.schema.json to allow users to toggle the policy.
  4. Cleaned up the manual step to apply the HTTPListenerPolicy from samples/from-image/doclet/README.md and samples/from-image/echo-websocket-service/README.md.

Related Issues

Closes #4068
Refs #3915

Checklist

  • Tests added or updated (unit, integration, etc.)
  • Samples updated (if applicable)
  • Added backport/<release-branch> label if this should be backported (e.g., backport/release-v1.0)
  • This PR includes AI-generated code or content

Add a default HTTPListenerPolicy targeting the default-gateway in the data-plane Helm chart. Enable it by default, gated on gatewayClassName being "kgateway". This allows workloads with Websocket endpoints to function correctly out of the box without requiring manual cluster-wide operations.

Also, remove the manual HTTPListenerPolicy creation steps from the doclet and echo-websocket-service sample READMEs.

Refs openchoreo#4068, openchoreo#3915

Signed-off-by: kavix <[email protected]>
@coderabbitai

coderabbitai Bot commented Jul 3, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

This PR adds a Helm template that conditionally creates an HTTPListenerPolicy for WebSocket upgrade support on the default gateway, along with corresponding values.yaml and values.schema.json entries. Two sample READMEs are updated to remove now-unnecessary manual WebSocket-enabling steps and renumber subsequent steps.

Changes

HTTPListenerPolicy chart support and sample doc updates

Layer / File(s) Summary
HTTPListenerPolicy template, values, and schema
install/helm/openchoreo-data-plane/templates/gateway/httplistenerpolicy.yaml, install/helm/openchoreo-data-plane/values.yaml, install/helm/openchoreo-data-plane/values.schema.json
Adds a new Helm template rendering an HTTPListenerPolicy targeting gateway-default with enabledUpgrades: [websocket], gated on gateway support, gatewayClassName: kgateway, and httpListenerPolicy.enabled; adds the gateway.httpListenerPolicy.enabled (default true) field to values and schema.
Sample README step renumbering
samples/from-image/doclet/README.md, samples/from-image/echo-websocket-service/README.md
Removes manual HTTPListenerPolicy WebSocket-enabling instructions from both sample READMEs and renumbers subsequent deployment/testing steps.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related issues

Suggested reviewers: akila-i, binoyPeries, chalindukodikara, ChathurangaKCD, JanakaSandaruwan, LakshanSS, Mirage20, nilushancosta, sameerajayasoma, VajiraPrabuddhaka, yashodgayashan

🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Linked Issues check ⚠️ Warning The PR does not implement #4068's kgateway TrafficPolicy gating in the control/observability charts; it adds a data-plane HTTPListenerPolicy instead. Update the control-plane and observability-plane TrafficPolicy templates to gate on gatewayClassName == "kgateway", and verify the affected charts render only for kgateway.
Out of Scope Changes check ⚠️ Warning The data-plane HTTPListenerPolicy and sample README changes are outside #4068, which only asks to gate existing kgateway TrafficPolicies in other charts. Remove or justify the data-plane policy/sample edits, or add the corresponding issue requirements that cover them.
✅ Passed checks (3 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check ✅ Passed The title matches the PR’s main change and follows the required Conventional Commits format.
Description check ✅ Passed The description covers Purpose, Approach, Related Issues, and Checklist, with only Remarks left empty.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In
`@install/helm/openchoreo-data-plane/templates/gateway/httplistenerpolicy.yaml`:
- Around line 1-19: The chart is still rendering the deprecated
HTTPListenerPolicy resource; update the gateway template to emit ListenerPolicy
instead. Keep the existing gating around .Values.gateway.enabled and
.Values.gateway.httpListenerPolicy.enabled, but change the manifest from
HTTPListenerPolicy to ListenerPolicy and move the websocket upgrade
configuration under ListenerPolicy.spec.default.httpSettings. Ensure the
targetRefs still point at the default Gateway and preserve the existing
labels/metadata structure in the gateway template.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 03edfca7-ad2a-433e-918e-16eee77d8a01

📥 Commits

Reviewing files that changed from the base of the PR and between 05ab88c and 0ea6110.

📒 Files selected for processing (5)
  • install/helm/openchoreo-data-plane/templates/gateway/httplistenerpolicy.yaml
  • install/helm/openchoreo-data-plane/values.schema.json
  • install/helm/openchoreo-data-plane/values.yaml
  • samples/from-image/doclet/README.md
  • samples/from-image/echo-websocket-service/README.md

Comment on lines +1 to +19
{{- if and .Values.gateway.enabled (eq (.Values.gateway.gatewayClassName | default "kgateway") "kgateway") .Values.gateway.httpListenerPolicy.enabled }}
apiVersion: gateway.kgateway.dev/v1alpha1
kind: HTTPListenerPolicy
metadata:
name: default-httplistenerpolicy
namespace: {{ .Release.Namespace }}
labels:
{{- include "openchoreo-data-plane.componentLabels" (dict "context" . "component" "gateway") | nindent 4 }}
spec:
# Target the default gateway created by this chart
targetRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: gateway-default
# Enable WebSocket upgrades by default on all listeners of the target Gateway
upgradeConfig:
enabledUpgrades:
- websocket
{{- end }}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Find the kgateway version pinned by this chart to check HTTPListenerPolicy deprecation status
rg -n 'tag:|appVersion|kgateway' install/helm/openchoreo-data-plane/Chart.yaml install/helm/openchoreo-data-plane/values.yaml

Repository: openchoreo/openchoreo

Length of output: 670


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Show the gateway/controller values block and any kgateway API references.
sed -n '1,120p' install/helm/openchoreo-data-plane/values.yaml
printf '\n---\n'
sed -n '200,260p' install/helm/openchoreo-data-plane/values.yaml
printf '\n---\n'
rg -n 'HTTPListenerPolicy|ListenerPolicy|kgateway|gatewayClassName|controller.image.tag' install/helm/openchoreo-data-plane

Repository: openchoreo/openchoreo

Length of output: 7439


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Query upstream docs/changelog for HTTPListenerPolicy deprecation and ListenerPolicy replacement.
python3 - <<'PY'
import urllib.request, urllib.parse, ssl
queries = [
    "kgateway HTTPListenerPolicy deprecated v2.2.0 ListenerPolicy httpSettings",
    "site:kgateway.dev HTTPListenerPolicy deprecated ListenerPolicy",
]
for q in queries:
    print("QUERY:", q)
PY

Repository: openchoreo/openchoreo

Length of output: 310


🌐 Web query:

kgateway HTTPListenerPolicy deprecated ListenerPolicy v2.2.0 site:kgateway.dev OR site:docs.kgateway.dev OR site:github.com/kgateway-dev

💡 Result:

In Kgateway, the HTTPListenerPolicy resource is officially deprecated [1][2][3]. Users are instructed to migrate their configurations to the ListenerPolicy resource instead [1][2]. Specifically, configuration previously handled by HTTPListenerPolicy should now be managed using the httpSettings field within a ListenerPolicy [2][3]. This change was noted in the release notes for version 2.2.0, which formalised the deprecation of HTTPListenerPolicy [2].

Citations:


Migrate HTTPListenerPolicy to ListenerPolicy kgateway deprecates HTTPListenerPolicy in 2.2.0+, so this chart keeps emitting a deprecated API. Move the websocket upgrade config under ListenerPolicy.spec.default.httpSettings.

🧰 Tools
🪛 YAMLlint (1.37.1)

[error] 1-1: syntax error: expected the node content, but found '-'

(syntax)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@install/helm/openchoreo-data-plane/templates/gateway/httplistenerpolicy.yaml`
around lines 1 - 19, The chart is still rendering the deprecated
HTTPListenerPolicy resource; update the gateway template to emit ListenerPolicy
instead. Keep the existing gating around .Values.gateway.enabled and
.Values.gateway.httpListenerPolicy.enabled, but change the manifest from
HTTPListenerPolicy to ListenerPolicy and move the websocket upgrade
configuration under ListenerPolicy.spec.default.httpSettings. Ensure the
targetRefs still point at the default Gateway and preserve the existing
labels/metadata structure in the gateway template.

@codecov

codecov Bot commented Jul 3, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@kavix kavix closed this Jul 3, 2026
@kavix
kavix deleted the feat/enable-websockets-by-default branch July 3, 2026 11:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Gate kgateway TrafficPolicies on gatewayClassName being kgateway

1 participant