Skip to content

feat(helm): enable WebSocket upgrades by default on KGateway - #4078

Closed
kavix wants to merge 1 commit into
openchoreo:mainfrom
kavix:fix/websocket-upgrade-default
Closed

kavix wants to merge 1 commit into
openchoreo:mainfrom
kavix:fix/websocket-upgrade-default

Conversation

@kavix

@kavix kavix commented Jul 3, 2026 •

Copy link
Copy Markdown
Contributor

Purpose

Websocket is a first-class workload endpoint type in OpenChoreo, but connections failed out of the box because KGateway (based on Envoy) disables WebSocket upgrades by default. Enabling upgrades requires an HTTPListenerPolicy (gateway.kgateway.dev/v1alpha1) on the Gateway listener.

This PR deploys a default HTTPListenerPolicy in the data-plane Helm chart so that WebSocket upgrades work out-of-the-box for all users without manual cluster-wide operations.

Approach

  1. Added a new template install/helm/openchoreo-data-plane/templates/gateway/httplistenerpolicy.yaml which creates an HTTPListenerPolicy targeting the default gateway (gateway-default) with WebSocket upgrades enabled.
  2. Gated the generation on gateway.enabled and gateway.gatewayClassName == "kgateway" to align with the KGateway-specific CRD availability and prevent installation failures on non-KGateway configurations.
  3. Added the gateway.httpListenerPolicy configuration under gateway in values.yaml and values.schema.json to allow users to toggle the policy.
  4. Cleaned up the manual step to apply the HTTPListenerPolicy from samples/from-image/doclet/README.md and samples/from-image/echo-websocket-service/README.md.

Related Issues

Closes #4069
Refs #3915

Checklist

  • Tests added or updated (unit, integration, etc.)
  • Samples updated (if applicable)
  • Added backport/<release-branch> label if this should be backported (e.g., backport/release-v1.0)
  • This PR includes AI-generated code or content

Add a default HTTPListenerPolicy targeting the default-gateway in the data-plane Helm chart. Enable it by default, gated on gatewayClassName being "kgateway". This allows workloads with Websocket endpoints to function correctly out of the box without requiring manual cluster-wide operations.

Also, remove the manual HTTPListenerPolicy creation steps from the doclet and echo-websocket-service sample READMEs.

Refs openchoreo#4068, openchoreo#3915

Signed-off-by: kavix <[email protected]>
@coderabbitai

coderabbitai Bot commented Jul 3, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Adds a Helm template that conditionally creates a default HTTPListenerPolicy enabling WebSocket upgrades on the data-plane gateway, gated by a new gateway.httpListenerPolicy.enabled values/schema setting. Updates two sample READMEs to remove now-unnecessary manual WebSocket-enablement steps and renumber remaining steps.

Changes

Default HTTPListenerPolicy support

Layer / File(s) Summary
HTTPListenerPolicy Helm template and configuration
install/helm/openchoreo-data-plane/templates/gateway/httplistenerpolicy.yaml, install/helm/openchoreo-data-plane/values.yaml, install/helm/openchoreo-data-plane/values.schema.json
New template conditionally renders an HTTPListenerPolicy targeting the default gateway when enabled and gatewayClassName is kgateway, enabling WebSocket upgrades by default; new httpListenerPolicy.enabled boolean added to values and schema.
Sample README updates for removed manual WebSocket step
samples/from-image/doclet/README.md, samples/from-image/echo-websocket-service/README.md
Removes manual HTTPListenerPolicy WebSocket-enablement instructions from Step 1 and renumbers subsequent steps accordingly.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related issues

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Linked Issues check ⚠️ Warning The linked issue asks to gate existing kgateway TrafficPolicy templates, but this PR only adds a data-plane HTTPListenerPolicy. Add the requested gatewayClassName == "kgateway" gating to the control-plane and observability-plane TrafficPolicy templates, or relink this PR to the correct issue.
✅ Passed checks (4 passed)
Check name Status Explanation
Out of Scope Changes check ✅ Passed The changes stay focused on the new KGateway HTTPListenerPolicy and matching sample/doc updates, with no clearly unrelated edits.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check ✅ Passed The title is concise, conventional, and accurately highlights the main change: enabling WebSocket upgrades by default on KGateway.
Description check ✅ Passed The description covers Purpose, Approach, Related Issues, and Checklist; only the optional Remarks section is missing.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Jul 3, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@kavix kavix closed this Jul 3, 2026
@kavix
kavix deleted the fix/websocket-upgrade-default branch July 3, 2026 11:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Apply HTTPListenerPolicy by default to enable Websocket endpoints

1 participant