feat(aisix): deploy the gateway's Admin API in standalone mode through admin values - #399
Merged
Merged
Conversation
…h admin values A new `admin` block, off by default: `admin.enabled` binds the Admin API on `containerPorts.admin` (3001) and publishes it on its own ClusterIP Service, `<fullname>-admin`, never on the proxy Service. Admin keys come from `admin.keys` (rendered into a chart-managed Secret) or `admin.existingSecret` / `admin.existingSecretKey`, and reach the gateway only as the `AISIX_ADMIN__ADMIN_KEYS` secretKeyRef env var, never the ConfigMap. The rendered file gets `admin.enabled: true` and `admin.addr: 0.0.0.0:<port>`. The render fails when admin is enabled without keys, with a key containing a comma (the gateway reads the list comma-separated), or together with `controlPlane.enabled` (a managed gateway never binds the admin listener). `admin` stays refused under `config:`. With defaults the rendered manifests are byte-identical to before, and a release that binds the Admin API through `AISIX_ADMIN__*` in `extraEnvVars` keeps working, since the environment overrides the file.
|
Warning Review limit reached
This review includes 10 billable files and costs up to $2.50.
Reviews can continue after your included limit without a manual trigger. An admin must approve usage-based billing. Or wait 10 minutes for your next included review. View limit detailsLimit details: You’ve used all 2 included reviews currently available. Your 53 included PR review attempts over the past 7 days set your current allowance at 2 reviews per hour. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (10)
Comment |
nic-6443
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The gateway's read-only Admin API becomes a supported part of
charts/aisixin standalone mode. It is configured through values, so theextraEnvVarsworkaround is no longer needed.There is a new
adminblock, off by default:When enabled:
admin: {enabled: true, addr: 0.0.0.0:<containerPorts.admin>}.adminport.<fullname>-adminpublishes it. The proxy Service is untouched.AISIX_ADMIN__ADMIN_KEYS, asecretKeyRefenv var. The gateway registers it as a list key and splits it on commas. The keys come either from the chart-managed Secret<fullname>-admin(keyadmin-keys, the keys joined with commas) or fromexistingSecret. They never go into the ConfigMap.The render fails in three cases:
admin.enabledwithout keys.admin.enabledtogether withcontrolPlane.enabled. A managed gateway never binds the admin listener (AdminConfiginaisix-core, andmain.rslogs "admin surface not bound").adminstays refused underconfig:, and its message now points at these values.With default values the rendered manifests are byte-identical to
mainin both modes. A release that binds the Admin API throughAISIX_ADMIN__*inextraEnvVarskeeps working unchanged, because the environment overrides the file.The README's standalone section gains an "Admin API" subsection. It covers the Service, the key sources, the refusals, and that the same listener also serves the Playground (
POST /playground/chat/completions), which is authenticated with a caller API key like the proxy.Tests: six new render checks cover disabled, enabled,
existingSecret, and the three refusals. There is also a new CI install leg. It installs standalone with admin enabled and asserts, through the admin Service, 401 without a key and 200 with one.🤖 Generated with Claude Code