Skip to content

feat(aisix): deploy the gateway's Admin API in standalone mode through admin values - #399

Merged
nic-6443 merged 1 commit into
mainfrom
feat/aisix-admin-api
Sep 29, 2026
Merged

nic-6443 merged 1 commit into
mainfrom
feat/aisix-admin-api

Conversation

@jarvis9443

Copy link
Copy Markdown
Contributor

The gateway's read-only Admin API becomes a supported part of charts/aisix in standalone mode. It is configured through values, so the extraEnvVars workaround is no longer needed.

There is a new admin block, off by default:

containerPorts:
  admin: 3001
admin:
  enabled: false
  keys: []                     # rendered into a chart-managed Secret
  existingSecret: ""           # or read them from your own Secret
  existingSecretKey: admin-keys
  service:
    port: 3001
    annotations: {}

When enabled:

  • The config file gets admin: {enabled: true, addr: 0.0.0.0:<containerPorts.admin>}.
  • The container declares an admin port.
  • A ClusterIP Service <fullname>-admin publishes it. The proxy Service is untouched.
  • The keys reach the gateway only as AISIX_ADMIN__ADMIN_KEYS, a secretKeyRef env var. The gateway registers it as a list key and splits it on commas. The keys come either from the chart-managed Secret <fullname>-admin (key admin-keys, the keys joined with commas) or from existingSecret. They never go into the ConfigMap.

The render fails in three cases:

  • admin.enabled without keys.
  • A key that is empty or contains a comma.
  • admin.enabled together with controlPlane.enabled. A managed gateway never binds the admin listener (AdminConfig in aisix-core, and main.rs logs "admin surface not bound").

admin stays refused under config:, and its message now points at these values.

With default values the rendered manifests are byte-identical to main in both modes. A release that binds the Admin API through AISIX_ADMIN__* in extraEnvVars keeps working unchanged, because the environment overrides the file.

The README's standalone section gains an "Admin API" subsection. It covers the Service, the key sources, the refusals, and that the same listener also serves the Playground (POST /playground/chat/completions), which is authenticated with a caller API key like the proxy.

Tests: six new render checks cover disabled, enabled, existingSecret, and the three refusals. There is also a new CI install leg. It installs standalone with admin enabled and asserts, through the admin Service, 401 without a key and 200 with one.

🤖 Generated with Claude Code

…h admin values

A new `admin` block, off by default: `admin.enabled` binds the Admin API on
`containerPorts.admin` (3001) and publishes it on its own ClusterIP Service,
`<fullname>-admin`, never on the proxy Service. Admin keys come from
`admin.keys` (rendered into a chart-managed Secret) or `admin.existingSecret`
/ `admin.existingSecretKey`, and reach the gateway only as the
`AISIX_ADMIN__ADMIN_KEYS` secretKeyRef env var, never the ConfigMap. The
rendered file gets `admin.enabled: true` and `admin.addr: 0.0.0.0:<port>`.

The render fails when admin is enabled without keys, with a key containing a
comma (the gateway reads the list comma-separated), or together with
`controlPlane.enabled` (a managed gateway never binds the admin listener).
`admin` stays refused under `config:`.

With defaults the rendered manifests are byte-identical to before, and a
release that binds the Admin API through `AISIX_ADMIN__*` in `extraEnvVars`
keeps working, since the environment overrides the file.
@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Warning

Review limit reached

  • Run on-demand review

This review includes 10 billable files and costs up to $2.50.

  • Ask an admin to make reviews automatic

Open in CodeRabbit

Reviews can continue after your included limit without a manual trigger. An admin must approve usage-based billing.

Or wait 10 minutes for your next included review.

Check out review usage here.

View limit details

Limit details: You’ve used all 2 included reviews currently available. Your 53 included PR review attempts over the past 7 days set your current allowance at 2 reviews per hour.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Essentials

Run ID: a1499281-5b62-4c34-a30d-bf1791a4a296

📥 Commits

Reviewing files that changed from the base of the PR and between dae97ac and fc62507.

📒 Files selected for processing (10)
  • .github/scripts/aisix-render-checks.sh
  • .github/workflows/ci.yaml
  • charts/aisix/README.md
  • charts/aisix/README.md.gotmpl
  • charts/aisix/config-policy.yaml
  • charts/aisix/templates/_helpers.tpl
  • charts/aisix/templates/deployment.yaml
  • charts/aisix/templates/secret.yaml
  • charts/aisix/templates/service-admin.yaml
  • charts/aisix/values.yaml

Comment @coderabbitai help to get the list of available commands.

@nic-6443
nic-6443 merged commit 35f240d into main Sep 29, 2026
3 checks passed
@nic-6443
nic-6443 deleted the feat/aisix-admin-api branch September 29, 2026 11:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants