Files
nomulus/jetty/kubernetes/gateway/nomulus-route-backend.yaml
T
Nilay ShahandGitHub d98d65eee5 Add mosapi client to intract with ICANN's monitoring system (#2892)
* Add mosapi client to intract with ICANN's monitoring system

This change introduces a comprehensive client to interact with ICANN's Monitoring System API (MoSAPI). This provides direct, automated access to critical registry health and compliance data, moving Nomulus towards a more proactive monitoring posture.

A core, stateless MosApiClient that manages communication and authentication with the MoSAPI service using TLS client certificates.

* Resolve review feedback & upgrade to OkHttp3 client

This commit addresses and resolves all outstanding review comments, primarily encompassing a shift to OkHttp3, security configuration cleanup, and general code improvements.

* **Review:** Addressed and resolved all pending review comments.
* **Feature:** Switched the underlying HTTP client implementation to [OkHttp3](https://square.github.io/okhttp/).
* **Configuration:** Consolidated TLS Certificates-related configuration into the dedicated configuration area.
* **Cleanup:** Removed unused components (`HttpUtils` and `HttpModule`) and performed general code cleanup.
* **Quality:** Improved exception handling logic for better robustness.

* Refactor and fix Mosapi exception handling

Addresses code review feedback and resulting test failures.

- Flattens package structure by moving MosApiException and its test.
- Corrects exception handling to ensure MosApiAuthorizationException
  propagates correctly, before the general exception handler.
- Adds a default case to the MosApiException factory for robustness.
- Uses lowercase for placeholder TLDs in default-config.yaml.

* Refactor and improve Mosapi client implementation

Simplifying URL validation with Guava
Preconditions and refining exception handling to use `Throwables`.

* Refactor precondition checks using project specific utility
2025-12-09 16:29:05 +00:00

109 lines
2.1 KiB
YAML

apiVersion: gateway.networking.k8s.io/v1beta1
kind: HTTPRoute
metadata:
name: backend
spec:
parentRefs:
- kind: Gateway
name: nomulus
sectionName: https
hostnames:
- "backend.BASE_DOMAIN"
rules:
- matches:
- path:
type: PathPrefix
value: /_dr/task
- path:
type: PathPrefix
value: /_dr/cron
- path:
type: PathPrefix
value: /_dr/admin
- path:
type: PathPrefix
value: /_dr/epptool
- path:
type: PathPrefix
value: /_dr/loadtest
- path:
type: PathPrefix
value: /_dr/mosapi
backendRefs:
- group: net.gke.io
kind: ServiceImport
name: backend
port: 80
- matches:
- path:
type: PathPrefix
value: /_dr/task
headers:
- name: "canary"
value: "true"
- path:
type: PathPrefix
value: /_dr/cron
headers:
- name: "canary"
value: "true"
- path:
type: PathPrefix
value: /_dr/admin
headers:
- name: "canary"
value: "true"
- path:
type: PathPrefix
value: /_dr/epptool
headers:
- name: "canary"
value: "true"
- path:
type: PathPrefix
value: /_dr/loadtest
headers:
- name: "canary"
value: "true"
- path:
type: PathPrefix
value: /_dr/mosapi
headers:
- name: "canary"
value: "true"
backendRefs:
- group: net.gke.io
kind: ServiceImport
name: backend-canary
port: 80
---
apiVersion: networking.gke.io/v1
kind: HealthCheckPolicy
metadata:
name: backend
spec:
default:
config:
type: HTTP
httpHealthCheck:
requestPath: /healthz/
targetRef:
group: net.gke.io
kind: ServiceImport
name: backend
---
apiVersion: networking.gke.io/v1
kind: HealthCheckPolicy
metadata:
name: backend-canary
spec:
default:
config:
type: HTTP
httpHealthCheck:
requestPath: /healthz/
targetRef:
group: net.gke.io
kind: ServiceImport
name: backend-canary