Skip to content

Document gateway publishing and verification - #1220

Open
danbarr wants to merge 2 commits into
mainfrom
document-gateway-publishing
Open

danbarr wants to merge 2 commits into
mainfrom
document-gateway-publishing

Conversation

@danbarr

@danbarr danbarr commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator

Description

Operators could enable the gateways without instructions for publishing usable client endpoints, and discovered Kubernetes connectors still required operators to infer the cluster's verification allowlist and recovery steps. Add publishing and verification sections to both gateway deployment guides, plus Service CIDR discovery and failed-connector recovery to Manage connectors.

  • Document Connector Gateway data-plane and control-plane Services, a Gateway API HTTPRoute example, OAuth discovery/callback routing, TLS, streaming, and separate authentication checks.
  • Document AI Gateway HTTPS listener, cert-manager certificate, LoadBalancer publishing, Envoy Service discovery, the existing-edge-proxy alternative, management API access, and authenticated inference and streaming checks.
  • Replace the fixed Service CIDR example with the cluster's actual ranges, explain re-saving persisted failures, and add API status checks and group-access guidance.
  • Link the deployment, client rollout, and API reference pages to the publishing instructions. Make troubleshooting tolerate failed-write logs without an err field, as observed during live validation.

Validation

Production build, Prettier, ESLint, and git diff --check pass. Publishing YAML parses, and the AI Gateway configuration fields and enum values match the source CRD. Service targets, ports, routing, and verification behavior were checked against stacklok-enterprise-platform at a711b3e256fe515675f41de0b7aa36498be4a3f2.

Live tests passed on kind-stacklok-enterprise-demo with platform chart 0.21.0:

  • Service CIDR discovery and API-server fallback both returned 10.96.0.0/16; the configured verification allowlist matched it.
  • A temporary Connector Gateway HTTPRoute was accepted with resolved references and served OAuth discovery with private-CA validation.
  • A separate temporary AI Gateway received a LoadBalancer address, obtained its HTTPS certificate through cert-manager, and served an authenticated model completion.
  • The existing Traefik publishing path served authenticated model completions and streamed SSE responses.
  • Connector Gateway, Enterprise Manager, and AI Gateway management API port-forwards accepted the demo account's token.
  • A connector pointing at a private Pod IP outside the allowlist persisted as failure despite allow_private_ips: true. Re-saving with an allowed Service endpoint produced available.
  • A temporary connector, group grant, and user connection completed browser login, gateway token exchange, MCP initialization, tool listing, and a successful fetch tool call.

Temporary Kubernetes resources, connectors, connections, and OAuth registrations were cleaned up; the original gateways remained healthy. No Helm upgrade or Claude Code UI workflow was performed. The MCP flow was exercised directly.

Type of change

  • Documentation update

Related issues/PRs

Closes #1161.
Closes #1217.
Partially addresses #1159 by adding endpoint publishing and separate registration, control-plane, and MCP verification. Its remaining identity configuration and platform-admin grant gaps are outside this PR.

Submitter checklist

Content and formatting

  • I have reviewed the content for technical accuracy
  • I have reviewed the content for spelling, grammar, and style

Reviewer checklist

Content

  • I have reviewed the content for technical accuracy
  • I have reviewed the content for spelling, grammar, and style

Copilot AI balanced review requested due to automatic review settings October 7, 2026 18:26
@vercel

vercel Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs-website Ready Ready Preview Oct 7, 2026 6:35pm UTC

Request Review

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Independent verification against the cited upstream source remains incomplete, so the operational guidance needs human confirmation.

1 open finding
What changed in this PR

Adds endpoint publishing and verification workflows to the Stacklok Enterprise gateway documentation.

Changes:

  • Documents gateway routing, TLS, streaming, and separate API checks.
  • Explains Service CIDR discovery and failed-connector recovery.
  • Links deployment, client rollout, and API references to publishing guidance.
File Description
docs/​platform/​enterprise-platform/​roll-out-gateway-clients.mdx Adds publishing prerequisites.
docs/​platform/​enterprise-platform/​deployment.mdx Links gateway publishing workflows.
docs/​platform/​enterprise-platform/​configure-connector-gateway.mdx Adds routing and authentication checks.
docs/​platform/​enterprise-platform/​configure-ai-gateway.mdx Adds inference publishing and API verification.
docs/​connector-gateway/​connectors.mdx Explains network allowlists and recovery.
docs/​connector-gateway/​api-reference.mdx Links Connector Gateway publishing guidance.
docs/​ai-gateway/​api-reference.mdx Links AI Gateway publishing guidance.

🧠 Review effort: Balanced


💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread docs/platform/enterprise-platform/deployment.mdx Outdated

This branch was successfully deployed

1 active deployment
Preview — a2c78175 Deployed Oct 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Gap]: Document gateway endpoint publishing and verification [Gap]: Document in-cluster connector discovery network prerequisites and recovery

2 participants