From a93619acab237b6c71559529877e029b6dc5c58d Mon Sep 17 00:00:00 2001 From: "aspire-repo-bot[bot]" <268009190+aspire-repo-bot[bot]@users.noreply.github.com> Date: Tue, 25 Aug 2026 00:22:43 +0000 Subject: [PATCH 1/4] docs: document hostname inheritance for Ingress paths and Gateway routes Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- .../docs/deployment/kubernetes-ingress.mdx | 33 +++++++++++++++++++ 1 file changed, 33 insertions(+) diff --git a/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx b/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx index 75507028c..0e64d4945 100644 --- a/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx +++ b/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx @@ -113,6 +113,39 @@ await ingress.withPath('/', web.getEndpoint('http')); the `HTTPRoute` resource it generates. +## Hostname inheritance for paths and routes + +`WithHostname(...)` on the Ingress or Gateway sets the hostname that applies +to any path (`WithPath`) or route (`WithRoute`) you add **without** an +explicit hostname of its own. This lets you set the hostname once and reuse it +across every hostless path or route: + +```csharp title="AppHost.cs" +var ingress = k8s.AddIngress("public") + .WithHostname("app.example.com") + .WithTls(); + +// Both paths inherit "app.example.com" from WithHostname(...). +ingress.WithPath("/api", api.GetEndpoint("http")); +ingress.WithPath("/", web.GetEndpoint("http")); +``` + +If a path or route specifies its own hostname — via the host-scoped +`WithPath("api.example.com", "/", endpoint)` overload, or the equivalent on +`WithRoute` — that explicit hostname takes precedence over the one from +`WithHostname(...)`. + +`WithDefaultBackend(endpoint)` is unaffected by `WithHostname(...)`: the +default backend always generates a catch-all rule (no `host` restriction) so +it keeps accepting any traffic that doesn't match a more specific path or +route, including the TLS compatibility rule Aspire generates for it. + + + ## TLS and certificates When you configure TLS with `WithTls()`, Aspire handles the initial bootstrapping: From e7fbfc615e158554148f2c5bc5fed4ba9dff83b4 Mon Sep 17 00:00:00 2001 From: Maddy Montaquila Date: Tue, 29 Sep 2026 16:25:30 -0400 Subject: [PATCH 2/4] Apply suggestion from @alistairmatthews Co-authored-by: Alistair Matthews --- .../src/content/docs/deployment/kubernetes-ingress.mdx | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx b/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx index 0e64d4945..f2bc6f25a 100644 --- a/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx +++ b/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx @@ -115,10 +115,9 @@ await ingress.withPath('/', web.getEndpoint('http')); ## Hostname inheritance for paths and routes -`WithHostname(...)` on the Ingress or Gateway sets the hostname that applies -to any path (`WithPath`) or route (`WithRoute`) you add **without** an -explicit hostname of its own. This lets you set the hostname once and reuse it -across every hostless path or route: +The `WithHostname()` method on the Ingress or Gateway sets the hostname that applies +to any path or route you add **without** an +explicit hostname of its own, by using `WithPath` or `WithRoute`. This arrangement lets you set the hostname once and reuse it across every hostless path or route: ```csharp title="AppHost.cs" var ingress = k8s.AddIngress("public") From eb690324431b7f1410610bdfe42ed7afc3f104ba Mon Sep 17 00:00:00 2001 From: Maddy Montaquila Date: Tue, 29 Sep 2026 16:25:46 -0400 Subject: [PATCH 3/4] Apply suggestion from @alistairmatthews Co-authored-by: Alistair Matthews --- src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx b/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx index f2bc6f25a..3ab8e8b1c 100644 --- a/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx +++ b/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx @@ -135,7 +135,7 @@ If a path or route specifies its own hostname — via the host-scoped `WithHostname(...)`. `WithDefaultBackend(endpoint)` is unaffected by `WithHostname(...)`: the -default backend always generates a catch-all rule (no `host` restriction) so +default backend always generates a catch-all rule, no `host` restriction. Thus it keeps accepting any traffic that doesn't match a more specific path or route, including the TLS compatibility rule Aspire generates for it. From 568445a0fedd47c3a3bff5b2bc3e1d806a77d784 Mon Sep 17 00:00:00 2001 From: Maddy Montaquila Date: Tue, 29 Sep 2026 16:25:56 -0400 Subject: [PATCH 4/4] Apply suggestion from @alistairmatthews Co-authored-by: Alistair Matthews --- .../src/content/docs/deployment/kubernetes-ingress.mdx | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx b/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx index 3ab8e8b1c..85812d4bc 100644 --- a/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx +++ b/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx @@ -129,10 +129,9 @@ ingress.WithPath("/api", api.GetEndpoint("http")); ingress.WithPath("/", web.GetEndpoint("http")); ``` -If a path or route specifies its own hostname — via the host-scoped +If a path or route specifies its own hostname, that explicit hostname takes precedence over the one from `WithHostname()`. You can specify the hostname by using the host-scoped `WithPath("api.example.com", "/", endpoint)` overload, or the equivalent on -`WithRoute` — that explicit hostname takes precedence over the one from -`WithHostname(...)`. +`WithRoute` . `WithDefaultBackend(endpoint)` is unaffected by `WithHostname(...)`: the default backend always generates a catch-all rule, no `host` restriction. Thus