Skip to content

Fix Kubernetes hostname publishing and routing - #19430

Merged
Mitch Denny (mitchdenny) merged 2 commits into
mainfrom
mitchdenny-fix-kubernetes-ingress-hostname
Aug 24, 2026
Merged

Mitch Denny (mitchdenny) merged 2 commits into
mainfrom
mitchdenny-fix-kubernetes-ingress-hostname

Conversation

@mitchdenny

@mitchdenny Mitch Denny (mitchdenny) commented Aug 17, 2026 •

Copy link
Copy Markdown
Member

Description

Kubernetes publishing currently hardcodes runtime-only hostname parameter values and leaves hostless Ingress paths and Gateway routes as catch-all rules. This means WithHostname(...) does not provide the documented routing scope and publishValueAsDefault: false is not honored for these resources.

This change:

  • preserves secrets and parameters without published defaults as owner-scoped Helm values;
  • applies configured hostnames to hostless Ingress paths and Gateway HTTPRoute resources;
  • keeps explicit per-route hostnames authoritative;
  • preserves Kubernetes default backends as catch-all, including the existing TLS compatibility rule generation; and
  • documents the hostname inheritance and default-backend behavior.

User-facing usage

C# AppHost:

var hostname = builder.AddParameter("hostname", "localhost");
var k8s = builder.AddKubernetesEnvironment("k8s");
var ingress = k8s.AddIngress("public")
    .WithHostname(hostname)
    .WithTls();

ingress.WithPath("/api", api.GetEndpoint("http"));

The generated Ingress now scopes the route and TLS configuration with a deploy-time value:

spec:
  rules:
    - host: "{{ .Values.parameters.public.hostname }}"
  tls:
    - hosts:
        - "{{ .Values.parameters.public.hostname }}"

TypeScript AppHost:

const k8s = await builder.addKubernetesEnvironment("k8s");
const ingress = await k8s.addIngress("public");
await ingress.withHostname("api.example.com");
await ingress.withIngressPath("/api", api.getEndpoint("http"));

Validation

  • Aspire.Hosting.Kubernetes.Tests: 287 passed
  • AzureKubernetesIngressTests: 8 passed
  • Deployment E2E Tests: 42 of 42 deployment jobs passed

Fixes #17755

Checklist

  • Is this feature complete?
    • Yes. Ready to ship.
    • No. Follow-up changes expected.
  • Are you including unit tests for the changes and scenario tests if relevant?
    • Yes
    • No
  • Did you add public API?
    • Yes
      • If yes, did you have an API Review for it?
        • Yes
        • No
      • Did you add <remarks /> and <code /> elements on your triple slash comments?
        • Yes
        • No
    • No
  • Does the change make any security assumptions or guarantees?
    • Yes
      • If yes, have you done a threat model and had a security review?
        • Yes
        • No
    • No

Preserve runtime-only parameters as Helm values and apply configured hostnames to hostless Ingress paths and Gateway routes. Keep default backends catch-all outside the existing TLS compatibility behavior.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: f5d87339-2d36-4690-8422-801dfac7e135
Copilot AI balanced review requested due to automatic review settings August 17, 2026 09:14
@mitchdenny

Copy link
Copy Markdown
Member Author

/deployment-test

@github-actions

Copy link
Copy Markdown
Contributor

🚀 Dogfood this PR with:

⚠️ WARNING: Do not do this without first carefully reviewing the code of this PR to satisfy yourself it is safe.

curl -fsSL https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.sh | bash -s -- 19430

Or

  • Run remotely in PowerShell:
iex "& { $(irm https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.ps1) } 19430"

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Fixes #17755 by preserving deploy-time hostname parameters and applying configured hostnames to Kubernetes routing resources.

Changes:

  • Emits owner-scoped Helm values for deferred parameters and secrets.
  • Applies hostnames to hostless Ingress and Gateway routes while preserving explicit hosts and default backends.
  • Adds documentation and snapshot tests.
Show a summary per file
File Description
src/Aspire.Hosting.Kubernetes/KubernetesEnvironmentResource.cs Implements deferred values and hostname inheritance.
src/Aspire.Hosting.Kubernetes/KubernetesIngressExtensions.cs Documents Ingress routing behavior.
src/Aspire.Hosting.Kubernetes/KubernetesGatewayExtensions.cs Documents Gateway routing behavior.
tests/Aspire.Hosting.Kubernetes.Tests/KubernetesIngressTests.cs Adds Ingress regression tests.
tests/Aspire.Hosting.Kubernetes.Tests/KubernetesGatewayTests.cs Adds Gateway regression tests.
...Ingress...RuntimeOnlyHostnameParameter...#00.verified.yaml Verifies deferred Ingress hostname output.
...Ingress...RuntimeOnlyHostnameParameter...#01.verified.yaml Verifies Ingress Helm values.
...Ingress...Hostname_AppliesToHostlessPath.verified.yaml Verifies inherited Ingress hosts.
...Ingress...DefaultBackendWithoutTls...verified.yaml Verifies catch-all default backend.
...Gateway...RuntimeOnlyHostnameParameter...#00.verified.yaml Verifies deferred Gateway listener.
...Gateway...RuntimeOnlyHostnameParameter...#01.verified.yaml Verifies deferred HTTPRoute hostname.
...Gateway...RuntimeOnlyHostnameParameter...#02.verified.yaml Verifies Gateway Helm values.
...Gateway...Hostname_AppliesToHostlessRoute.verified.yaml Verifies inherited HTTPRoute hosts.

Review details

Suppressed comments (1)

src/Aspire.Hosting.Kubernetes/KubernetesEnvironmentResource.cs:1150

  • The inherited HTTPRoute.spec.hostnames behavior is validated only as generated YAML. Add or extend a deployment end-to-end test to deploy a Gateway with WithHostname(...) and verify matching and nonmatching host requests, so listener/route attachment and Helm substitution are exercised together.
            else
            {
                httpRoute.Spec.Hostnames.AddRange(resolvedHostnames);
  • Files reviewed: 13/13 changed files
  • Comments generated: 1
  • Review effort level: Balanced

Comment thread src/Aspire.Hosting.Kubernetes/KubernetesEnvironmentResource.cs
@github-actions

Copy link
Copy Markdown
Contributor

🚀 Deployment tests starting on PR #19430...

This will deploy to real Azure infrastructure. Results will be posted here when complete.

View workflow run

@github-actions
github-actions Bot temporarily deployed to deployment-testing August 17, 2026 09:25 Inactive
@github-actions

This comment has been minimized.

@github-actions
github-actions Bot temporarily deployed to deployment-testing August 17, 2026 09:33 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 17, 2026 09:33 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 17, 2026 09:33 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 17, 2026 09:33 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 17, 2026 09:33 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 17, 2026 09:33 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 17, 2026 09:33 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 17, 2026 09:33 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 17, 2026 09:33 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 17, 2026 09:33 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 17, 2026 09:33 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 17, 2026 09:33 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 17, 2026 09:33 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 17, 2026 09:33 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 17, 2026 09:33 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 17, 2026 09:33 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 17, 2026 09:33 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 17, 2026 09:33 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 17, 2026 09:33 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 24, 2026 09:13 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 24, 2026 09:13 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 24, 2026 09:13 Inactive
@github-actions
github-actions Bot temporarily deployed to deployment-testing August 24, 2026 09:13 Inactive
@github-actions

Copy link
Copy Markdown
Contributor

Retrying the failed CI jobs for this pull request from the CI run attempt. The rerun is being tracked in the rerun attempt.

@github-actions

Copy link
Copy Markdown
Contributor

Retrying the failed CI jobs for this pull request from the CI run attempt. The rerun is being tracked in the rerun attempt.

@eerhardt Eric Erhardt (eerhardt) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the hostname routing and deploy-time parameter handling changes. No blocking issues found.

@mitchdenny

Copy link
Copy Markdown
Member Author

/deployment-test

@github-actions

Copy link
Copy Markdown
Contributor

🚀 Deployment tests starting on PR #19430...

This will deploy to real Azure infrastructure. Results will be posted here when complete.

View workflow run

@aspire-repo-bot

Copy link
Copy Markdown
Contributor

Pull request created: #1574

Generated by PR Documentation Check · auto · 79.6 AIC · ⌖ 8.28 AIC · ⊞ 19.6K

@aspire-repo-bot

Copy link
Copy Markdown
Contributor

📝 Documentation has been drafted in microsoft/aspire.dev#1574 targeting release/13.6.

Added a "Hostname inheritance for paths and routes" section to src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx explaining that WithHostname(...) now scopes hostless WithPath/WithRoute calls, that explicit per-path/route hostnames still take precedence, and that WithDefaultBackend(...) remains an unscoped catch-all rule (including its TLS compatibility rule). Triggered by the pr_body_has_user_facing_section signal from the source PR's "User-facing usage" section.

Note

This draft PR needs human review before merging.

@github-actions

Copy link
Copy Markdown
Contributor

⚠️ CI Failure Analysis: Possible Flaky Test(s)

The CI build failed due to test failure(s) that appear unrelated to the PR changes. These may be flaky tests.

Suspected flaky test(s):

Suggested actions:

  • Re-run the failed CI jobs to confirm if the failure is intermittent
  • If the test continues to fail, consider quarantining it using /quarantine-test <test name> <issue URL>
  • Search existing issues to see if this test is already known to be flaky

You can re-run the failed jobs from the workflow run page.

This branch was previously deployed

1 inactive deployment
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Kubernetes ingress WithHostname with parameter is hardcoding the hostname and doesn't add the hostname to the rules

4 participants