Skip to content

Add the Serval API and controller for the non-cluster host gateway#5067

Draft
hjiawei wants to merge 1 commit into
tigera:masterfrom
hjiawei:serval-non-cluster-host-gateway
Draft

Add the Serval API and controller for the non-cluster host gateway#5067
hjiawei wants to merge 1 commit into
tigera:masterfrom
hjiawei:serval-non-cluster-host-gateway

Conversation

@hjiawei

@hjiawei hjiawei commented Jul 19, 2026

Copy link
Copy Markdown
Contributor

Description

New feature. Adds the Serval API (operator.tigera.io/v1) and controller. Serval is a layer-7 gateway that becomes the single entrypoint for non-cluster hosts: one HTTPS endpoint serving the impersonating kube-apiserver proxy, the log ingestion routes, and a WebSocket tunnel that carries the felix-typha sync connection. It supersedes the deprecated NonClusterHost resource; NonClusterHost keeps working unchanged as a legacy mode until a later removal release.

The controller renders the gateway Deployment (combined calico image, controlPlaneReplicas with pod anti-affinity, enableServiceLinks: false), a ClusterIP Service, an operator-issued TLS keypair including the external endpoint SAN, RBAC (impersonation, TokenReview/SubjectAccessReview create, get on serviceaccounts for the Tigera-JWT authenticator), and allow-tigera network policies. The fluent-bit input policy admits serval as a source, and the host ClusterRole gains read on servals.

Testing: render unit tests, plus end-to-end validation of the rendered object shapes on a kubeadm Enterprise cluster with a Rocky 9 non-cluster host (felix in sync through the tunnel, apiserver proxy serving the cert-init and token-minting flows, logs flowing to linseed).

Companion PR (calico-private): https://github.com/tigera/calico-private/pull/12765
Design: tigera/designs 2026/serval-non-cluster-host-gateway

Release Note

Added the Serval resource and controller, deploying a layer-7 gateway that is the single entrypoint for non-cluster hosts. NonClusterHost is deprecated.

🤖 Generated with Claude Code

@marvin-tigera marvin-tigera added this to the v1.44.0 milestone Jul 19, 2026
@hjiawei
hjiawei force-pushed the serval-non-cluster-host-gateway branch 2 times, most recently from a5bfb21 to e2c4293 Compare July 19, 2026 16:20
The nonclusterhost controller renders the serval gateway when the NonClusterHost
resource has spec.typhaEndpoint unset; when it is set, the legacy
calico-typha-noncluster-host deployment renders as before. There is no Serval CR,
CRD, or controller — NonClusterHost is the sole resource for the feature.

Both modes share one host identity (the tigera-noncluster-host ServiceAccount)
and one Typha server keypair (typha-certs-noncluster-host, reused by serval's
in-process Typha), so switching modes adds no identity or secret and BYO typha
certs keep working.

A single HostEndpoint-count autoscaler (extracted into a shared typhaautoscaler
package) scales both the serval and calico-typha-noncluster-host deployments to
the same replica count; only one exists at a time. The fluent-bit log-ingestion
input and CSR signing are gated on NonClusterHost presence.

Also syncs the felixconfigurations CRDs from calico master.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@hjiawei
hjiawei force-pushed the serval-non-cluster-host-gateway branch from e2c4293 to 6c9665d Compare July 22, 2026 22:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants