MinIO ClusterIP service listens on port 80 (targetPort 9000). Config had port 9000 which caused 30s timeout then 502 — gateway connected to service port 9000 which doesn't exist on the ClusterIP. Changes: - configmap.yaml: S3 upstream :9000 → :80 - gateway-config-secret.enc.yaml: same - network-policy.yaml: add port 80 egress to storage namespace Verified: S3 adapter now reaches MinIO (403 AccessDenied = auth issue, not connectivity).
This commit is contained in:
+1
-1
@@ -113,7 +113,7 @@ data:
|
|||||||
|
|
||||||
- serviceName: s3
|
- serviceName: s3
|
||||||
upstream:
|
upstream:
|
||||||
url: http://minio.storage.svc.cluster.local:9000
|
url: http://minio.storage.svc.cluster.local:80
|
||||||
timeoutSeconds: 30
|
timeoutSeconds: 30
|
||||||
auth:
|
auth:
|
||||||
required: false
|
required: false
|
||||||
|
|||||||
@@ -91,7 +91,7 @@ stringData:
|
|||||||
upstreamPath: /memory/skills
|
upstreamPath: /memory/skills
|
||||||
- serviceName: s3
|
- serviceName: s3
|
||||||
upstream:
|
upstream:
|
||||||
url: http://minio.storage.svc.cluster.local:9000
|
url: http://minio.storage.svc.cluster.local:80
|
||||||
timeoutSeconds: 30
|
timeoutSeconds: 30
|
||||||
auth:
|
auth:
|
||||||
required: false
|
required: false
|
||||||
|
|||||||
@@ -123,10 +123,14 @@ spec:
|
|||||||
- protocol: TCP
|
- protocol: TCP
|
||||||
port: 8080
|
port: 8080
|
||||||
# Allow to MinIO (S3-compatible storage)
|
# Allow to MinIO (S3-compatible storage)
|
||||||
|
# Service `minio` listens on port 80 (targetPort 9000).
|
||||||
|
# Headless `minio-cluster-hl` is 9000. Allow both.
|
||||||
- to:
|
- to:
|
||||||
- namespaceSelector:
|
- namespaceSelector:
|
||||||
matchLabels:
|
matchLabels:
|
||||||
kubernetes.io/metadata.name: storage
|
kubernetes.io/metadata.name: storage
|
||||||
ports:
|
ports:
|
||||||
|
- protocol: TCP
|
||||||
|
port: 80
|
||||||
- protocol: TCP
|
- protocol: TCP
|
||||||
port: 9000
|
port: 9000
|
||||||
|
|||||||
Reference in New Issue
Block a user