feat(blink-lnurl-server): add ingress.annotations passthrough - #9352
Open
pretyflaco wants to merge 1 commit into
Open
feat(blink-lnurl-server): add ingress.annotations passthrough#9352pretyflaco wants to merge 1 commit into
pretyflaco wants to merge 1 commit into
Conversation
Allows attaching nginx ingress annotations (e.g. server-snippet for path-scoped rate limiting of /verify/*) via values, without forking the vendored chart. cert-manager.io/cluster-issuer remains the default.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Add an optional
ingress.annotationspassthrough to theblink-lnurl-serverchart so operators can attach nginx ingress annotations via values, without forking the vendored chart.Motivation
We need to apply path-scoped rate limiting to
lnurl.blink.sv/verify/*(see blinkbitcoin/blink-wip#1123 — runaway LUD-21 verify polling from BTCPay plugins). The rate limit is implemented as an ingress-nginxserver-snippetannotation on the lnurl-server Ingress, but the chart currently hardcodes its annotations block with no passthrough.Change
templates/ingress.yaml: merge.Values.ingress.annotationsunder the existingcert-manager.io/cluster-issuerdefault.values.yaml: document the newingress.annotationsfield (default{}).Fully backward-compatible: when
ingress.annotationsis unset the rendered manifest is unchanged.Validation
Rendered locally with
helm template:The companion
blinkbitcoin/blink-deploymentschange (staging) wires the actual rate-limit zone + snippet.