Skip to content

feat: CRD changes to support routing API in the operator - #142

Draft
k-wall wants to merge 9 commits into
kroxylicious:mainfrom
k-wall:kube-api-routing
Draft

k-wall wants to merge 9 commits into
kroxylicious:mainfrom
k-wall:kube-api-routing

Conversation

@k-wall

@k-wall k-wall commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Summary

Draft proposal for the Kubernetes CRD changes needed to support the routing API (proposal 070) in the Kroxylicious operator.

Addresses kroxylicious/kroxylicious#4430.

Key decisions

  • New KafkaProtocolRouter CRD (namespace-scoped, no proxyRef, consistent with KafkaProtocolFilter)
  • Routes declared inline within KafkaProtocolRouter, each with an explicit stable id, filterRefs, and a targetRef discriminated union (KafkaService | KafkaProtocolRouter)
  • VirtualKafkaCluster gains a targetRef field (same union); existing targetKafkaServiceRef is deprecated with a condition warning
  • Mutual exclusion of targetRef/targetKafkaServiceRef enforced via oneOf in the CRD OpenAPI schema
  • Route id uniqueness, non-negativity, and contiguity enforced via CEL validation rules
  • Cycle detection in the router DAG reported as conditions on each router in the cycle
  • KroxyliciousSidecarConfig extension is out of scope

Test plan

  • Review proposal for correctness and completeness
  • Agree on any open questions before implementation begins

🤖 Generated with Claude Code

k-wall and others added 4 commits October 9, 2026 10:18
Draft proposal for the KafkaProtocolRouter CRD and VirtualKafkaCluster
changes needed to support the routing API (proposal 070) in the operator.
Addresses kroxylicious/kroxylicious#4430.

Assisted-by: Claude Sonnet 4.6 <[email protected]>
Signed-off-by: Keith Wall <[email protected]>
Assisted-by: Claude Sonnet 4.6 <[email protected]>
Signed-off-by: Keith Wall <[email protected]>
- Use DeprecationWarning (from Condition.Type) instead of made-up DeprecatedField
  for the targetKafkaServiceRef deprecation condition on VKC
- KafkaProtocolRouter now follows the same ResolvedRefs-only pattern as
  KafkaProtocolFilter (no Accepted, since a router is not uniquely associated
  with a KafkaProxy)
- Move RouterDAGCycle warning from KafkaProtocolRouter to VirtualKafkaCluster,
  using Accepted: False (cycle is a structural validity problem, not a ref
  resolution failure), consistent with Gateway API conventions
- Split VKC unresolvable-target condition to TargetNotFound reason only;
  RouterDAGCycle now has its own Accepted condition

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
Signed-off-by: Keith Wall <[email protected]>
Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
Signed-off-by: Keith Wall <[email protected]>
k-wall and others added 5 commits October 9, 2026 10:32
…nal routing DAG

- Complete example updated to a two-level tenant→region routing DAG with two
  VKCs sharing the same graph, illustrating both full-graph reuse and sub-graph
  sharing (both tenant routes reference the same region-router)
- New "Router graph reuse" section explains the three reuse modes and the
  no-override constraint, cross-referencing the updated example

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
Signed-off-by: Keith Wall <[email protected]>
… override

Documents three approaches considered for allowing topology reuse with different
leaf KafkaService targets (template CRD, VKC-level substitution map, KPR
inheritance) and explains why each was rejected.

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
Signed-off-by: Keith Wall <[email protected]>
…ssplane evidence

- Adds context from Cluster API ClusterClass and Crossplane Compositions showing
  that every mature Kubernetes solution reaches for field path strings or code
- Explains CAPI's clean two-layer separation (template controller stamps out
  concrete resources; infrastructure controllers reconcile normally) and why
  collapsing that into one reconciler is an ugly mixture
- Notes that a single mixed-concern reconciler goes against the grain of the
  Java Operator SDK's one-reconciler-one-job model
- Ties all three points into the closing rationale for deferring to Kustomize/Helm

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
Signed-off-by: Keith Wall <[email protected]>
Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
Signed-off-by: Keith Wall <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant