fix(helm): make Service port name/appProtocol/containerPort configurable for Istio

Hardcoded Service port name `http` triggers Istio auto protocol selection and
breaks some mesh installs. Allow portName/appProtocol/containerPort overrides
while keeping the previous defaults.
This commit is contained in:
Alphaxiaoteng 2026-09-03 19:18:55 +08:00
parent 658f50663d
commit 5c909f5d77
10 changed files with 51 additions and 16 deletions

View file

@ -186,8 +186,8 @@ spec:
{{- end }}
{{- end }}
ports:
- name: http
containerPort: {{ .Values.service.port }}
- name: {{ .Values.service.portName | default "http" }}
containerPort: {{ .Values.service.containerPort | default .Values.service.port }}
protocol: TCP
livenessProbe:
httpGet:

View file

@ -15,8 +15,11 @@ spec:
{{- end }}
ports:
- port: {{ .Values.service.port }}
targetPort: http
targetPort: {{ .Values.service.portName | default "http" }}
protocol: TCP
name: http
name: {{ .Values.service.portName | default "http" }}
{{- with .Values.service.appProtocol }}
appProtocol: {{ . }}
{{- end }}
selector:
{{- include "litellm.selectorLabels" . | nindent 4 }}

View file

@ -85,6 +85,13 @@ environmentConfigMaps:
service:
type: ClusterIP
port: 4000
# Istio auto protocol selection uses the Service port name. Use "tcp"
# (and optionally appProtocol: tcp) for mesh installs that must not treat
# this port as HTTP.
portName: http
appProtocol: ""
# Container listen port. Defaults to service.port when empty/omitted.
containerPort: ""
# If service type is `LoadBalancer` you can
# optionally specify loadBalancerClass
# loadBalancerClass: tailscale

View file

@ -50,8 +50,8 @@ spec:
{{- toYaml . | nindent 12 }}
{{- end }}
ports:
- name: http
containerPort: 4001
- name: {{ .Values.backend.service.portName | default "http" }}
containerPort: {{ .Values.backend.service.containerPort | default .Values.backend.service.port }}
protocol: TCP
env:
{{- include "litellm.serverEnv" (dict "root" $ "component" .Values.backend) | nindent 12 }}

View file

@ -10,9 +10,12 @@ spec:
type: {{ .Values.backend.service.type }}
ports:
- port: {{ .Values.backend.service.port }}
targetPort: http
targetPort: {{ .Values.backend.service.portName | default "http" }}
protocol: TCP
name: http
name: {{ .Values.backend.service.portName | default "http" }}
{{- with .Values.backend.service.appProtocol }}
appProtocol: {{ . }}
{{- end }}
selector:
{{- include "litellm.backend.selectorLabels" . | nindent 4 }}
{{- end }}

View file

@ -48,8 +48,8 @@ spec:
{{- toYaml . | nindent 12 }}
{{- end }}
ports:
- name: http
containerPort: 4000
- name: {{ .Values.gateway.service.portName | default "http" }}
containerPort: {{ .Values.gateway.service.containerPort | default .Values.gateway.service.port }}
protocol: TCP
env:
{{- include "litellm.serverEnv" (dict "root" $ "component" .Values.gateway) | nindent 12 }}

View file

@ -10,9 +10,12 @@ spec:
type: {{ .Values.gateway.service.type }}
ports:
- port: {{ .Values.gateway.service.port }}
targetPort: http
targetPort: {{ .Values.gateway.service.portName | default "http" }}
protocol: TCP
name: http
name: {{ .Values.gateway.service.portName | default "http" }}
{{- with .Values.gateway.service.appProtocol }}
appProtocol: {{ . }}
{{- end }}
selector:
{{- include "litellm.gateway.selectorLabels" . | nindent 4 }}
{{- end }}

View file

@ -45,8 +45,8 @@ spec:
{{- toYaml . | nindent 12 }}
{{- end }}
ports:
- name: http
containerPort: 3000
- name: {{ .Values.ui.service.portName | default "http" }}
containerPort: {{ .Values.ui.service.containerPort | default .Values.ui.service.port }}
protocol: TCP
env:
{{- if .Values.ui.logLevel }}

View file

@ -10,9 +10,12 @@ spec:
type: {{ .Values.ui.service.type }}
ports:
- port: {{ .Values.ui.service.port }}
targetPort: http
targetPort: {{ .Values.ui.service.portName | default "http" }}
protocol: TCP
name: http
name: {{ .Values.ui.service.portName | default "http" }}
{{- with .Values.ui.service.appProtocol }}
appProtocol: {{ . }}
{{- end }}
selector:
{{- include "litellm.ui.selectorLabels" . | nindent 4 }}
{{- end }}

View file

@ -255,6 +255,14 @@ gateway:
service:
type: ClusterIP
port: 4000
# Service port name used for targetPort/container port name matching.
# Istio auto protocol selection treats a port named "http" as HTTP; set
# this to "tcp" (and optionally appProtocol: tcp) for mesh installs.
portName: http
# Optional Kubernetes appProtocol on the Service port.
appProtocol: ""
# Container listen port. Defaults to service.port when empty/omitted.
containerPort: ""
resources:
requests:
cpu: "1"
@ -376,6 +384,10 @@ backend:
service:
type: ClusterIP
port: 4001
# See gateway.service.portName / appProtocol / containerPort.
portName: http
appProtocol: ""
containerPort: ""
resources:
requests:
cpu: "1"
@ -442,6 +454,10 @@ ui:
service:
type: ClusterIP
port: 3000
# See gateway.service.portName / appProtocol / containerPort.
portName: http
appProtocol: ""
containerPort: ""
# The dashboard expects to know where to reach the backend API. Set this to
# the externally-routable URL (typically the ingress host + /api or similar).
backendUrl: ""