From 5c909f5d777b97b060ca90136735a87f122311ac Mon Sep 17 00:00:00 2001 From: Alphaxiaoteng <230277249+Alphaxiaoteng@users.noreply.github.com> Date: Thu, 3 Sep 2026 19:18:55 +0800 Subject: [PATCH] fix(helm): make Service port name/appProtocol/containerPort configurable for Istio Hardcoded Service port name `http` triggers Istio auto protocol selection and breaks some mesh installs. Allow portName/appProtocol/containerPort overrides while keeping the previous defaults. --- helm/litellm-helm/templates/deployment.yaml | 4 ++-- helm/litellm-helm/templates/service.yaml | 7 +++++-- helm/litellm-helm/values.yaml | 7 +++++++ helm/litellm/templates/backend/deployment.yaml | 4 ++-- helm/litellm/templates/backend/service.yaml | 7 +++++-- helm/litellm/templates/gateway/deployment.yaml | 4 ++-- helm/litellm/templates/gateway/service.yaml | 7 +++++-- helm/litellm/templates/ui/deployment.yaml | 4 ++-- helm/litellm/templates/ui/service.yaml | 7 +++++-- helm/litellm/values.yaml | 16 ++++++++++++++++ 10 files changed, 51 insertions(+), 16 deletions(-) diff --git a/helm/litellm-helm/templates/deployment.yaml b/helm/litellm-helm/templates/deployment.yaml index 52ffd117535..b61eb32469d 100644 --- a/helm/litellm-helm/templates/deployment.yaml +++ b/helm/litellm-helm/templates/deployment.yaml @@ -186,8 +186,8 @@ spec: {{- end }} {{- end }} ports: - - name: http - containerPort: {{ .Values.service.port }} + - name: {{ .Values.service.portName | default "http" }} + containerPort: {{ .Values.service.containerPort | default .Values.service.port }} protocol: TCP livenessProbe: httpGet: diff --git a/helm/litellm-helm/templates/service.yaml b/helm/litellm-helm/templates/service.yaml index 11812208929..11eb9c982dc 100644 --- a/helm/litellm-helm/templates/service.yaml +++ b/helm/litellm-helm/templates/service.yaml @@ -15,8 +15,11 @@ spec: {{- end }} ports: - port: {{ .Values.service.port }} - targetPort: http + targetPort: {{ .Values.service.portName | default "http" }} protocol: TCP - name: http + name: {{ .Values.service.portName | default "http" }} + {{- with .Values.service.appProtocol }} + appProtocol: {{ . }} + {{- end }} selector: {{- include "litellm.selectorLabels" . | nindent 4 }} diff --git a/helm/litellm-helm/values.yaml b/helm/litellm-helm/values.yaml index 637be2322e3..489a0e7d84c 100644 --- a/helm/litellm-helm/values.yaml +++ b/helm/litellm-helm/values.yaml @@ -85,6 +85,13 @@ environmentConfigMaps: service: type: ClusterIP port: 4000 + # Istio auto protocol selection uses the Service port name. Use "tcp" + # (and optionally appProtocol: tcp) for mesh installs that must not treat + # this port as HTTP. + portName: http + appProtocol: "" + # Container listen port. Defaults to service.port when empty/omitted. + containerPort: "" # If service type is `LoadBalancer` you can # optionally specify loadBalancerClass # loadBalancerClass: tailscale diff --git a/helm/litellm/templates/backend/deployment.yaml b/helm/litellm/templates/backend/deployment.yaml index 0db2f0b3d43..13fada8439d 100644 --- a/helm/litellm/templates/backend/deployment.yaml +++ b/helm/litellm/templates/backend/deployment.yaml @@ -50,8 +50,8 @@ spec: {{- toYaml . | nindent 12 }} {{- end }} ports: - - name: http - containerPort: 4001 + - name: {{ .Values.backend.service.portName | default "http" }} + containerPort: {{ .Values.backend.service.containerPort | default .Values.backend.service.port }} protocol: TCP env: {{- include "litellm.serverEnv" (dict "root" $ "component" .Values.backend) | nindent 12 }} diff --git a/helm/litellm/templates/backend/service.yaml b/helm/litellm/templates/backend/service.yaml index d480c654784..ef791ee95f7 100644 --- a/helm/litellm/templates/backend/service.yaml +++ b/helm/litellm/templates/backend/service.yaml @@ -10,9 +10,12 @@ spec: type: {{ .Values.backend.service.type }} ports: - port: {{ .Values.backend.service.port }} - targetPort: http + targetPort: {{ .Values.backend.service.portName | default "http" }} protocol: TCP - name: http + name: {{ .Values.backend.service.portName | default "http" }} + {{- with .Values.backend.service.appProtocol }} + appProtocol: {{ . }} + {{- end }} selector: {{- include "litellm.backend.selectorLabels" . | nindent 4 }} {{- end }} diff --git a/helm/litellm/templates/gateway/deployment.yaml b/helm/litellm/templates/gateway/deployment.yaml index 5030ba2c9dc..b0cc8cd604d 100644 --- a/helm/litellm/templates/gateway/deployment.yaml +++ b/helm/litellm/templates/gateway/deployment.yaml @@ -48,8 +48,8 @@ spec: {{- toYaml . | nindent 12 }} {{- end }} ports: - - name: http - containerPort: 4000 + - name: {{ .Values.gateway.service.portName | default "http" }} + containerPort: {{ .Values.gateway.service.containerPort | default .Values.gateway.service.port }} protocol: TCP env: {{- include "litellm.serverEnv" (dict "root" $ "component" .Values.gateway) | nindent 12 }} diff --git a/helm/litellm/templates/gateway/service.yaml b/helm/litellm/templates/gateway/service.yaml index 03a4167a0ab..5e9a4f487e8 100644 --- a/helm/litellm/templates/gateway/service.yaml +++ b/helm/litellm/templates/gateway/service.yaml @@ -10,9 +10,12 @@ spec: type: {{ .Values.gateway.service.type }} ports: - port: {{ .Values.gateway.service.port }} - targetPort: http + targetPort: {{ .Values.gateway.service.portName | default "http" }} protocol: TCP - name: http + name: {{ .Values.gateway.service.portName | default "http" }} + {{- with .Values.gateway.service.appProtocol }} + appProtocol: {{ . }} + {{- end }} selector: {{- include "litellm.gateway.selectorLabels" . | nindent 4 }} {{- end }} diff --git a/helm/litellm/templates/ui/deployment.yaml b/helm/litellm/templates/ui/deployment.yaml index b992b347bad..3922caf4907 100644 --- a/helm/litellm/templates/ui/deployment.yaml +++ b/helm/litellm/templates/ui/deployment.yaml @@ -45,8 +45,8 @@ spec: {{- toYaml . | nindent 12 }} {{- end }} ports: - - name: http - containerPort: 3000 + - name: {{ .Values.ui.service.portName | default "http" }} + containerPort: {{ .Values.ui.service.containerPort | default .Values.ui.service.port }} protocol: TCP env: {{- if .Values.ui.logLevel }} diff --git a/helm/litellm/templates/ui/service.yaml b/helm/litellm/templates/ui/service.yaml index 52b539fa00c..bbe229dad81 100644 --- a/helm/litellm/templates/ui/service.yaml +++ b/helm/litellm/templates/ui/service.yaml @@ -10,9 +10,12 @@ spec: type: {{ .Values.ui.service.type }} ports: - port: {{ .Values.ui.service.port }} - targetPort: http + targetPort: {{ .Values.ui.service.portName | default "http" }} protocol: TCP - name: http + name: {{ .Values.ui.service.portName | default "http" }} + {{- with .Values.ui.service.appProtocol }} + appProtocol: {{ . }} + {{- end }} selector: {{- include "litellm.ui.selectorLabels" . | nindent 4 }} {{- end }} diff --git a/helm/litellm/values.yaml b/helm/litellm/values.yaml index 378c3b7a618..33d71b33b1a 100644 --- a/helm/litellm/values.yaml +++ b/helm/litellm/values.yaml @@ -255,6 +255,14 @@ gateway: service: type: ClusterIP port: 4000 + # Service port name used for targetPort/container port name matching. + # Istio auto protocol selection treats a port named "http" as HTTP; set + # this to "tcp" (and optionally appProtocol: tcp) for mesh installs. + portName: http + # Optional Kubernetes appProtocol on the Service port. + appProtocol: "" + # Container listen port. Defaults to service.port when empty/omitted. + containerPort: "" resources: requests: cpu: "1" @@ -376,6 +384,10 @@ backend: service: type: ClusterIP port: 4001 + # See gateway.service.portName / appProtocol / containerPort. + portName: http + appProtocol: "" + containerPort: "" resources: requests: cpu: "1" @@ -442,6 +454,10 @@ ui: service: type: ClusterIP port: 3000 + # See gateway.service.portName / appProtocol / containerPort. + portName: http + appProtocol: "" + containerPort: "" # The dashboard expects to know where to reach the backend API. Set this to # the externally-routable URL (typically the ingress host + /api or similar). backendUrl: ""