Header
Specify a set of headers which incoming requests must match in entirety.
For more information, see the Kubernetes Gateway API documentation.
Before you begin
-
Follow the Get started guide to install K8sGateway, set up a gateway resource, and deploy the httpbin sample app.
-
Get the external address of the gateway and save it in an environment variable.
export INGRESS_GW_ADDRESS=$(kubectl get svc -n gloo-system gloo-proxy-http -o jsonpath="{.status.loadBalancer.ingress[0]['hostname','ip']}") echo $INGRESS_GW_ADDRESS
kubectl port-forward deployment/gloo-proxy-http -n gloo-system 8080:8080
Set up header matching
-
Create an HTTPRoute resource.
kubectl apply -f- <<EOF apiVersion: gateway.networking.k8s.io/v1 kind: HTTPRoute metadata: name: httpbin-match namespace: httpbin spec: parentRefs: - name: http namespace: gloo-system hostnames: - match.example rules: - matches: - headers: - name: version value: v2 type: Exact backendRefs: - name: httpbin port: 8000 EOF
-
Send a request to the httpbin app on the
match.example
domain without any headers. Verify that you get back a 404 HTTP response code as no matching request could be found.curl -vik http://$INGRESS_GW_ADDRESS:8080/status/200 -H "host: match.example:8080"
curl -vik localhost:8080/status/200 -H "host: match.example"
Example output:
* Mark bundle as not supporting multiuse < HTTP/1.1 404 Not Found HTTP/1.1 404 Not Found < date: Sat, 04 Nov 2023 03:16:43 GMT date: Sat, 04 Nov 2023 03:16:43 GMT < server: envoy server: envoy < content-length: 0 content-length: 0
-
Send another request to the httpbin app on the
match.example
domain. This time, add theversion: v2
header that you configured in the HTTPRoute. Verify that your request now succeeds and you get back a 200 HTTP response code.curl -vik http://$INGRESS_GW_ADDRESS:8080/status/200 -H "host: match.example:8080" -H "version: v2"
curl -vik localhost:8080/status/200 -H "host: match.example" -H "version: v2"
Example output:
* Mark bundle as not supporting multiuse < HTTP/1.1 200 OK HTTP/1.1 200 OK < access-control-allow-credentials: true access-control-allow-credentials: true < access-control-allow-origin: * access-control-allow-origin: * < date: Sat, 04 Nov 2023 03:19:26 GMT date: Sat, 04 Nov 2023 03:19:26 GMT < content-length: 0 content-length: 0 < x-envoy-upstream-service-time: 1 x-envoy-upstream-service-time: 1 < server: envoy server: envoy
Cleanup
You can remove the resources that you created in this guide.kubectl delete httproute httpbin-match -n httpbin