Skip to content

feat: Edit multiple ALB backends and tighten the overview layout - #1617

Merged
kevwilliams merged 13 commits into
mainfrom
feat/alb-multi-backend-overview
Oct 3, 2026
Merged

kevwilliams merged 13 commits into
mainfrom
feat/alb-multi-backend-overview

Conversation

@kevwilliams

@kevwilliams kevwilliams commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The portal could show only one ALB backend, and any routing edit rewrote the rule with just the first backend, silently dropping the rest.

Users can now edit every backend in one dialog, with URLs and NetworkServices side by side, weights, a load-balancing algorithm, and passive health checks. Routing the portal cannot save back intact is locked with a note to use datumctl.

The overview also moves to a two-column layout with the default hostname first, and page padding is tighter across the app.

image
Screencast.From.2026-10-02.17-07-05.mp4
Screencast.From.2026-10-02.17-08-04.mp4

Test plan

  • Add a URL and a NetworkService backend with weights, save, and see the traffic split on the backend card
  • Switch a consistent-hash ALB to round robin and save without an API error
  • Toggle HSTS or force HTTPS on a multi-backend ALB and every backend is still there
  • Unit tests, lint, and typecheck pass

Related to datum-cloud/enhancements#744
Related to datum-cloud/enhancements#291

mattdjenkinson and others added 9 commits September 29, 2026 13:30
An HTTPProxy rule can hold up to 16 weighted backends, choose a load
balancing algorithm, and eject failing endpoints with passive health
checks, but the portal only modelled the first backend. Worse, every
rules rebuild (HSTS, TLS hostname, Host header) wrote the backend rule
back with that one backend, so editing any of them on a weighted pool
would have silently dropped the rest.

The proxy now carries every backend with its kind, effective weight and
raw entry, plus spec.loadBalancer and spec.healthCheck. Rebuilds re-emit
every backend as the API returned it, applying a TLS hostname change to
the first only; an explicit pool replaces it. Algorithm and health check
writes null the keys merge-patch would otherwise leave behind, which the
API's CEL rules reject.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A load balancer's pool, how its traffic is split, and how failing
endpoints are handled had nowhere to live in the portal.

The Backends tab shows the pool's stats, its configured traffic split,
and every backend with its transport, weight and share, with add, edit,
drain and remove. Backends are public origins or Datum compute services;
connector and VPC backends are shown and weighted but not recreated. The
algorithm is chosen from a Select, and passive health checks are edited
in a card that says plainly they act within a backend, not across them.

The pool is read-only where the portal can't safely write it: rules or
filters it can't round-trip, and load balancers a compute workload
publishes, which each deploy replaces. A Host header override across
origins on different hostnames is flagged, since every origin would get
the same Host.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The single-origin editor and the TLS hostname field describe one
backend. On a weighted pool, the Backend pool card now links to the
Backends tab instead of opening an editor that would replace the pool,
and the TLS hostname is set per backend there.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The overview's health strip and the ALB list counted backends from the
proxy's endpoint URLs, so a pool of two origins and a compute service
read as 2 backends, and the Configuration tab's pool card left the
compute backend off its list. Both now read the whole pool, and the card
names a backend without a URL by its service, marked with its kind.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
On staging an HTTPProxy's healthCheck reaches a BackendTrafficPolicy but
never the edge's Envoy clusters: no tenant cluster reports any
outlier-detection stats, and a test failing one of three compute
instances left it serving a full third of traffic through 131 5xx.
Offering the setting would promise ejection the platform doesn't do.

The Health checks card and the outlier detection stat now sit behind
SHOW_HEALTH_CHECKS, off for now, and the stat row drops to three cards.
The model, writes and dialog stay, so turning it back on is one line.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…rkService

A compute backend showed its NetworkService name, a "Compute" chip and
"NetworkService · port http", none of which a user creates or sees; the
workload is what they deployed.

Workload backends now take the workload's name, linked to its page when
the compute plugin is mounted, a "Workload" chip, and a line saying what
runs behind it: healthy instances, locations and the port number, read
from the service's status. Their transport reads "Private network", VPC
backends drop the EndpointSlice wording, and the add dialog's compute
field is "Workload" and lists workloads by name.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Workload and VPC-instance backends are reached over the Network their
instances attach to, which the portal names Galactic VPC. Say so, rather
than the generic "private network", and give instance backends an
"Instance" chip so the row doesn't say VPC twice.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Compute deploys now keep an HTTPProxy's configuration and only repoint
the workload's own backend (datum-cloud/compute#395), so the Backends
tab no longer needs to be read-only for them.

The pool, weights and algorithm are editable. The workload's own
backend keeps its target locked, since each deploy resets it, and
can't be removed, since each deploy adds it back; its weight can still
change. The overview describes a multi-backend workload ALB as a pool.
Backends
- Model every backend on the backend rule (URL or NetworkService, with
  weight, TLS hostname, connector) plus spec.loadBalancer and
  spec.healthCheck.
- Replace the single-origin dialog with a backends editor: compact rows
  for URL and NetworkService backends, weights with live traffic share,
  load-balancing algorithm (incl. consistent hash on source IP or a
  header), and passive health checks.
- Fix a data-loss bug: any rules edit (origin, redirect, HSTS, Host
  header, TLS hostname) rewrote the rule with only the first backend.
  Rebuilds now keep every backend, and routing the portal cannot
  round-trip (several backend rules, instance backends, non-catch-all
  matches, custom filters) is classed advanced and refused.
- Clear stale consistentHash / header fields explicitly so a merge patch
  doesn't leave values the API forbids.
- Refuse a rules rebuild when the current proxy isn't loaded.
- Unlock backend editing for compute-created ALBs.
- Backend card lists weights, share of traffic, algorithm, health
  checks, and NetworkService health.

Overview layout
- Two columns: hostnames, backends, and the request feed on the left;
  traffic chart, stat tiles, and locations on the right.
- Default hostname leads the hostnames card; custom hostnames sit under
  it with an Add hostname action.
- Range picker moves into the Live traffic header.
- Page padding 36px -> 24px and tighter header spacing app-wide, with
  the negative-margin offsets that depend on it updated.
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

🧪 Test Summary

Job Status
Bun Unit Tests ✅ success
E2E Regression (0) ✅ success
E2E Regression (1) ✅ success
E2E Regression (2) ❌ failure
E2E Regression (3) ✅ success ⚠️ passed on retry
E2E Smoke ✅ success
Unit Tests ✅ success

View workflow run

⚠️ 1 e2e job(s) passed only on retry. That is a flake, not a pass; check the first-attempt screenshots in the artifacts.

Need another run? Use Re-run failed jobs: one shard costs a few minutes, the whole workflow about 26.

📎 Failure artifacts

Videos and screenshots from failed E2E tests:

  • e2e-regression-artifacts-36949681156-shard-2 – Download
  • e2e-regression-artifacts-36949681156-shard-3 – Download

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

🧪 Test Summary

Job Status
Bun Unit Tests ✅ success
E2E Regression (0) ✅ success
E2E Regression (1) ✅ success
E2E Regression (2) ✅ success
E2E Regression (3) ✅ success
E2E Smoke ✅ success
Unit Tests ✅ success

View workflow run

Need another run? Use Re-run failed jobs: one shard costs a few minutes, the whole workflow about 26.

mattdjenkinson and others added 2 commits October 2, 2026 13:42
Take the Backends tab, backend pool model, and save path from
feat/alb-backend-pool, and keep this branch's overview layout and
app-wide padding.

- Drop this branch's backends dialog and form; the overview's backend
  card now links to the Backends tab for every ALB, with share chips,
  the algorithm, and a "Backends · N" header for pools.
- Port guards onto the pool save path: path-specific backend rules
  classify as advanced, rules rebuilds on advanced proxies are refused,
  and a rebuild without the current proxy loaded is refused.
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

🧪 Test Summary

Job Status
Bun Unit Tests ✅ success
E2E Regression (0) ✅ success
E2E Regression (1) ✅ success
E2E Regression (2) ❌ failure
E2E Regression (3) ✅ success
E2E Smoke ✅ success ⚠️ passed on retry
Unit Tests ✅ success

View workflow run

⚠️ 1 e2e job(s) passed only on retry. That is a flake, not a pass; check the first-attempt screenshots in the artifacts.

Need another run? Use Re-run failed jobs: one shard costs a few minutes, the whole workflow about 26.

📎 Failure artifacts

Videos and screenshots from failed E2E tests:

  • e2e-regression-artifacts-37056683232-shard-2 – Download
  • e2e-smoke-artifacts-37056683232 – Download

- Add domain and Add ALB on the project home page open their create
  dialogs in place instead of linking to the list page with
  ?action=create. Each navigates to the new resource once created.
- Home column add actions accept either a link or a click handler.
- Give the Add domain dialog the same width as the Add ALB dialog.
@kevwilliams
kevwilliams marked this pull request as ready for review October 3, 2026 00:11
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown

🧪 Test Summary

Job Status
Bun Unit Tests ✅ success
E2E Regression (0) ✅ success
E2E Regression (1) ✅ success
E2E Regression (2) ✅ success ⚠️ passed on retry
E2E Regression (3) ✅ success
E2E Smoke ✅ success
Unit Tests ✅ success

View workflow run

⚠️ 1 e2e job(s) passed only on retry. That is a flake, not a pass; check the first-attempt screenshots in the artifacts.

Need another run? Use Re-run failed jobs: one shard costs a few minutes, the whole workflow about 26.

@kevwilliams
kevwilliams merged commit 5bf55b5 into main Oct 3, 2026
19 checks passed
@kevwilliams
kevwilliams deleted the feat/alb-multi-backend-overview branch October 3, 2026 16:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants