Repository navigation
feat: Edit multiple ALB backends and tighten the overview layout - #1617
Conversation
An HTTPProxy rule can hold up to 16 weighted backends, choose a load balancing algorithm, and eject failing endpoints with passive health checks, but the portal only modelled the first backend. Worse, every rules rebuild (HSTS, TLS hostname, Host header) wrote the backend rule back with that one backend, so editing any of them on a weighted pool would have silently dropped the rest. The proxy now carries every backend with its kind, effective weight and raw entry, plus spec.loadBalancer and spec.healthCheck. Rebuilds re-emit every backend as the API returned it, applying a TLS hostname change to the first only; an explicit pool replaces it. Algorithm and health check writes null the keys merge-patch would otherwise leave behind, which the API's CEL rules reject. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A load balancer's pool, how its traffic is split, and how failing endpoints are handled had nowhere to live in the portal. The Backends tab shows the pool's stats, its configured traffic split, and every backend with its transport, weight and share, with add, edit, drain and remove. Backends are public origins or Datum compute services; connector and VPC backends are shown and weighted but not recreated. The algorithm is chosen from a Select, and passive health checks are edited in a card that says plainly they act within a backend, not across them. The pool is read-only where the portal can't safely write it: rules or filters it can't round-trip, and load balancers a compute workload publishes, which each deploy replaces. A Host header override across origins on different hostnames is flagged, since every origin would get the same Host. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The single-origin editor and the TLS hostname field describe one backend. On a weighted pool, the Backend pool card now links to the Backends tab instead of opening an editor that would replace the pool, and the TLS hostname is set per backend there. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The overview's health strip and the ALB list counted backends from the proxy's endpoint URLs, so a pool of two origins and a compute service read as 2 backends, and the Configuration tab's pool card left the compute backend off its list. Both now read the whole pool, and the card names a backend without a URL by its service, marked with its kind. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
On staging an HTTPProxy's healthCheck reaches a BackendTrafficPolicy but never the edge's Envoy clusters: no tenant cluster reports any outlier-detection stats, and a test failing one of three compute instances left it serving a full third of traffic through 131 5xx. Offering the setting would promise ejection the platform doesn't do. The Health checks card and the outlier detection stat now sit behind SHOW_HEALTH_CHECKS, off for now, and the stat row drops to three cards. The model, writes and dialog stay, so turning it back on is one line. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…rkService A compute backend showed its NetworkService name, a "Compute" chip and "NetworkService · port http", none of which a user creates or sees; the workload is what they deployed. Workload backends now take the workload's name, linked to its page when the compute plugin is mounted, a "Workload" chip, and a line saying what runs behind it: healthy instances, locations and the port number, read from the service's status. Their transport reads "Private network", VPC backends drop the EndpointSlice wording, and the add dialog's compute field is "Workload" and lists workloads by name. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Workload and VPC-instance backends are reached over the Network their instances attach to, which the portal names Galactic VPC. Say so, rather than the generic "private network", and give instance backends an "Instance" chip so the row doesn't say VPC twice. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Compute deploys now keep an HTTPProxy's configuration and only repoint the workload's own backend (datum-cloud/compute#395), so the Backends tab no longer needs to be read-only for them. The pool, weights and algorithm are editable. The workload's own backend keeps its target locked, since each deploy resets it, and can't be removed, since each deploy adds it back; its weight can still change. The overview describes a multi-backend workload ALB as a pool.
Backends - Model every backend on the backend rule (URL or NetworkService, with weight, TLS hostname, connector) plus spec.loadBalancer and spec.healthCheck. - Replace the single-origin dialog with a backends editor: compact rows for URL and NetworkService backends, weights with live traffic share, load-balancing algorithm (incl. consistent hash on source IP or a header), and passive health checks. - Fix a data-loss bug: any rules edit (origin, redirect, HSTS, Host header, TLS hostname) rewrote the rule with only the first backend. Rebuilds now keep every backend, and routing the portal cannot round-trip (several backend rules, instance backends, non-catch-all matches, custom filters) is classed advanced and refused. - Clear stale consistentHash / header fields explicitly so a merge patch doesn't leave values the API forbids. - Refuse a rules rebuild when the current proxy isn't loaded. - Unlock backend editing for compute-created ALBs. - Backend card lists weights, share of traffic, algorithm, health checks, and NetworkService health. Overview layout - Two columns: hostnames, backends, and the request feed on the left; traffic chart, stat tiles, and locations on the right. - Default hostname leads the hostnames card; custom hostnames sit under it with an Add hostname action. - Range picker moves into the Live traffic header. - Page padding 36px -> 24px and tighter header spacing app-wide, with the negative-margin offsets that depend on it updated.
🧪 Test Summary
Need another run? Use Re-run failed jobs: one shard costs a few minutes, the whole workflow about 26. 📎 Failure artifactsVideos and screenshots from failed E2E tests: |
🧪 Test Summary
Need another run? Use Re-run failed jobs: one shard costs a few minutes, the whole workflow about 26. |
Take the Backends tab, backend pool model, and save path from feat/alb-backend-pool, and keep this branch's overview layout and app-wide padding. - Drop this branch's backends dialog and form; the overview's backend card now links to the Backends tab for every ALB, with share chips, the algorithm, and a "Backends · N" header for pools. - Port guards onto the pool save path: path-specific backend rules classify as advanced, rules rebuilds on advanced proxies are refused, and a rebuild without the current proxy loaded is refused.
🧪 Test Summary
Need another run? Use Re-run failed jobs: one shard costs a few minutes, the whole workflow about 26. 📎 Failure artifactsVideos and screenshots from failed E2E tests: |
- Add domain and Add ALB on the project home page open their create dialogs in place instead of linking to the list page with ?action=create. Each navigates to the new resource once created. - Home column add actions accept either a link or a click handler. - Give the Add domain dialog the same width as the Add ALB dialog.
🧪 Test Summary
Need another run? Use Re-run failed jobs: one shard costs a few minutes, the whole workflow about 26. |
Summary
The portal could show only one ALB backend, and any routing edit rewrote the rule with just the first backend, silently dropping the rest.
Users can now edit every backend in one dialog, with URLs and NetworkServices side by side, weights, a load-balancing algorithm, and passive health checks. Routing the portal cannot save back intact is locked with a note to use datumctl.
The overview also moves to a two-column layout with the default hostname first, and page padding is tighter across the app.
Screencast.From.2026-10-02.17-07-05.mp4
Screencast.From.2026-10-02.17-08-04.mp4
Test plan
Related to datum-cloud/enhancements#744
Related to datum-cloud/enhancements#291