You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何利用Quarkus的quarkus.openshift.route.annotations配置HTTPS方式暴露OpenShift Route?

Exposing Quarkus App via HTTPS on OpenShift Route

Got it, let's break down how to get your Quarkus application exposed over HTTPS using an OpenShift Route. You don't need to rely solely on annotations for core TLS/port configuration—Quarkus's OpenShift extension has built-in properties that make this straightforward.

1. Use Quarkus OpenShift Extension's Built-in Route Configuration

This is the cleanest approach, as it leverages Quarkus's native configuration for OpenShift resources, no need to hack annotations for basic TLS/port settings. Just add these properties to your application.properties:

# Enable automatic Route creation
quarkus.openshift.route.enabled=true

# Set the target port matching your service's port name
quarkus.openshift.route.target-port=8080-tcp

# Configure TLS settings for HTTPS
quarkus.openshift.route.tls.insecure-edge-termination-policy=Redirect
quarkus.openshift.route.tls.termination=edge

What this does:

  • Enables Quarkus to generate an OpenShift Route automatically during deployment
  • Routes traffic to your app's 8080-tcp port
  • Sets up edge termination (OpenShift handles TLS termination at the Route level)
  • Redirects all HTTP traffic to HTTPS, so users can't access the unencrypted endpoint

If you need to use a custom TLS certificate instead of OpenShift's default, you can add this property to reference a secret containing your cert:

quarkus.openshift.route.tls.certificate-secret=your-custom-cert-secret

2. Manual Route Creation (For Full Control)

If you prefer to define the Route explicitly (e.g., for more complex configurations), you can create a YAML file and have Quarkus apply it during deployment, or apply it manually with oc.

Create a file like src/main/kubernetes/route.yaml with this content:

apiVersion: route.openshift.io/v1
kind: Route
metadata:
  name: my-quarkus-app-route
spec:
  port:
    targetPort: 8080-tcp
  tls:
    insecureEdgeTerminationPolicy: Redirect
    termination: edge
  to:
    kind: Service
    name: ${quarkus.application.name} # Uses your app's service name automatically
    weight: 100

Quarkus will automatically apply any Kubernetes/OpenShift resources in the src/main/kubernetes directory when you run mvn quarkus:deploy. Alternatively, apply it manually with:

oc apply -f src/main/kubernetes/route.yaml

3. Annotations Are For Extra Settings (Not Core TLS/Port)

The annotations you mentioned (like kubernetes.io/tls-acme) are for additional features (e.g., auto-renewing certificates via Let's Encrypt), not for configuring the core port or TLS termination. You can combine these annotations with the above configurations if needed:

quarkus.openshift.route.annotations."kubernetes.io/tls-acme"=true

This would enable ACME certificate management alongside your TLS termination setup.

内容的提问来源于stack exchange,提问作者Bruno Baiano

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 18:17:39