如何利用Quarkus的quarkus.openshift.route.annotations配置HTTPS方式暴露OpenShift Route?
Got it, let's break down how to get your Quarkus application exposed over HTTPS using an OpenShift Route. You don't need to rely solely on annotations for core TLS/port configuration—Quarkus's OpenShift extension has built-in properties that make this straightforward.
1. Use Quarkus OpenShift Extension's Built-in Route Configuration
This is the cleanest approach, as it leverages Quarkus's native configuration for OpenShift resources, no need to hack annotations for basic TLS/port settings. Just add these properties to your application.properties:
# Enable automatic Route creation quarkus.openshift.route.enabled=true # Set the target port matching your service's port name quarkus.openshift.route.target-port=8080-tcp # Configure TLS settings for HTTPS quarkus.openshift.route.tls.insecure-edge-termination-policy=Redirect quarkus.openshift.route.tls.termination=edge
What this does:
- Enables Quarkus to generate an OpenShift Route automatically during deployment
- Routes traffic to your app's
8080-tcpport - Sets up edge termination (OpenShift handles TLS termination at the Route level)
- Redirects all HTTP traffic to HTTPS, so users can't access the unencrypted endpoint
If you need to use a custom TLS certificate instead of OpenShift's default, you can add this property to reference a secret containing your cert:
quarkus.openshift.route.tls.certificate-secret=your-custom-cert-secret
2. Manual Route Creation (For Full Control)
If you prefer to define the Route explicitly (e.g., for more complex configurations), you can create a YAML file and have Quarkus apply it during deployment, or apply it manually with oc.
Create a file like src/main/kubernetes/route.yaml with this content:
apiVersion: route.openshift.io/v1 kind: Route metadata: name: my-quarkus-app-route spec: port: targetPort: 8080-tcp tls: insecureEdgeTerminationPolicy: Redirect termination: edge to: kind: Service name: ${quarkus.application.name} # Uses your app's service name automatically weight: 100
Quarkus will automatically apply any Kubernetes/OpenShift resources in the src/main/kubernetes directory when you run mvn quarkus:deploy. Alternatively, apply it manually with:
oc apply -f src/main/kubernetes/route.yaml
3. Annotations Are For Extra Settings (Not Core TLS/Port)
The annotations you mentioned (like kubernetes.io/tls-acme) are for additional features (e.g., auto-renewing certificates via Let's Encrypt), not for configuring the core port or TLS termination. You can combine these annotations with the above configurations if needed:
quarkus.openshift.route.annotations."kubernetes.io/tls-acme"=true
This would enable ACME certificate management alongside your TLS termination setup.
内容的提问来源于stack exchange,提问作者Bruno Baiano

