Goma Gateway Kubernetes Provider
2.4K
A lightweight sidecar that watches Kubernetes Route and Middleware custom
resources (defined by Goma Operator) and materializes them
into a config bundle on disk that Goma Gateway
consumes via its file provider.
It runs alongside the gateway container in the same Pod, giving the gateway
near-instant, restart-free reloads whenever a Route/Middleware changes.
flowchart TB
subgraph Pod["Gateway Pod"]
direction LR
Gateway["goma-gateway<br/>(file provider)"]
Provider["goma-k8s-provider<br/>(this image)"]
Gateway <-. "shared volume<br/>/etc/goma/..." .-> Provider
end
K8sAPI["Kubernetes API<br/>Route / Middleware CRs<br/>(owned by a Gateway CR)"]
Provider -- "watch" --> K8sAPI
Route and Middleware CRs scoped to a single
Gateway (by name, via GOMA_K8S_GATEWAY).GOMA_K8S_OUTPUT_DIR
(default /etc/goma/providers/k8s), where the gateway's file provider
picks it up and reloads.acme.json) to a Kubernetes Secret, so certificates survive pod
restarts and rescheduling.The sidecar is injected automatically by goma-operator unless disabled via:
spec:
providers:
kubernetes:
enabled: false
All configuration is via environment variables.
| Variable | Required | Default | Description |
|---|---|---|---|
GOMA_K8S_GATEWAY | yes | — | Name of the Gateway CR this sidecar serves. |
GOMA_K8S_NAMESPACE | no | all namespaces | Namespace to watch. Leave empty for cluster-wide. |
GOMA_K8S_OUTPUT_DIR | no | /etc/goma/providers/k8s | Directory where the generated config bundle is written. |
GOMA_K8S_DEBOUNCE_MS | no | 500 | Debounce window for coalescing rapid CR changes (milliseconds). |
GOMA_K8S_ACME_SECRET | no | — | Name of a Secret to mirror acme.json into. Empty disables ACME sync. |
GOMA_K8S_ACME_FILE | no | /etc/letsencrypt/acme.json | Path to the gateway's ACME store inside the shared volume. |
GOMA_K8S_LOG_LEVEL | no | info | One of debug, info, warn, error. |
The sidecar needs read access to routes and middlewares in the watched
namespace(s), plus read/write on the ACME Secret (when ACME sync is
enabled). When installed via goma-operator, these permissions are granted
automatically.
Minimal rules:
- apiGroups: ["gateway.jkaninda.dev"]
resources: ["routes", "middlewares"]
verbs: ["get", "list", "watch"]
- apiGroups: [""]
resources: ["secrets"]
verbs: ["get", "create", "update", "patch"]
The sidecar falls back to $HOME/.kube/config when not running in-cluster:
export GOMA_K8S_GATEWAY=ingress
export GOMA_K8S_NAMESPACE=default
export GOMA_K8S_OUTPUT_DIR=/tmp/goma-k8s
export GOMA_K8S_LOG_LEVEL=debug
go run ./cmd
make build # local binary
make docker-build # container image
This project is licensed under the Apache-2.0.
Copyright 2026 Jonas Kaninda
Content type
Image
Digest
sha256:9f5c561cb…
Size
13.5 MB
Last updated
5 months ago
docker pull jkaninda/goma-k8s-provider