Skip to content

Fix Connector Gateway config so the install renders - #1180

Open
tgrunnagle wants to merge 1 commit into
mainfrom
fix-connector-gateway-config
Open

tgrunnagle wants to merge 1 commit into
mainfrom
fix-connector-gateway-config

Conversation

@tgrunnagle

Copy link
Copy Markdown
Contributor

Description

The values example in Configure the Connector Gateway failed helm template because it had no authServer section. This PR rewrites the page so the install renders and the gateway starts.

configure-connector-gateway.mdx:

  • Prerequisites: Redis/Valkey is listed as required, since the embedded auth server stores sessions only in Redis at any replica count. The directory's KEK, gRPC TLS, NetworkPolicy, and BYPASSRLS admin role are listed with links to where Deploy the platform covers them.
  • Prepare the gateway's secrets: commands for the gateway KEK, auth server keys, and a CA-only directory bundle, with a warning that generate: true doesn't work with GitOps.
  • Values example: adds enterpriseConfig.authServer (schema_version, allowed_audiences, storage.type: redis), vmcpConfig.incomingAuth, enterpriseConfig.directory.addr on the TLS port, directoryTLS, kek, and authServerKeys.
  • Connect the gateway to the directory: how the gateway's TLS pairs with enterprise-manager.grpc.tls, clusterOidcIssuer, and the three caller allowlists, plus the dev-only insecure option.
  • Gateway ID: states that connectorGatewayId must be unique per install.
  • Corporate identity provider settings: clientClaim, clientClaimAllowUnsafe, allowPrivateIps, and caBundleRef, with the warning that the control-plane token validator trusts only the bundle, so it needs the full chain.
  • API name: "the directory API" is now the Enterprise Manager API, linked to the API reference.
  • Troubleshooting: a pod that stays unready, organized by the error in the logs.

Two things go beyond the issue's list:

  • credentialSaSubjectAllowlist: the render fails without it once caller auth is on. The chart's values comment saying the gateway doesn't use it is out of date.
  • vmcpConfig.incomingAuth: helm template doesn't check it, but the gateway refuses to start unless it is oidc with an issuer and audience matching the auth server.

deployment.mdx: adds a Connector Gateway row to the global.redis table and fixes one sentence that listed only the flag, ID, and issuer as requirements.

Verification: I rendered the umbrella chart from stacklok-enterprise-platform main with the page's own YAML blocks, placeholders filled in. The page's current values reproduce the error in the issue, and the new values render with no errors. The dev-only insecure variant renders too. I checked the rendered ServiceAccount name, the Enterprise Manager Service ports (9091/9443), the gateway pod labels, and the projected Redis and bindingClaims config against the page. npm run build passes with no broken links.

Type of change

  • Documentation update

Related issues/PRs

Closes #1176 (part of #1175)

Submitter checklist

Content and formatting

  • I have reviewed the content for technical accuracy
  • I have reviewed the content for spelling, grammar, and style

Reviewer checklist

Content

  • I have reviewed the content for technical accuracy
  • I have reviewed the content for spelling, grammar, and style

🤖 Generated with Claude Code

The values example on the configure page failed helm template because
it omitted the required authServer section. Add the auth server, Redis
storage, key material, and directory TLS settings, the Enterprise
Manager caller allowlists, the primaryIdp keys the gateway reads, and
a troubleshooting section for an unready pod.

Closes #1176

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs-website Ready Ready Preview Sep 29, 2026 1:23pm UTC

Request Review

This branch was successfully deployed

1 active deployment
Preview — 644b6bb8 Deployed Sep 29, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Connector Gateway: fix configure page so the install renders

1 participant