HyperSpace Service Agent for Kubernetes deployments.
2.2K
Primary HyperSpace service workload with REST and CLI endpoints.
Expose services securely through HyperSpace.
This is the Kubernetes runtime image for HyperSpace Service Agent. Use it when the agent will run inside a Kubernetes workload managed by a Helm chart or a manifest. It is not a cluster installer by itself.
Repository: whitestarcommunications/k8s-hyperspaceserviceagent
Current release tag:
0.04.15.26.2If you are writing Helm values or raw manifests, pin the runtime image to:
whitestarcommunications/k8s-hyperspaceserviceagent:0.04.15.26.2This image runs in non-interactive mode. That means:
The workload still needs the normal HyperSpace runtime requirements:
/dev/net/tunNET_ADMINNET_RAWThe current profile contract is:
singleton1ClusterIPinternalhyperspace.whitestar/tun=truePersistent storage must be mounted at:
/var/lib/hyperspace/var/log/hyperspace/root/serviceAgentUse either:
charts/hyperspace-agent//dev/net/tun and grants the required privilegesIf you are applying the image by hand, the pinned reference to set is:
whitestarcommunications/k8s-hyperspaceserviceagent:0.04.15.26.2These checks tell you whether the deployment is healthy:
kubectl -n hyperspace-service-agent rollout status deployment/hyperspace-service-agent
kubectl -n hyperspace-service-agent get pods
kubectl -n hyperspace-service-agent logs deployment/hyperspace-service-agent
kubectl -n hyperspace-service-agent exec deploy/hyperspace-service-agent -- curl -fsS http://127.0.0.1:42587/api/openapi.json
Port-forward the service locally:
kubectl -n hyperspace-service-agent port-forward service/hyperspace-service-agent 42588:42587
Then use:
http://127.0.0.1:42588/api/uicurl http://127.0.0.1:42588/api/openapi.jsonTo print the current identity from inside the pod:
kubectl -n hyperspace-service-agent exec deploy/hyperspace-service-agent -- /bin/bash -lc 'HS_IDENTITY_URL="http://127.0.0.1:42587/api/command/whoAmI" /usr/local/bin/extractIdentityValue.sh'
To move to a newer release, roll the workload to a newer image tag while reusing the same persistent volumes. Identity and state should survive pod replacement through mounted storage, not through pod-local filesystems.
If HyperSpace must manage node-level routes, firewall state, or
NetworkManager-managed DNS, set HS_K8S_NODE_NETWORK_CONTROL=true.
That mode changes the pod contract substantially:
hostNetwork: truehostPID: trueallowPrivilegeEscalation: trueprivileged: trueHS_NETWORK_SETUP_MODE=hostUse that mode deliberately. It is intended for native Linux nodes, or for
kind on Linux when the required host sockets and helpers are available.
whitestarcommunications/k8s-hyperspaceconnectionagent
Create secure outbound HyperSpace connections from this device.whitestarcommunications/k8s-hyperspaceproxyagent
Accept secure inbound HyperSpace traffic and relay it to local services.whitestarcommunications/k8s-hyperspaceserviceagent
Expose services securely through HyperSpace.Content type
Image
Digest
sha256:164b6a130…
Size
292.8 MB
Last updated
6 months ago
docker pull whitestarcommunications/k8s-hyperspaceserviceagent