Skip to content

feat(gateway-service): self-hosted HTTP privacy boundary with Kuberne… - #5

Merged
nickjlamb merged 1 commit into
mainfrom
k8s-gateway-service
Aug 9, 2026
Merged

feat(gateway-service): self-hosted HTTP privacy boundary with Kuberne…#5
nickjlamb merged 1 commit into
mainfrom
k8s-gateway-service

Conversation

@nickjlamb

Copy link
Copy Markdown
Owner

…tes deployment

A new surface wrapping PrivacyGateway from @pharmatools/redacta 1.4.0 as a zero-dependency HTTP service, with plain-YAML manifests: a stateless multi-replica gateway (RollingUpdate, HPA 2-10) for redact/reinstate/guard, and a deliberately single-replica session boundary (Recreate) for the protect/release loop — sessions live in pod memory and the multi-replica profile refuses session endpoints rather than failing intermittently. Optional bearer-token auth from a Secret, probes, resource limits, restrictive securityContext, read-only root FS, no-PHI logs.

Verified on a live cluster: zero-downtime rolling update under load, pod-failure recovery, full HPA cycle (2→7→2), session-loss-on-restart semantics, Secret-based auth. Docs: gateway-service/k8s/README.md (kind walkthrough) and docs/KUBERNETES.md (concepts in Redacta terms).

Claude-Session: https://claude.ai/code/session_01NdKLGgtKs6NojsaC335uw4

…tes deployment

A new surface wrapping PrivacyGateway from @pharmatools/redacta 1.4.0 as a
zero-dependency HTTP service, with plain-YAML manifests: a stateless
multi-replica gateway (RollingUpdate, HPA 2-10) for redact/reinstate/guard,
and a deliberately single-replica session boundary (Recreate) for the
protect/release loop — sessions live in pod memory and the multi-replica
profile refuses session endpoints rather than failing intermittently.
Optional bearer-token auth from a Secret, probes, resource limits,
restrictive securityContext, read-only root FS, no-PHI logs.

Verified on a live cluster: zero-downtime rolling update under load,
pod-failure recovery, full HPA cycle (2→7→2), session-loss-on-restart
semantics, Secret-based auth. Docs: gateway-service/k8s/README.md
(kind walkthrough) and docs/KUBERNETES.md (concepts in Redacta terms).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NdKLGgtKs6NojsaC335uw4
@nickjlamb
nickjlamb merged commit d858d2e into main Aug 9, 2026
4 checks passed
@nickjlamb
nickjlamb deleted the k8s-gateway-service branch August 9, 2026 09:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants