Proxy gRPC Traffic
Learn how to use APISIX or API7 Ingress Controller to configure routes to proxy gRPC traffic.
Google Remote Procedure Call (gRPC) is an open-source, high-performance RPC framework built on the HTTP/2 protocol and using Protocol Buffers (protobuf) as its Interface Description Language (IDL).
This guide will show you how to configure the gateway to proxy gRPC traffic using the Ingress Controller.
Prerequisites
- Complete Set Up Ingress Controller and Gateway.
- Install gRPCurl to verify gRPC traffic proxying.
Start an Example Upstream Service
Create a Kubernetes manifest file for the gRPC server deployment and service:
apiVersion: apps/v1
kind: Deployment
metadata:
namespace: aic
name: grpc-service
spec:
replicas: 1
selector:
matchLabels:
app: grpc-service
template:
metadata:
labels:
app: grpc-service
spec:
containers:
- name: grpc-service
image: api7/grpc-server-example:1.0.0
ports:
- containerPort: 50051
---
apiVersion: v1
kind: Service
metadata:
namespace: aic
name: grpc-service
spec:
type: ClusterIP
selector:
app: grpc-service
ports:
- name: grpc
port: 50051
targetPort: 50051Apply the configuration to your cluster:
kubectl apply -f grpc-server.yamlTo verify whether the gRPC server is running, first, port forward the gRPC server's service port to your local machine:
kubectl port-forward svc/grpc-service 50051:50051 &Send a request to the service to list all available gRPC services and methods:
grpcurl -plaintext 127.0.0.1:50051 listIf everything is ok, you should see the following response:
grpc.reflection.v1alpha.ServerReflection
helloworld.Greeter
helloworld.TestImportList all the available methods for the helloworld.Greeter service:
grpcurl -plaintext 127.0.0.1:50051 list helloworld.GreeterIf everything is ok, you should see the following response:
helloworld.Greeter.GetErrResp
helloworld.Greeter.Plus
helloworld.Greeter.SayHello
helloworld.Greeter.SayHelloAfterDelay
helloworld.Greeter.SayHelloBidirectionalStream
helloworld.Greeter.SayHelloClientStream
helloworld.Greeter.SayHelloServerStreamCreate a Route
Create a Kubernetes manifest file to configure a GRPCRoute to the gRPC service:
apiVersion: gateway.networking.k8s.io/v1
kind: GRPCRoute
metadata:
namespace: aic
name: grpc-route
spec:
parentRefs:
- name: apisix
rules:
- matches:
- method:
service: helloworld.Greeter
method: SayHello
backendRefs:
- name: grpc-service
port: 50051Create a Kubernetes manifest file to configure a route to the gRPC service and configure the upstream schema to be grpc:
apiVersion: apisix.apache.org/v2
kind: ApisixUpstream
metadata:
namespace: aic
name: grpc-service
spec:
ingressClassName: apisix
scheme: grpc
---
apiVersion: apisix.apache.org/v2
kind: ApisixRoute
metadata:
namespace: aic
name: grpc-route
spec:
ingressClassName: apisix
http:
- name: helloworld-greeter
match:
paths:
- /helloworld.Greeter/SayHello
methods:
- GET
- POST
backends:
- serviceName: grpc-service
servicePort: 50051Apply the configurations to your cluster:
kubectl apply -f grpc-route.yamlUpdate Gateway Configuration for HTTP/2
By default, the gateway supports TLS-encrypted HTTP/2 on port 9443. For non-encrypted HTTP/2, you can add a new port to the gateway configuration.
In this section, you will be updating the gateway configuration and deployment to support non-encrypted HTTP/2 on 9081.
To update the gateway's HTTP2 configuration, first export all values (including defaults):
helm get values -n aic apisix --all > values.yamlIn the values file, update the following section values as such:
service:
http:
containerPort: 9080
enabled: true
servicePort: 80
additionalContainerPorts:
- port: 9081
enable_http2: trueUpgrade the release:
helm upgrade -n aic apisix apisix/apisix -f values.yamlTo update the gateway's HTTP2 configuration, first export all values (including defaults):
helm get values -n aic api7-ee-3-gateway --all > values.yamlIn the values file, update the following section values as such:
gateway:
http:
enabled: true
ip: 0.0.0.0
servicePort: 80
containerPort: 9080
additionalContainerPorts:
- port: 9081
enable_http2: trueUpgrade the release:
helm upgrade --install -n aic api7-ee-3-gateway api7/gateway -f values.yamlVerify
Download the helloworld.proto file here.
This example uses the helloworld.proto file to ensure the gRPCurl CLI tool aligns the request and response format with the gRPC service definition.
Expose the gateway’s HTTP/2 service port to your local machine:
# replace with your gateway’s service name
kubectl port-forward svc/<gateway-service-name> 9081:9081 &Send a request to the route:
grpcurl -plaintext \
-proto helloworld.proto \
-d '{"name":"World"}' \
"127.0.0.1:9081" \
"helloworld.Greeter.SayHello"You should see the following output:
{
"message": "Hello World"
}