TuanDang1996 opened a new issue, #11662:
URL: https://github.com/apache/seatunnel/issues/11662

   ### Search before asking
   
   - [x] I had searched in the 
[issues](https://github.com/apache/seatunnel/issues?q=is%3Aissue+label%3A%22bug%22)
 and found no similar issues.
   
   
   ### What happened
   
   When SeaTunnel Zeta runs on Kubernetes and the Web UI / REST API is exposed 
through Ingress (or any reverse proxy) with a public domain, the job log links 
in the UI / `/logs` response are built with each Hazelcast member's **pod IP**, 
which is not reachable from the browser.
   
   Example (from Web UI / `/logs`):
   
   ```text
   http://10.0.1.167:8080/logs/job-1137316576459685899.log
   ```
   
   Expected (reachable via Ingress):
   
   ```text
   https://domain.com/logs/job-1137316576459685899.log
   ```
   
   **Root cause** (2.3.13 and current `dev`): `LogService` builds absolute URLs 
from the cluster member address / system monitoring `host` field, e.g.:
   
   ```java
   String host = member.getAddress().getHost(); // or systemMonitoring "host"
   String url = "http://"; + host + ":" + nodeHttpPort + contextPath;
   // ...
   url + REST_URL_LOGS + "/" + fileName
   ```
   
   There is **no** `seatunnel.engine.http` option to set a public / advertise 
host or base URL. Available HTTP options today are only things like 
`enable-http`, `port`, `context-path`, auth, and HTTPS keystore settings.
   
   **Notes:**
   - Serving the same file via relative path on the ingress host works, e.g. 
`https://<ingress-host>/logs/job-<id>.log`
   - `/log` (current-node) already uses relative links (`log/<file>`), which 
work behind Ingress
   - `/logs` (all-node / UI job log list) uses absolute member-IP links, which 
break behind Ingress
   
   **Suggested fix direction:**
   1. Add a config such as `seatunnel.engine.http.public-url` / `public-host` 
(and optionally scheme) used when generating `logLink` values, **or**
   2. Prefer relative log links in the Web UI / `/logs` HTML (same style as 
`/log`), so the browser stays on the Ingress host
   
   
   ### SeaTunnel Version
   
   2.3.13
   
   ### SeaTunnel Config
   
   ```conf
   conf
   seatunnel:
     engine:
       history-job-expire-minutes: 1440
       backup-count: 1
       http:
         enable-http: true
         port: 8080
         enable-dynamic-port: false
         enable-basic-auth: true
         # no public-host / public-url option exists today
       telemetry:
         metric:
           enabled: true
   ```
   
   ### Running Command
   
   ```shell
   shell
   # Separated cluster mode
   ./bin/seatunnel-cluster.sh -r master
   ./bin/seatunnel-cluster.sh -r worker
   
   # Open Web UI via Ingress, click a finished job's log link
   # or:
   curl -u 'user:pass' 'https://<ingress-host>/logs'
   ```
   
   ### Error Exception
   
   ```log
   log
   No server-side exception. Browser cannot open the log link because it points 
at the pod ClusterIP, e.g.:
   
   http://10.0.1.167:8080/logs/job-1137316576459685899.log
   
   Connection fails from outside the cluster. Opening the same path on the 
Ingress host succeeds:
   
   https://<ingress-host>/logs/job-1137316576459685899.log
   ```
   
   ### Zeta or Flink or Spark Version
   
   Zeta
   
   ### Java or Scala Version
   
   1.8
   
   ### Screenshots
   
   N/A — log list returns absolute URLs with member pod IPs (same pattern as 
#9287).
   
   ### Are you willing to submit PR?
   
   - [ ] Yes I am willing to submit a PR!
   
   ### Code of Conduct
   
   - [x] I agree to follow this project's [Code of 
Conduct](https://www.apache.org/foundation/policies/conduct)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to