This is an automated email from the ASF dual-hosted git repository.

rusackas pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/superset.git


The following commit(s) were added to refs/heads/master by this push:
     new 10866337c5c docs(helm): document Gateway API HTTPRoute support (#43635)
10866337c5c is described below

commit 10866337c5c41b33ef12c3df4040ae6ba43b4354
Author: Evan Rusackas <[email protected]>
AuthorDate: Tue Sep 8 15:33:45 2026 -0700

    docs(helm): document Gateway API HTTPRoute support (#43635)
    
    Co-authored-by: Claude <[email protected]>
---
 docs/admin_docs/installation/kubernetes.mdx | 48 +++++++++++++++++++++++++++++
 1 file changed, 48 insertions(+)

diff --git a/docs/admin_docs/installation/kubernetes.mdx 
b/docs/admin_docs/installation/kubernetes.mdx
index fe22a780471..bed1732af48 100644
--- a/docs/admin_docs/installation/kubernetes.mdx
+++ b/docs/admin_docs/installation/kubernetes.mdx
@@ -87,6 +87,7 @@ The chart will publish appropriate services to expose the 
Superset UI internally
 
 - Configure the Service as a `LoadBalancer` or `NodePort`
 - Set up an `Ingress` for it - the chart includes a definition, but will need 
to be tuned to your needs (hostname, tls, annotations etc...)
+- Set up a Gateway API `HTTPRoute` for it - see [Exposing Superset via Gateway 
API (HTTPRoute)](#exposing-superset-via-gateway-api-httproute) below
 - Run `kubectl port-forward superset-xxxx-yyyy :8088` to directly tunnel one 
pod's port into your localhost
 
 Depending how you configured external access, the URL will vary. Once you've 
identified the appropriate URL you can log in with:
@@ -319,6 +320,53 @@ configOverrides:
     AUTH_USER_REGISTRATION_ROLE = "Admin"
 ```
 
+### Exposing Superset via Gateway API (HTTPRoute)
+
+As an alternative to `Ingress`, the chart can create a [Gateway 
API](https://gateway-api.sigs.k8s.io/)
+`HTTPRoute` that attaches to a Gateway already running in your cluster. This 
requires the Gateway
+API CRDs serving the configured `httproute.apiVersion` 
(`gateway.networking.k8s.io/v1` by default)
+to be installed, along with a Gateway resource for the route to attach to. If 
the Gateway lives in
+a different namespace than the `HTTPRoute` (as in the
+example below), its listener's `allowedRoutes` must explicitly permit routes 
from this release's
+namespace, or the `HTTPRoute` will install successfully but never attach.
+
+```yaml
+httproute:
+  enabled: true
+  parentRefs:
+    - name: my-gateway
+      namespace: gateway-system
+  hostnames:
+    - superset.example.com
+  rules:
+    - matches:
+        - path:
+            type: PathPrefix
+            value: /
+```
+
+- `httproute.parentRefs` lists the Gateway(s) the route attaches to.
+- `httproute.hostnames` matches against the HTTP `Host` header; it's 
templated, so values like
+  `{{ .Release.Name }}` can be used.
+- `httproute.rules` are routing rules backed by the Superset service; each 
rule accepts standard
+  `matches`, `filters`, and `timeouts` fields, and an optional `weight` 
(defaults to `1`) applied to
+  its single backend reference. Since each rule maps to one backend, `weight` 
has no traffic-splitting
+  effect here; it only matters if you fork the template to add multiple 
`backendRefs` to a rule.
+  `timeouts` only joined the Gateway API Standard channel in v1.2, so it 
requires both v1.2+ CRDs
+  and a supporting controller; drop it if either predates that.
+- If `supersetWebsockets.enabled` is set, an extra rule routing 
`supersetWebsockets.ingress.path`
+  (default `/ws`) to the `-ws` service is appended automatically, mirroring 
the `Ingress` behavior.
+  WebSocket upgrade support is controller-dependent under Gateway API; check 
your Gateway
+  implementation's docs in case it needs an explicit protocol opt-in for 
global async queries to
+  keep working behind a Gateway.
+- If `supersetMcp.enabled` and `supersetMcp.httproute.enabled` are both set, 
an extra rule routing
+  `supersetMcp.httproute.path` to the `-mcp` service is appended as well. 
Don't expose this route
+  without first enabling MCP authentication — see the
+  [MCP Server Deployment & 
Authentication](/admin-docs/configuration/mcp-server#authentication) doc;
+  by default the MCP server runs in dev mode with auth disabled.
+- Set `httproute.apiVersion` to `gateway.networking.k8s.io/v1beta1` if your 
cluster's Gateway API
+  installation hasn't promoted `HTTPRoute` to `v1` yet.
+
 ### Enable Alerts and Reports
 
 For this, as per the [Alerts and Reports 
doc](/admin-docs/configuration/alerts-reports), you will need to:

Reply via email to