from 🌐 Justin's Blog

Some unfiltered thoughts about the current state of the online course platform industry.

I've been trying to think of something insightful to say about online courses and course platforms, but I don't have the brain power now with an infant in the house. So instead I think I'll share a little bit about the motivation I had with LearnDash and how I think it relates to what we see today for online course platforms.

Back when I started LearnDash in 2012, online courses looked a lot different. Those big SaaS platforms that you see today like Teachable and Thinkific didn't exist. Membership plugins were around, but they weren't connecting the dots for online learning. More often than not, courses were primarily text and images, and only sometimes did they include video.

The timing was perfect for a new vision.

The Original Vision

Essentially, my vision with LearnDash at the time was:

  • Eliminate the learning curve that was so steep with learning management systems, and;
  • To provide an enjoyable learning experience to the learner.

In fact, through my entire time leading LearnDash, I always tried to tie features back to the learner in some capacity.

Learner-First Approach

I discovered that by doing this “learner first” approach, the course creators (admins) benefited as well. Their courses were impressive. More people finished them. They had a “vibe” about them. They built trust. Learners would be more motivated to take additional courses, something that's incredibly important when you are selling courses in the B2C online course platform space.

I think we did a pretty good job at LearnDash with this vision, and plenty of other platforms followed our lead with their own innovations.

The Golden Era and What Changed

By 2019 the entire online course platform space had changed dramatically from what I had seen in 2012 at the beginning of the LearnDash project. Learners were benefiting, as well as course creators. It was truly the golden era.

But in my view though this emphasis on the learner has sort of diminished since around 2019-2020.

This is mainly because of the consolidation in the space and the growing influence of private equity.

The short of it is that there is no money in creating modern learning experiences. It's more profitable to feature stuff on the admin side in hopes of luring more users of the software. I mean I get it. I can't even blame them for that, given their purpose of flipping for profit.

These companies, as a result, though, are leading the stagnation in the space. And that sucks, because they are in a position to do so much more. Throwing AI at a platform isn't innovation. I'd say it's more to just “check a box” and then justify a price hike.

These are things I think about sometimes in an industry I see changing, and not necessarily for the better.

#elearning

 
Read more... Discuss...

from Roscoe's Quick Notes

Brewers vs Cubs

This afternoon, Baseball!

My game of choice today has the Milwaukee Brewers playing the Chicago Cubs. This MLB game is scheduled to start at 1:10 PM CDT and will be played at American Family Field in Milwaukee. As usual I'll follow the game's scores and stats in real time via MLB's Gameday Service where we can also find links to the radio-call of the game provided by announcers of either team we choose.

And the adventure continues.

 
Read more...

from Kelly Kintner - Blog

As a kid in church in the South.

When I was a kid, I sang at church with Mom a lot. They had this saying about no one at home listening, “Even Jesus had to skip his hometown.” I’ve thought about that since I was a boy, and how true it is. I’ve come up with and found some analogies on it I would like to share, should you wonder too.

This old costume

Hometowns often see you like you were years ago. They do not allow for growth. Many times I’ve heard musicians say, “It is Halloween and I get to wear my 5-year-old costume.” In order to get that Halloween show, that musician has to be who they were years ago. That is not fun for a lot of us who like growth. So showing our new costumes online helps.

Ancient tree in the backyard

I’ve heard an analogy involving an old-growth tree by itself in the backyard not being as cool as in an ancient forest. I don’t really like this one as much because I would think that tree in my backyard was amazing. I get what folks are saying here. But I bet they don’t have old-growth trees in their yard.

Big fish/small pond

I like the big fish in a small pond analogy. Once you play every venue in town a couple of times, what else are you going to do? Most towns in the world don’t have the resources to support a healthy music scene. Mentally or financially, folks are stressed. They can only give so much. That kid they watched grow up playing guitar does not compete with the things on their mind. 

Digital vs Analog

My favorite analogy of being a musician in your hometown has to do with digital and analog. Folks online, on socials, get the digital you. That’s usually a better sell. The digital you doesn’t need food, have hygiene issues, talk too loud, or barely speak. The digital you isn’t obnoxious, doesn’t grind his jaw, doesn’t talk about everything on your mind. Folks at home aren’t given the same deal. They get the analog you that whines, or stinks it up in the bathroom, or eats the last of the cake.  It is possible it isn’t even right to expect the same from each crowd; they get different things from you. Why should they give the same back?

What can we do?

Not much. The thing is, this is so old, it is probably human nature. There’s not a realistic way to change that for everyone. But there are realistic ways to change it in ourselves. I keep saying “music is an inside job.” This is one of the ways I mean that. We can give ourselves what we need from the music we make. If we are able to do that, then we can tell folks how cool it is and be honest about it instead of hoping for their validation for it. How?

For me, I have to get away from most everything. People and noise don’t bother me, but I find them terribly distracting. If I am going to think up something I think is cool and go through the trouble of crafting that, I need to be alone. At least in the beginning stages. If I am to craft something I love first before anyone else loves it, I have to be there when it is crafted. If I am somewhere else, it doesn’t work. I need the moment when it comes together and I think it is rad. If I deprive myself of that, I can’t tell other folks I think it is rad. Important here, for me: I struggled forever, most of my life, in trying to make songs I’d guess folks liked. I no longer do this. I try to make songs I like. Then all I have to do is tell folks I like them. They can agree with my taste in music or not. But it doesn’t let me down, either way.

Also, if no one comes to my show, I am still there. It does not make sense to sit there and play songs I don’t even like for an empty house. If I like them, at least I get to play them. 

The Listener

I talk about “the listener” a lot. I am not averaging out folks who have heard my songs and spitting out lines. I am talking about me. Before I ever played a note, I enjoyed listening to them. I am a listener, first. I learn from every progression on the radio, all three of them. I pretended to be Neil Diamond in diapers, had a tennis racket guitar, I am a listener. I run across peeps who play all the time, but never listen. People know if you listen. If you think they don’t, they probably aren’t listening to you either. It’s wonderful to listen to music, conversations, street noises, even alarm clocks. There are songs in all of that. If you identify with them, someone else will too. Maybe more than a desire to be famous, a desire to make something you honestly love is what’s needed in your artistic career. Don’t pick it or its components from a menu. Craft that shit.

Build. Don’t just take. 

Is this going to help you in your hometown? Probably not. But if you learn music or art, that will probably help your hometown in some way. If you just guess what they want on weekends, you’re really throwing darts. Tell those folks what’s cool. Research it, learn some skills, show up, and put it together. That’s not throwing darts. That’s foundation work.

Kelly Kintner

The Kintners. Djembe Funk (Links to Subvert.fm music)

 
Read more... Discuss...

from Faucet Repair

28 August 2026

National Gallery with Toby today, so many nice moments. But perhaps none more satisfying than standing with him in front of Degas's HélÚne Rouart in her Father's Study (1886). He re-oriented my view on the work (and Degas more generally).

For some reason, I suppose based on the selected reading I've done and my relatively limited knowledge of his oeuvre, I've always had it in my head that Degas was the prettier and more accessible one in relation to Manet. And for some works that still holds true. But Toby is quite attuned to his idiosyncrasies, the formal painterly challenges setup within each of his works, and the often confounding logic of his choices. Some blips I remember: “incidents and accidents” around recording, resistance to decoding while observing, the work's relationship to provisionality.

It's a strange painting, askew and loose. The physical encounter with it is a floaty, sensuous, disorienting experience. Framings abound, (the edge of the red silk wall-hanging, the glass case containing Egyptian statues, the back of the chair, the literal frame around Corot’s Castel dell’Ovo in Naples), and they all collapse and compress into flatness despite suggesting a network of distinct and different spatial planes. The glass case in particular becomes a portal, like an open door to a hallway that piereces through the left side of the composition. The eye travels like a fly trying to escape a room. And those precarious, gummed up stacks of paper at the bottom left resting on a maroon blob of a surface-table-floor. Simply a pile of color. Green-blue-gray-orange-yellow-pink held together by a few suggestions of edge; the incident. Perhaps not unlike the disheveled spread at the bottom left of Le DĂ©jeuner, actually.

 
Read more...

from An Open Letter

I went to the mall with L and L and I got a shirt and pants. I was also looking for a pair of glasses, and the guy there commented about my traps, and asked me if I get that a lot. He said he immediately noticed when I entered, and I was wearing just a regular T-shirt. I think the journaling and writing down all of these compliments have started to work because I’m able to recognize That I do get this feedback a lot, and that I am jacked. I think it’s also one of those things where I have been so incredibly in the fitness space in the types of content I consume, and a lot of the friends that I have outside of work, and so I forget how much of a difference it is from just the regular population who doesn’t do some sort of weightlifting. I’m really grateful to myself for getting into this hobby because I feel unrecognizable from past me, and I think it’s something that I just enjoy so incredibly much, that also has given me such drastic benefits in life.

 
Read more...

from The Unbroken Ink Memoir

“Even here, even now, I am still unfolding.”

There was a time when I thought my story had ended, When the pain felt too heavy, and the silence too long. But I see now that it wasn’t an ending at all. It was a beginning disguised as loss.

Every storm I’ve faced, every mistake I’ve made, Every tear I’ve cried, They’ve all led me here, To this version of me that stands a little taller, Breathes a little deeper, And finally believes in her own strength.

I used to ask, “Why me?” Now I whisper, Thank you. Because every difficult season taught me something I couldn’t have learned any other way. I learned patience. I learned compassion. I learned that I can rebuild, Again and again, And still find beauty in the pieces.

I’m not who I was, And that’s okay. That’s growth. That’s healing.

To my children,

If you ever read these words, I hope you see that your mother wasn’t perfect, But she never stopped trying. I hope you see that no matter how many times I fell, I always got back up. I hope you know that you were my reason, The light that kept me moving when everything felt dark.

I want you to believe in your own strength the way I’ve learned to believe in mine. And that no matter what life takes from you, You always have the power to rebuild.

This isn’t the end of my story. It’s just a new chapter, One I’m writing slowly, With peace in my heart and love in my hands.

I don’t know what tomorrow will bring. But I do know this, I’ll keep waking up, Keep choosing kindness, Keep forgiving, Keep learning, Keep moving forward.

Because even after everything, I am still here. Still standing Still growing. Still becoming the woman, I was always meant to be.

 
Read more...

from The Unbroken Ink Memoir

“The road was rough, but it led me back to myself.”

I’ve walked through some dark places, The kind of moments that change you in ways you don’t see until the dust settles. There are times I thought I’d never make it out. Times I didn’t recognize myself in the mirror. But looking back now, I see someone who didn’t quit. I see someone who refused to stay broken.

So far, my journey hasn’t been easy, and it’s far from being over. It’s been messy, Painful, And full of mistakes. But I don’t regret a single step. Because each one, Even the wrong turns, Is shaping me into who I am becoming.

There was a time when I carried shame like a second skin, When I looked at my life and only saw the ruins. But now I see the rebuilding. I see the lessons hiding inside the heartbreak. I see the woman learning how to love herself. Even after being told, she wasn’t worth loving.

I lost myself for a long time.

I let other people’s voices drown out my own. But somewhere in the silence that followed, I started to hear her again. The version of me I thought was gone. The girl who dreamed. The woman who believed in love. The mother who gave everything she had, even when it wasn’t enough.

And little by little, I’ve been finding her. I’m becoming stronger now. Wiser. Softer, but also braver. I know now that mistakes don’t make you unworthy, they make me real.

If I’ve learned anything, Its growth doesn’t come from comfort. It comes from being cracked open, From learning to sit in the pain long enough to understand what it’s trying to teach you. And even though this road has been hard, I wouldn’t trade it, Because it has brought me here. To truth, To peace, To becoming the woman, I was meant to be.

I’m still walking the path, still learning, Still healing. But I’m no longer walking in circles. I’m walking forward.

One day, I hope my kids can see this, Not the mistakes or the chaos, But the strength it takes to rise again. I hope they see that even when I was at my lowest, I kept fighting and will continue to fight to become better. Not just for me, but for them.

I want them to know that life will hurt sometimes. That people will leave, Things will fall apart, And they’ll doubt themselves too. But I also want them to know that those moments don’t define them. Their resilience does.

If they can see me, The imperfect, Healing, still growing into myself, And know that it’s possible to fall and still stand tall again, then maybe they’ll believe they can too.

Because that’s the legacy I want to leave behind. Not perfection, But persistence. Not always an easy life, But a real one.

I am not who I used to be, And I’m not yet who I’ll become. But I am proud of the woman standing here today, the one who is turning pain into purpose, Mistakes into lessons, And heartbreak into a reason to keep rising.

 
Read more...

from EpicMind

Illustration eines antiken Philosophen in Toga, der erschöpft an einem modernen BĂŒroarbeitsplatz vor einem Computer sitzt, umgeben von leeren BĂŒrostĂŒhlen und urbaner Architektur.

Freundinnen & Freunde der Weisheit! Toxic Productivity beschreibt ein Mindset, in dem der eigene Selbstwert ausschliesslich von Erfolgen und Ergebnissen abhÀngt. Diesem Mindset kann man mit einfachen Mitteln entkommen.

Die New Yorker Psychotherapeutin Israa Nasir thematisiert dieses PhĂ€nomen in ihrem Buch Toxic Productivity: Reclaim Your Times and Emotional Energy in a World That Always Demands More. Sie erklĂ€rt, dass ein stĂ€ndiger Drang nach hyperoptimierten Arbeitsablaufen – etwa durch minutioses Zeittracking, SchuldgefĂŒhle beim Pausieren, Übercommitment und den unaufhörlichen Vergleich mit anderen – zu Überarbeitung, Selbstkritik und letztlich Burnout fĂŒhrt.

Als Massnahmen gegen toxische ProduktivitĂ€t empfiehlt Nasir, sich auf wertebasierte Ziele zu konzentrieren und echte ProduktivitĂ€t von reiner GeschĂ€ftigkeit zu unterscheiden. Dazu gehören das bewusste Einplanen von Pausen, das klare Setzen von PrioritĂ€ten sowie das Regulieren von negativen Emotionen, die aus Angst, Perfektionismus oder dem Drang nach externer BestĂ€tigung resultieren. Gleichzeitig soll der innere Coach gestĂ€rkt werden und Mythen wie die vermeintliche ProduktivitĂ€t durch Multitasking, lĂ€ngere Arbeitszeiten oder frĂŒhes Aufstehen kritisch hinterfragt werden.

Hier sind meine drei einfachen, sofort umsetzbaren Beispiele, um Nasirs Empfehlungen in den Alltag zu integrieren:

  1. Feste Pausen einplanen:
    Stelle einen Timer, der dich jede Stunde an eine fĂŒnfminĂŒtige Pause erinnert. Nutze diese kurzen Pausen, um dich zu strecken, bewusst tief durchzuatmen oder kurz vom Bildschirm wegzukommen – so verhinderst du Überarbeitung und förderst deine Erholung.

  2. Klare PrioritÀten setzen:
    Notiere dir jeden Morgen die drei wichtigsten Aufgaben, die deinen langfristigen Zielen entsprechen. Arbeite diese Aufgaben nacheinander ab, ohne dich von weniger wichtigen TÀtigkeiten ablenken zu lassen. So vermeidest du Multitasking und behÀltst den Fokus.

  3. Negative Emotionen regulieren:
    Richte dir tĂ€glich drei Minuten fĂŒr eine AchtsamkeitsĂŒbung ein. Setze dich an einen ruhigen Ort, schliesse die Augen und konzentriere dich auf deinen Atem. Diese kurze Meditation hilft dir, Stress abzubauen und den inneren Coach zu aktivieren, sodass du mit mehr Gelassenheit an deine Aufgaben herangehst.

Denkanstoss zum Wochenbeginn

„Der Weg, anzufangen, ist, mit dem Reden aufzuhören und mit dem Tun zu beginnen.“ – Walt Disney (1901–1966)

ProductivityPorn-Tipp der Woche: Öffentliche Verpflichtungen eingehen

ErzÀhle anderen von Deinen Zielen. Sobald Du Dich öffentlich zu etwas bekannt hast, steigt die Wahrscheinlichkeit, dass Du es auch durchziehst.

Aus dem Archiv: Das analoge Falschspiel der Digitalelite

Sam Altman, Bill Gates und Richard Branson haben die digitale Welt geformt wie kaum andere. Doch wenn es um ihre wichtigsten Entscheidungen geht, greifen sie ausgerechnet zu Stift und Papier. Das ist kein nostalgischer Tick, sondern kalkulierte Notwendigkeit. Handschrift ist fĂŒr sie ein Werkzeug des Denkens, das Klarheit erzwingt und Ideen verankert. Dabei liegt hier eine bemerkenswerte Ironie verborgen: Die „Tech-Gurus“ zerstören genau jene Kulturtechnik, auf die sie selbst angewiesen sind. WĂ€hrend sie ihre Gedanken von Hand entwickeln, schaffen ihre Produkte eine Welt, in der kommende Generationen diese Erfahrung nie mehr machen werden.

weiterlesen 


Vielen Dank, dass Du Dir die Zeit genommen hast, diesen Newsletter zu lesen. Ich hoffe, die Inhalte konnten Dich inspirieren und Dir wertvolle Impulse fĂŒr Dein (digitales) Leben geben. Bleib neugierig und hinterfrage, was Dir begegnet!


EpicMind – Weisheiten fĂŒr das digitale Leben „EpicMind“ (kurz fĂŒr „Epicurean Mindset“) ist mein Blog und Newsletter, der sich den Themen Lernen, ProduktivitĂ€t, Selbstmanagement und Technologie widmet – alles gewĂŒrzt mit einer Prise Philosophie.


Disclaimer Teile dieses Texts wurden mit Deepl Write (Korrektorat und Lektorat) ĂŒberarbeitet. FĂŒr die Recherche in den erwĂ€hnten Werken/Quellen und in meinen Notizen wurde NotebookLM von Google verwendet. Das Artikel-Bild wurde mit ChatGPT erstellt und anschliessend nachbearbeitet.

Topic #Newsletter

 
Weiterlesen... Discuss...

from Joyrex

I used to run the (kubernetes-run) ingress-nginx. When they announced they’d stop updating it, I knew I wanted to move to the Gateway API/HTTPRoute method, because that seems like the future. I originally switched to nginx-gateway-fabric. That is controlled by NGINX/F5 though, and they want money, so they’re putting features I want behind a very expensive paywall. You know who doesn’t paywall features and also supports Gateway API v1.5.1 (or newer)? envoy-gateway.

History / Requirements

When ingress-nginx announced they weren’t going to be updating it after March of 2026, I started looking into GatewayAPI, knowing I wanted to jump to HTTPRoute. I tried moving over to nginx-gateway-fabric at one point, but I quickly found out a Gateway only supports 16 Listeners. This was way too little, and being a homelab, I only have one public IP to point to for all my services. Thankfully, I saw that ListenerSets were being added (or already had been) in v1.5.1 of the Gatewy API, but when looking, most implementations hadn’t implemented that version yet. So I ended up waiting.

Eventually nginx-gateway-fabric released a version with support for ListenerSets, so I made the move. While I implemented it successfully, I learned a couple things:

  • To increase the body size of the request (to allow large uploads for social media or whatever), you need to create a ClientSettingPolicy that is attached to an HTTPRoute for the connection you want. The following example is for making the body size 10g.
apiVersion: gateway.nginx.org/v1alpha1
kind: ClientSettingsPolicy
metadata:
  name: client-settings
spec:
  targetRef:
    group: gateway.networking.k8s.io
    kind: HTTPRoute
    name: myhttproute
  body:
    maxSize: "10g"
  • With ingress-nginx, I used something called OIDCGuard to let me put OIDC in front of whatever site I wanted. I just assumed NGINX will have something similar, and they do, but they put it behind a paywall. I tried contacting them to see if they offered some sort of deal/free license for homelab people like some companies do. I heard nothing back. They’re obviously looking for big money from companies, and not some dweeb who has overengineered his setup at home. The whole reason I started down the path of kube was so I could learn the skills that I would need at work. Whatever I learn at home, I end up applying to work, including what specific implementations of stuff we use. Seems like supporting people nuts enough to homelab up kube with advanced features, you’d want those people to use your software. Whatever. Anyway, as OIDC is behind a paywall, I added BasicAuth. To do that, you add an AuthenticationFilter and refer to an htpasswd file secret:
apiVersion: gateway.nginx.org/v1alpha1
kind: AuthenticationFilter
metadata:
  name: basic-auth
spec:
  type: Basic
  basic:
    secretRef:
      name: basic-auth
    realm: "Basic auth"

Then you attach that AuthenticationFilter to an HTTPRoute

apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
  name: mysite
spec:
  hostnames:
  - mysite.joyrex.net
  parentRefs:
  - group: gateway.networking.k8s.io
    kind: ListenerSet
    name: my-ls
    sectionName: mysite
  rules:
  - backendRefs:
    - kind: Service
      name: my-service
      port: 80
    matches:
    - path:
        type: PathPrefix
        value: /
    filters:
    - type: ExtensionRef
      extensionRef:
        group: gateway.nginx.org
        kind: AuthenticationFilter
        name: basic-auth

Learned Requirements

  • I need to have ListenerSets so I can attach >16 Listeners to a gateway
  • I need the ability to change upload body size
  • I really really want OIDC authentication

Envoy Gateway

Looking around, I found envoy-gateway was another popular gateway server, supported my requirements (I thought, more later) and had good documentation.

Thankfully, gateway and HTTPProxy are core stuff not unique to nginx’s implementation, so there wasn’t much I needed to change for my gateway or applications. I just had to update the gateway name I was using and make some of the other changes. Those are talked about below. Before I did that, I disabled all the HTTPRoutes that use BasicAuth so I didn’t accidentally put stuff on the public web until I got OIDC working.

Dual-Stack

I had dual-stack (IPv4/IPv6) going with nginx and I wanted the same for this gateway. To do that, I have to use an envoy-specific manifest to make sure the Service is correctly set up:

apiVersion: gateway.envoyproxy.io/v1alpha1
kind: EnvoyProxy
metadata:
  name: config
spec:
  provider:
    type: Kubernetes
    kubernetes:
      envoyDeployment:
        replicas: 2
      envoyService:
        annotations:
          metallb.io/loadBalancerIPs: 192.168.1.209,2400:a842:40ae::209
  ipFamily: DualStack

The ipFamily: DualStack is the important part here, and then I use the annotations to set the IPs I want via MetalLB.

For this to be used, you attach it to the gateway’s spec:

apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
  name: klopjob-gateway
spec:
  ...
  infrastructure:
    parametersRef:
      group: gateway.envoyproxy.io
      kind: EnvoyProxy
      name: config
  ...

OIDC Support

Using the Envoy Gateway documentation about OIDC and the Authelia Envoy Gateway documentation, I was able to get OIDC working fine. For reference, here’s an example entry for something I want to have behind OIDC.

Authelia OIDC Client Config
- client_id: 'clientid'
  client_name: 'mysite.joyrex.net'
  client_secret: 
    path: "/secrets/authelia-secrets/oidc.client.mysite-joyrex-net.value"
  consent_mode: "implicit"
  public: false
  authorization_policy: 'two_factor'
  require_pkce: false
  pkce_challenge_method: ''
  redirect_uris:
    - 'https://mysite.joyrex.net/authelia/openid_connect/callback'
  scopes:
    - 'openid'
  grant_types:
    - 'authorization_code'
  response_types:
    - 'code'
  access_token_signed_response_alg: 'none'
  userinfo_signed_response_alg: 'none'
  token_endpoint_auth_method: 'client_secret_basic'
Security Policy
apiVersion: gateway.envoyproxy.io/v1alpha1
kind: SecurityPolicy
metadata:
  name: mysite-joyrex-net-oidc
spec:
  targetRefs:
    - group: gateway.networking.k8s.io
      kind: HTTPRoute
      name: mysite
  oidc:
    provider:
      issuer: 'https://auth.joyrex.net'
      authorizationEndpoint: 'https://auth.joyrex.net/api/oidc/authorization'
      tokenEndpoint: 'https://auth.joyrex.net/api/oidc/token'
    clientID: "clientid"
    clientSecret:
      name: "mysite-joyrex-net-oidc-secret"
    cookieDomain: 'mysite.joyrex.net'
    cookieNames:
      idToken: ''
      accessToken: ''
    scopes:
      - 'openid'
    redirectURL: "https://mysite.joyrex.net/authelia/openid_connect/callback"
    forwardAccessToken: false
    refreshToken: false
    passThroughAuthHeader: false
HTTPRoute
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
  name: mysite
spec:
  hostnames:
  - mysite.joyrex.net
  parentRefs:
  - group: gateway.networking.k8s.io
    kind: ListenerSet
    name: my-ls
    sectionName: mysite
  rules:
  - backendRefs:
    - kind: Service
      name: mysite
      port: 8080
    matches:
    - path:
        type: PathPrefix
        value: /
    filters:
    - type: RequestHeaderModifier
      requestHeaderModifier:
        add:
        - name: x-real-ip
          value: '%DOWNSTREAM_REMOTE_ADDRESS_WITHOUT_PORT%'
  - matches:
    - path:
        type: PathPrefix
        value: /authelia/openid_connect/callback
    filters:
    - type: RequestRedirect
      requestRedirect:
        path:
          type: ReplaceFullPath
          replaceFullPath: /
        statusCode: 302

The x-real-ip setting is something that I’ll be describing right now.

X-Real-Ip

The X-Forwarded-For header is already set, but X-Real-Ip doesn’t get set by default. Anubis looks for this value to verify stuff is configured properly, so I wanted this attached to all my requests.

I’m supposed to be able to attach this to a gateway as a whole, but that didn’t work for me. I was tired of debugging and learning, so for right now I just attached the filter to all the httproutes I wanted it on.

    filters:
    - type: RequestHeaderModifier
      requestHeaderModifier:
        add:
        - name: x-real-ip
          value: '%DOWNSTREAM_REMOTE_ADDRESS_WITHOUT_PORT%'

This is shown in place in the full httproute above.

Body Size

This is where I hit issues. I just assumed setting body size would be common enough, but it’s not. According to this ticket and this question page, the way you increase the body size is to enable requestBuffering. This has the following downsides:

  • breaks anything using websockets. Hopefully this gets resolved in the future.
  • Limits the max upload size to 4G (or more exactly, 4294967295). Depending on your use case this could suck.

That said, to set requestBuffering, you need to create a BackendPolicy that attaches to one or more HTTPRoutes.

apiVersion: gateway.envoyproxy.io/v1alpha1
kind: BackendTrafficPolicy
metadata:
  name: request-buffer
spec:
  targetRefs:
  - group: gateway.networking.k8s.io
    kind: HTTPRoute
    name: mysite
  requestBuffer:
    limit: 4294967295

Conclusion

Besides the requestBuffer issue, and the minor X-Real-IP header setting not applying to the Gateway as a whole, I am extremely happy with Envoy. Leaving nginx-gateway-fabric behind is great, and I am stoked I have OIDC back.

 
Read more...

Join the writers on Write.as.

Start writing or create a blog