Skip to content

For the complete documentation index, see llms.txt. Markdown versions of all docs pages are available by appending .md to any docs URL.

Strip trailing dots from hostnames

Page as Markdown

    

Strip a trailing dot from Host and authority headers so that fully qualified domain name requests match routes without dotted hostnames.

Some clients send a fully qualified domain name (FQDN) with a trailing dot in the Host or :authority header, such as www.example.com.. Gateway API hostnames cannot include the trailing dot, so an HTTPRoute with the www.example.com hostname does not match the trailing dot hostname by default.

To strip the trailing dot, create a ListenerPolicy and set spec.default.httpSettings.stripTrailingHostDot to true. The gateway proxy strips the trailing dot before filter processing and route matching, and forwards the stripped host value upstream. If you omit the field or set it to false, the gateway proxy keeps the trailing dot.

Before you begin

  1. Follow the Get started guide to install kgateway.

  2. Follow the Sample app guide to create a gateway proxy with an HTTP listener and deploy the httpbin sample app.

  3. Get the external address of the gateway and save it in an environment variable.

    export INGRESS_GW_ADDRESS=$(kubectl get svc -n kgateway-system http -o jsonpath="{.status.loadBalancer.ingress[0]['hostname','ip']}")
    echo $INGRESS_GW_ADDRESS  

Strip trailing dots

Attach a ListenerPolicy to the Gateway that serves the www.example.com route from the sample app. The policy applies to all HTTP and HTTPS listeners on the Gateway.

  1. Create a ListenerPolicy that strips trailing dots from hostnames.

    kubectl apply -f- <<EOF
    apiVersion: gateway.kgateway.dev/v1alpha1
    kind: ListenerPolicy
    metadata:
      name: strip-trailing-host-dot
      namespace: kgateway-system
    spec:
      targetRefs:
      - group: gateway.networking.k8s.io
        kind: Gateway
        name: http
      default:
        httpSettings:
          stripTrailingHostDot: true
    EOF
    Review the following table to understand this configuration.
    Field Description
    spec.targetRefsAttaches the ListenerPolicy to the http Gateway. The policy applies to all HTTP and HTTPS listeners on that Gateway.
    spec.default.httpSettings.stripTrailingHostDotSet to true to strip one trailing dot from the Host or :authority header before filter processing and route matching. The stripped value is also forwarded upstream. Omit the field or set it to false to keep the trailing dot.
  2. Send a request to the httpbin app and include a Host header with a trailing dot. Verify that the request succeeds and that the dot is removed in the Host header that is returned in your CLI output.

    curl -i http://$INGRESS_GW_ADDRESS:8080/headers -H "host: www.example.com."

    Example output:

    HTTP/1.1 200 OK
    access-control-allow-credentials: true
    access-control-allow-origin: *
    content-type: application/json; encoding=utf-8 
    x-envoy-upstream-service-time: 16
    content-length: 440
    server: envoy
    
    {
      "headers": {
        "Accept": [
          "*/*"
        ],
        "Host": [
          "www.example.com"
        ],
        "User-Agent": [
          "curl/8.7.1"
        ],
        "X-Envoy-Expected-Rq-Timeout-Ms": [
          "15000"
        ],
        "X-Envoy-External-Address": [
          "127.0.0.1"
        ],
        "X-Forwarded-For": [
          "10.244.0.7"
        ],
        "X-Forwarded-Proto": [
          "http"
        ],
        "X-Request-Id": [
          "6abca5b7-9028-44bb-a694-66ad86cedfe2"
        ]
      }
    }
    

Cleanup

You can remove the resources that you created in this guide.
kubectl delete listenerpolicy strip-trailing-host-dot -n kgateway-system --ignore-not-found
Was this page helpful?