gRPC reverse bridging
How reverse bridging works
-
Client sends a gRPC request on HTTP/2 connection with gRPC headers in HTTP/2 frames and proto-buf payload.
-
Based on policy evaluation, the load balancing virtual server (with gRPC service bound to it) translates and forwards the request over HTTP/1.1 connection to backend server.
-
On receiving the HTTP/1.1 response, if there is no grpc-status code in the response, ADC derives a grpc status-case from the HTTP response code.
-
The appliance then inserts the gRPC headers into HTTP/2 trailer before forwarding the response to the client.
Configure gRPC reverse bridging by using the CLI
-
Add HTTP profile 1 with HTTP/2 and HTTP/2 direct enabled for load balancing virtual server
-
Add HTTP profile 2 with HTTP/2 disabled for back-end server
-
Add load balancing virtual server of type SSL/HTTP and set to HTTP profile 1
-
Add service for gRPC endpoint and set to HTTP profile 2
-
Bind Service for gRPC endpoint to load balancing virtual server
-
Map HTTP-status code to gRPC status code if the response does not have a grpc status code
Add HTTP profile 1 with HTTP/2 and HTTP/2 direct enabled for load balancing virtual server
add ns httpProfile <name> - http2 ( ENABLED | DISABLED ) [-http2Direct ( ENABLED | DISABLED )]
Add HTTP profile 2 with HTTP/2 disabled for back-end server
add ns httpProfile <name> - http2 ( ENABLED | DISABLED ) [-http2Direct ( ENABLED | DISABLED )]
Add load balancing virtual server of type SSL/HTTP and set to HTTP profile 1
add lb vserver <name> <service type> [(<IP address>@ <port>)] [-httpProfileName <string>]
Add service for gRPC endpoint and set to HTTP profile 2
add service <name> (<IP> | <serverName> ) <serviceType> <port> [-httpProfileName <string>]
add service svc-grpc 10.10.10.11 HTTP 80 -httpProfileName profile2
Bind service for gRPC endpoint to load balancing virtual server
bind lb vserver <name> <serviceName>
bind lb vserver lb-grpc svc-grpc
Map HTTP response code to gRPC status code
| HTTP Response status-code | gRPC status code |
|---|---|
| 200 | OK |
| 400 | INTERNAL = 13 |
| 403 | PERMISSION_DENIED = 7 |
| 401 | UNAUTHENTICATED = 16 |
| 429, 502, 503, 504 | UNAVAILABLE = 14 |
| 404 | UNIMPLEMENTED = 12 |
Configure gRPC reverse bridging by using the GUI
Add HTTP profile 1 with HTTP/2 and HTTP/2 direct enabled for load balancing virtual server
-
Navigate to System > Profiles and click HTTP Profiles.
-
Enable HTTP/2 option in a HTTP profile 1.
Add HTTP profile 2 with HTTP/2 disabled for back-end server
-
Navigate to System > Profiles and click HTTP Profiles.
-
Enable HTTP/2 option in a HTTP profile 2.
-
Click OK.
Add load balancing virtual server of type SSL/HTTP and set to HTTP profile 1
-
Navigate to Traffic Management > Load Balancing > Virtual Servers.
-
Click Add to create a load balancing virtual server for gRPC traffic.
-
In Load Balancing Virtual Server page, click Profiles.
-
In the Profiles section, select the profile type as HTTP.
-
Click OK and then Done.
Add service with gRPC endpoint and set to HTTP profile 2
-
Navigate to Traffic Management > Load Balancing > Services.
-
Click Add to create an application server for gRPC traffic.
-
In Load Balancing Service page, go to Profile section.
-
Under Profiles, add HTTP profile for gRPC endpoint.
-
Click OK and then Done.
Bind Service for gRPC endpoint to load balancing virtual server
-
Navigate to Traffic Management > Load Balancing > Virtual Servers.
-
Click Add to create a load balancing virtual server for gRPC traffic.
-
In Load Balancing Virtual Server page, click Service and Service Groups section.
-
In the Load Balancing Virtual Server Service Binding page, select the gRPC service to bind.
-
Click Close and then Done.