gRPC bridging
How gRPC bridging works
-
When a gRPC request is sent, the NetScaler appliance checks if the connection is HTTP/1.1 and the content type is application/grpc. The HTTP/1.1 requests translate to the following pseudo headers.
-
On receiving a gRPC request on HTTP/1.1. connection as indicated by the Content-Type header, the ADC appliance transforms the request into gRPC over HTTP/2 as given below:
:method: Method-name in HTTP/1.1 request
:path: Path is HTTP/1.1 request
content-type: application/grpc
-
Based on policy evaluation, the load balancing virtual server (with the gRPC service bound to it) terminates the request or forwards it over HTTP/2 frames to the back-end gRPC server.
-
On receiving the response on a HTTP/2 connection from the gRPC server, the appliance buffers until it receives the HTTP/2 trailer and then checks for the gRPC-status code. If it is non-zero gRPC error status, the appliance looks for the mapping HTTP Status code and send a suitable HTTP/1.1 error response.
Configure gRPC bridging by using the CLI
-
Add HTTP profile with HTTP/2 and HTTP/2 direct enabled
-
Enable global back-end HTTP/2 support in the HTTP parameter
-
Add load balancing virtual server of type SSL/HTTP and set the HTTP profile
-
Add Service for gRPC endpoint and set the HTTP profile
-
Bind gRPC end point service to load balancing virtual server
-
Map gRPC status code to the HTTP response for non-zero gRPC status
-
Configure gRPC buffering by time and/or size
Add HTTP profile with the HTTP/2 and HTTP/2 direct enabled
add ns httpProfile <name> - http2 ( ENABLED | DISABLED ) [-http2Direct ( ENABLED | DISABLED )]
add ns httpProfile http2gRPC -http2Direct ENABLED -http2 ENABLED
Enable global back end HTTP/2 support in the HTTP parameter
set ns httpParam -http2ServerSide( ON | OFF )
set ns httpParam -http2ServerSide ON
Add load balancing virtual server of type SSL/HTTP and set the HTTP profile
add lb vserver <name> <service type> [(<IP address>@ <port>)] [-httpProfileName <string>]
add lb vserver lb-grpc HTTP 10.10.10.10 80 -httpProfileName http2gRPC
Add Service for gRPC endpoint and set the HTTP profile
add service <name> (<IP> | <serverName> ) <serviceType> <port> [-httpProfileName <string>]
add service svc-grpc 10.10.10.10 HTTP 80 -httpProfileName http2gRPC
Bind gRPC end point service to load balancing virtual server
bind lb vserver <name> <serviceName>
bind lb vserver lb-grpc svc-grpc
Map gRPC status code to HTTP status-code in the HTTP/1.1 response
| gRPC status-code | HTTP response status-code | HTTP response reason-phrase |
|---|---|---|
| OK = 0 | 200 | OK |
| CANCELLED = 1 | 499 | * |
| UNKNOWN = 2 | 500 | Internal Server Error |
| INVALID_ARGUMENT = 3 | 400 | Bad Request |
| DEADLINE_EXCEEDED = 4 | 504 | Gateway Timeout |
| NOT_FOUND = 5 | 404 | * |
| ALREADY_EXISTS = 6 | 409 | Conflict |
| PERMISSION_DENIED = 7 | 403 | Forbidden |
| UNAUTHENTICATED = 16 | 401 | Unauthorized |
| RESOURCE_EXHAUSTED = 8 | 429 | * |
| FAILED_PRECONDITION = 9 | 400 | Bad Request |
| ABORTED = 10 | 409 | Conflict |
| OUT_OF_RANGE = 11 | 400 | Bad Request |
| UNIMPLEMENTED = 12 | 501 | Not Implemented |
| INTERNAL = 13 | 500 | Internal Server Error |
| UNAVAILABLE = 14 | 503 | Service Unavailable |
| DATA_LOSS = 15 | 500 | Internal Server Error |
Configure gRPC buffering by time and/or size
add ns httpProfile http2gRPC [-grpcHoldLimit <positive_integer>] [-grpcHoldTimeout <positive_integer>]
set ns httpProfile http2gRPC [-grpcHoldLimit <positive_integer>] [-grpcHoldTimeout <positive_integer>]
grpcholdlimit. Maximum size in bytes allowed to buffer gRPC packets until trailer is received. You can configure both the parameters and any one.
grpcholdtimeout. Maximum time in milliseconds allowed to buffer gRPC packets until trailer is received. The value should be in multiples of 100. Default value: 1000 Minimum value: 0 Maximum value: 180000
add httpprofile http2gRPC -grpcholdlimit 1048576 -grpcholdtimeout 5000 set httpprofile http2gRPC -grpcholdlimit 1048576 -grpcholdtimeout 5000
Configure gRPC bridging by using the GUI
Add HTTP profile with HTTP/2 and HTTP/2 direct enabled
-
Navigate to System > Profiles and click HTTP Profiles.
-
Select HTTP/2 in the HTTP profile.
Enable global back-end HTTP/2 support in the HTTP parameter
-
Navigate to System > Settings > HTTP Parameters.
-
In the Configure HTTP Parameter page, select HTTP/2 on Server Side option.
-
Click OK.
Add load balancing virtual server of type SSL/HTTP and set HTTP profile
-
Navigate to Traffic Management > Load Balancing > Virtual Servers.
-
Click Add to create a load balancing virtual server for gRPC traffic.
-
In Load Balancing Virtual Server page, click Profiles.
-
In the Profiles section, select the profile type as HTTP.
-
Click OK and then Done.
Add Service for gRPC endpoint and set HTTP profile
-
Navigate to Traffic Management > Load Balancing > Services.
-
Click Add to create an application server for gRPC traffic.
-
In Load Balancing Service page, go to Profile section.
-
Under Profiles, add HTTP profile for gRPC endpoint.
-
Click OK and then Done.
Bind Service for gRPC endpoint to load balancing virtual server
-
Navigate to Traffic Management > Load Balancing > Virtual Servers.
-
Click Add to create a load balancing virtual server for gRPC traffic.
-
In Load Balancing Virtual Server page, click Service and Service Groups section.
-
In the Load Balancing Virtual Server Service Binding page, select the gRPC service to bind.
-
Click Close and then Done.
Configure gRPC buffering by time and size by using the GUI
-
Navigate to System > Profiles and click HTTP Profiles.
-
Select HTTP/2 in the HTTP profile.
-
In the Configure HTTP Profile page, set the following parameters:
-
grpcHoldTimeout. Enter the time in milliseconds to buffer gRPC packets until the trailer is received.
-
grpcHoldLimit. Enter the maximum size in bytes to buffer gRPC packets until the trailer is received.
-
-
Click OK and Close.