mirror of
https://github.com/hcengineering/huly-selfhost.git
synced 2026-10-01 22:15:08 +02:00
fix(helm): make built-in MinIO credentials match STORAGE_CONFIG (#324)
The generated STORAGE_CONFIG carried randAlphaNum access/secret keys, but the MinIO deployment set no MINIO_ROOT_USER/MINIO_ROOT_PASSWORD, so MinIO ran on its built-in credentials and rejected those keys with InvalidAccessKeyId. Root credentials now come from minio.rootUser/minio.rootPassword, are injected into MinIO, and build the default STORAGE_CONFIG, so the two always agree. Defaults match MinIO's built-ins, which is what running deployments actually use today, and can now be overridden. Values shorter than MinIO accepts fail at template time instead of crash-looping the pod. Signed-off-by: Artyom Savchenko <armisav@gmail.com> Co-authored-by: Artyom Savchenko <armisav@gmail.com>
This commit is contained in:
co-authored by
Artyom Savchenko
parent
c32e79dcb4
commit
ca3808a57c
@@ -73,6 +73,20 @@ helm install huly ./helm/huly \
|
||||
|
||||
Setting `storage.type=s3` automatically disables the built-in MinIO deployment and PVC.
|
||||
|
||||
### Built-in MinIO credentials
|
||||
|
||||
The built-in MinIO runs with `minio.rootUser` / `minio.rootPassword`, and the generated
|
||||
`STORAGE_CONFIG` uses the same pair. They default to MinIO's own built-in credentials; override
|
||||
both to change them:
|
||||
|
||||
```bash
|
||||
--set minio.rootUser=huly \
|
||||
--set minio.rootPassword=YOUR_PASSWORD
|
||||
```
|
||||
|
||||
Changing them on an existing install rotates MinIO's root credentials — stored objects are
|
||||
unaffected, but any other client of that MinIO must be updated too.
|
||||
|
||||
**Bucket modes:**
|
||||
- `rootBucket` — all workspaces share one bucket, isolated by workspace-ID prefix (recommended)
|
||||
- `bucketPrefix` — each workspace gets its own bucket, prefixed with this string
|
||||
@@ -345,6 +359,8 @@ Each infra service can be disabled to use an external instance. When disabled, p
|
||||
| `elastic.javaOpts` | JVM heap options | `-Xms1024m -Xmx1024m` |
|
||||
| `minio.enabled` | Deploy built-in MinIO | `true` |
|
||||
| `minio.image` | MinIO-compatible Silo image | `pgsty/silo` |
|
||||
| `minio.rootUser` | Built-in MinIO root user (also used in `STORAGE_CONFIG`) | `minioadmin` |
|
||||
| `minio.rootPassword` | Built-in MinIO root password (also used in `STORAGE_CONFIG`) | `minioadmin` |
|
||||
| `minio.storage` | Data PVC size | `50Gi` |
|
||||
| `minio.storageClassName` | PVC storage class | `""` |
|
||||
|
||||
|
||||
@@ -30,6 +30,9 @@ spec:
|
||||
- ":9000"
|
||||
- --console-address
|
||||
- ":9001"
|
||||
env:
|
||||
{{- include "huly.envSecret" (dict "name" "MINIO_ROOT_USER" "key" "MINIO_ROOT_USER" "root" .) | nindent 12 }}
|
||||
{{- include "huly.envSecret" (dict "name" "MINIO_ROOT_PASSWORD" "key" "MINIO_ROOT_PASSWORD" "root" .) | nindent 12 }}
|
||||
ports:
|
||||
- name: api
|
||||
containerPort: 9000
|
||||
|
||||
@@ -33,7 +33,13 @@
|
||||
{{- $redpandaPwd = randAlphaNum 24 -}}
|
||||
{{- end -}}
|
||||
|
||||
{{- /* STORAGE_CONFIG — explicit values > storage.type config > existing secret > auto-generate */ -}}
|
||||
{{- /* STORAGE_CONFIG — explicit values > storage.type config > built-in MinIO > existing secret */ -}}
|
||||
{{- if eq (include "huly.minioEnabled" .) "true" -}}
|
||||
{{- if or (lt (len .Values.minio.rootUser) 3) (lt (len .Values.minio.rootPassword) 8) -}}
|
||||
{{- fail "MinIO rejects short credentials: minio.rootUser must be at least 3 characters and minio.rootPassword at least 8" -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- $minioStorageConfig := printf "minio|minio?accessKey=%s&secretKey=%s" .Values.minio.rootUser .Values.minio.rootPassword -}}
|
||||
{{- $storageConfig := "" -}}
|
||||
{{- if .Values.secrets.storageConfig -}}
|
||||
{{- $storageConfig = .Values.secrets.storageConfig -}}
|
||||
@@ -46,10 +52,12 @@
|
||||
{{- $s3Params = printf "%s&bucketPrefix=%s" $s3Params .Values.storage.s3.bucketPrefix -}}
|
||||
{{- end -}}
|
||||
{{- $storageConfig = printf "s3|%s?%s" .Values.storage.s3.endpoint $s3Params -}}
|
||||
{{- else if eq (include "huly.minioEnabled" .) "true" -}}
|
||||
{{- $storageConfig = $minioStorageConfig -}}
|
||||
{{- else if and $hasExisting (hasKey $existing.data "STORAGE_CONFIG") -}}
|
||||
{{- $storageConfig = index $existing.data "STORAGE_CONFIG" | b64dec -}}
|
||||
{{- else -}}
|
||||
{{- $storageConfig = printf "minio|minio?accessKey=%s&secretKey=%s" (randAlphaNum 20) (randAlphaNum 40) -}}
|
||||
{{- $storageConfig = $minioStorageConfig -}}
|
||||
{{- end -}}
|
||||
|
||||
{{- /* CR_DB_URL */ -}}
|
||||
@@ -84,6 +92,10 @@ data:
|
||||
COCKROACH_PASSWORD: {{ $cockroachPwd | b64enc | quote }}
|
||||
REDPANDA_SUPERUSER_PASSWORD: {{ $redpandaPwd | b64enc | quote }}
|
||||
STORAGE_CONFIG: {{ $storageConfig | b64enc | quote }}
|
||||
{{- if eq (include "huly.minioEnabled" .) "true" }}
|
||||
MINIO_ROOT_USER: {{ .Values.minio.rootUser | b64enc | quote }}
|
||||
MINIO_ROOT_PASSWORD: {{ .Values.minio.rootPassword | b64enc | quote }}
|
||||
{{- end }}
|
||||
CR_DB_URL: {{ $crDbUrl | b64enc | quote }}
|
||||
AIBOT_PASSWORD: {{ $aibotPwd | b64enc | quote }}
|
||||
{{- if .Values.aibot.enabled }}
|
||||
|
||||
@@ -39,7 +39,8 @@ secrets:
|
||||
# Shared JWT signing secret (auto-generated if empty)
|
||||
serverSecret: ""
|
||||
# Full storage config string override.
|
||||
# When empty, auto-derived from storage.type + storage.s3.* (or random MinIO creds).
|
||||
# When empty, auto-derived from storage.type + storage.s3.* (or minio.rootUser /
|
||||
# minio.rootPassword when using the built-in MinIO).
|
||||
# Format: s3|https://s3.example.com?accessKey=X&secretKey=Y®ion=us-east-1&rootBucket=data
|
||||
# or: minio|minio?accessKey=<key>&secretKey=<secret>
|
||||
storageConfig: ""
|
||||
@@ -169,6 +170,12 @@ minio:
|
||||
# Automatically disabled when storage.type=s3
|
||||
enabled: true
|
||||
image: pgsty/silo
|
||||
# Root credentials for the built-in MinIO. Passed to MinIO as
|
||||
# MINIO_ROOT_USER/MINIO_ROOT_PASSWORD and used to build secrets.storageConfig,
|
||||
# so the two always agree. The defaults are MinIO's own built-in credentials —
|
||||
# change them for anything beyond a trial install.
|
||||
rootUser: minioadmin
|
||||
rootPassword: minioadmin
|
||||
storage: 50Gi
|
||||
storageClassName: ""
|
||||
resources: {}
|
||||
|
||||
Reference in New Issue
Block a user