fix(helm): make built-in MinIO credentials match STORAGE_CONFIG (#324)

The generated STORAGE_CONFIG carried randAlphaNum access/secret keys,
but the MinIO deployment set no MINIO_ROOT_USER/MINIO_ROOT_PASSWORD, so
MinIO ran on its built-in credentials and rejected those keys with
InvalidAccessKeyId.

Root credentials now come from minio.rootUser/minio.rootPassword, are
injected into MinIO, and build the default STORAGE_CONFIG, so the two
always agree. Defaults match MinIO's built-ins, which is what running
deployments actually use today, and can now be overridden. Values
shorter than MinIO accepts fail at template time instead of
crash-looping the pod.

Signed-off-by: Artyom Savchenko <armisav@gmail.com>
Co-authored-by: Artyom Savchenko <armisav@gmail.com>
This commit is contained in:
Nayeem Syed
2026-09-29 08:29:51 +02:00
committed by GitHub
co-authored by Artyom Savchenko
parent c32e79dcb4
commit ca3808a57c
4 changed files with 41 additions and 3 deletions
+16
View File
@@ -73,6 +73,20 @@ helm install huly ./helm/huly \
Setting `storage.type=s3` automatically disables the built-in MinIO deployment and PVC.
### Built-in MinIO credentials
The built-in MinIO runs with `minio.rootUser` / `minio.rootPassword`, and the generated
`STORAGE_CONFIG` uses the same pair. They default to MinIO's own built-in credentials; override
both to change them:
```bash
--set minio.rootUser=huly \
--set minio.rootPassword=YOUR_PASSWORD
```
Changing them on an existing install rotates MinIO's root credentials — stored objects are
unaffected, but any other client of that MinIO must be updated too.
**Bucket modes:**
- `rootBucket` — all workspaces share one bucket, isolated by workspace-ID prefix (recommended)
- `bucketPrefix` — each workspace gets its own bucket, prefixed with this string
@@ -345,6 +359,8 @@ Each infra service can be disabled to use an external instance. When disabled, p
| `elastic.javaOpts` | JVM heap options | `-Xms1024m -Xmx1024m` |
| `minio.enabled` | Deploy built-in MinIO | `true` |
| `minio.image` | MinIO-compatible Silo image | `pgsty/silo` |
| `minio.rootUser` | Built-in MinIO root user (also used in `STORAGE_CONFIG`) | `minioadmin` |
| `minio.rootPassword` | Built-in MinIO root password (also used in `STORAGE_CONFIG`) | `minioadmin` |
| `minio.storage` | Data PVC size | `50Gi` |
| `minio.storageClassName` | PVC storage class | `""` |
@@ -30,6 +30,9 @@ spec:
- ":9000"
- --console-address
- ":9001"
env:
{{- include "huly.envSecret" (dict "name" "MINIO_ROOT_USER" "key" "MINIO_ROOT_USER" "root" .) | nindent 12 }}
{{- include "huly.envSecret" (dict "name" "MINIO_ROOT_PASSWORD" "key" "MINIO_ROOT_PASSWORD" "root" .) | nindent 12 }}
ports:
- name: api
containerPort: 9000
+14 -2
View File
@@ -33,7 +33,13 @@
{{- $redpandaPwd = randAlphaNum 24 -}}
{{- end -}}
{{- /* STORAGE_CONFIG — explicit values > storage.type config > existing secret > auto-generate */ -}}
{{- /* STORAGE_CONFIG — explicit values > storage.type config > built-in MinIO > existing secret */ -}}
{{- if eq (include "huly.minioEnabled" .) "true" -}}
{{- if or (lt (len .Values.minio.rootUser) 3) (lt (len .Values.minio.rootPassword) 8) -}}
{{- fail "MinIO rejects short credentials: minio.rootUser must be at least 3 characters and minio.rootPassword at least 8" -}}
{{- end -}}
{{- end -}}
{{- $minioStorageConfig := printf "minio|minio?accessKey=%s&secretKey=%s" .Values.minio.rootUser .Values.minio.rootPassword -}}
{{- $storageConfig := "" -}}
{{- if .Values.secrets.storageConfig -}}
{{- $storageConfig = .Values.secrets.storageConfig -}}
@@ -46,10 +52,12 @@
{{- $s3Params = printf "%s&bucketPrefix=%s" $s3Params .Values.storage.s3.bucketPrefix -}}
{{- end -}}
{{- $storageConfig = printf "s3|%s?%s" .Values.storage.s3.endpoint $s3Params -}}
{{- else if eq (include "huly.minioEnabled" .) "true" -}}
{{- $storageConfig = $minioStorageConfig -}}
{{- else if and $hasExisting (hasKey $existing.data "STORAGE_CONFIG") -}}
{{- $storageConfig = index $existing.data "STORAGE_CONFIG" | b64dec -}}
{{- else -}}
{{- $storageConfig = printf "minio|minio?accessKey=%s&secretKey=%s" (randAlphaNum 20) (randAlphaNum 40) -}}
{{- $storageConfig = $minioStorageConfig -}}
{{- end -}}
{{- /* CR_DB_URL */ -}}
@@ -84,6 +92,10 @@ data:
COCKROACH_PASSWORD: {{ $cockroachPwd | b64enc | quote }}
REDPANDA_SUPERUSER_PASSWORD: {{ $redpandaPwd | b64enc | quote }}
STORAGE_CONFIG: {{ $storageConfig | b64enc | quote }}
{{- if eq (include "huly.minioEnabled" .) "true" }}
MINIO_ROOT_USER: {{ .Values.minio.rootUser | b64enc | quote }}
MINIO_ROOT_PASSWORD: {{ .Values.minio.rootPassword | b64enc | quote }}
{{- end }}
CR_DB_URL: {{ $crDbUrl | b64enc | quote }}
AIBOT_PASSWORD: {{ $aibotPwd | b64enc | quote }}
{{- if .Values.aibot.enabled }}
+8 -1
View File
@@ -39,7 +39,8 @@ secrets:
# Shared JWT signing secret (auto-generated if empty)
serverSecret: ""
# Full storage config string override.
# When empty, auto-derived from storage.type + storage.s3.* (or random MinIO creds).
# When empty, auto-derived from storage.type + storage.s3.* (or minio.rootUser /
# minio.rootPassword when using the built-in MinIO).
# Format: s3|https://s3.example.com?accessKey=X&secretKey=Y&region=us-east-1&rootBucket=data
# or: minio|minio?accessKey=<key>&secretKey=<secret>
storageConfig: ""
@@ -169,6 +170,12 @@ minio:
# Automatically disabled when storage.type=s3
enabled: true
image: pgsty/silo
# Root credentials for the built-in MinIO. Passed to MinIO as
# MINIO_ROOT_USER/MINIO_ROOT_PASSWORD and used to build secrets.storageConfig,
# so the two always agree. The defaults are MinIO's own built-in credentials —
# change them for anything beyond a trial install.
rootUser: minioadmin
rootPassword: minioadmin
storage: 50Gi
storageClassName: ""
resources: {}