From ca3808a57c83518b971343df7d073753f38796ed Mon Sep 17 00:00:00 2001 From: Nayeem Syed Date: Tue, 29 Sep 2026 07:29:51 +0100 Subject: [PATCH] fix(helm): make built-in MinIO credentials match STORAGE_CONFIG (#324) The generated STORAGE_CONFIG carried randAlphaNum access/secret keys, but the MinIO deployment set no MINIO_ROOT_USER/MINIO_ROOT_PASSWORD, so MinIO ran on its built-in credentials and rejected those keys with InvalidAccessKeyId. Root credentials now come from minio.rootUser/minio.rootPassword, are injected into MinIO, and build the default STORAGE_CONFIG, so the two always agree. Defaults match MinIO's built-ins, which is what running deployments actually use today, and can now be overridden. Values shorter than MinIO accepts fail at template time instead of crash-looping the pod. Signed-off-by: Artyom Savchenko Co-authored-by: Artyom Savchenko --- helm/huly/README.md | 16 ++++++++++++++++ helm/huly/templates/minio/deployment.yaml | 3 +++ helm/huly/templates/secret.yaml | 16 ++++++++++++++-- helm/huly/values.yaml | 9 ++++++++- 4 files changed, 41 insertions(+), 3 deletions(-) diff --git a/helm/huly/README.md b/helm/huly/README.md index da8ea0a..1c118e2 100644 --- a/helm/huly/README.md +++ b/helm/huly/README.md @@ -73,6 +73,20 @@ helm install huly ./helm/huly \ Setting `storage.type=s3` automatically disables the built-in MinIO deployment and PVC. +### Built-in MinIO credentials + +The built-in MinIO runs with `minio.rootUser` / `minio.rootPassword`, and the generated +`STORAGE_CONFIG` uses the same pair. They default to MinIO's own built-in credentials; override +both to change them: + +```bash +--set minio.rootUser=huly \ +--set minio.rootPassword=YOUR_PASSWORD +``` + +Changing them on an existing install rotates MinIO's root credentials — stored objects are +unaffected, but any other client of that MinIO must be updated too. + **Bucket modes:** - `rootBucket` — all workspaces share one bucket, isolated by workspace-ID prefix (recommended) - `bucketPrefix` — each workspace gets its own bucket, prefixed with this string @@ -345,6 +359,8 @@ Each infra service can be disabled to use an external instance. When disabled, p | `elastic.javaOpts` | JVM heap options | `-Xms1024m -Xmx1024m` | | `minio.enabled` | Deploy built-in MinIO | `true` | | `minio.image` | MinIO-compatible Silo image | `pgsty/silo` | +| `minio.rootUser` | Built-in MinIO root user (also used in `STORAGE_CONFIG`) | `minioadmin` | +| `minio.rootPassword` | Built-in MinIO root password (also used in `STORAGE_CONFIG`) | `minioadmin` | | `minio.storage` | Data PVC size | `50Gi` | | `minio.storageClassName` | PVC storage class | `""` | diff --git a/helm/huly/templates/minio/deployment.yaml b/helm/huly/templates/minio/deployment.yaml index 02d78c0..5dcd0b9 100644 --- a/helm/huly/templates/minio/deployment.yaml +++ b/helm/huly/templates/minio/deployment.yaml @@ -30,6 +30,9 @@ spec: - ":9000" - --console-address - ":9001" + env: + {{- include "huly.envSecret" (dict "name" "MINIO_ROOT_USER" "key" "MINIO_ROOT_USER" "root" .) | nindent 12 }} + {{- include "huly.envSecret" (dict "name" "MINIO_ROOT_PASSWORD" "key" "MINIO_ROOT_PASSWORD" "root" .) | nindent 12 }} ports: - name: api containerPort: 9000 diff --git a/helm/huly/templates/secret.yaml b/helm/huly/templates/secret.yaml index 1815e98..4cc74c0 100644 --- a/helm/huly/templates/secret.yaml +++ b/helm/huly/templates/secret.yaml @@ -33,7 +33,13 @@ {{- $redpandaPwd = randAlphaNum 24 -}} {{- end -}} -{{- /* STORAGE_CONFIG — explicit values > storage.type config > existing secret > auto-generate */ -}} +{{- /* STORAGE_CONFIG — explicit values > storage.type config > built-in MinIO > existing secret */ -}} +{{- if eq (include "huly.minioEnabled" .) "true" -}} + {{- if or (lt (len .Values.minio.rootUser) 3) (lt (len .Values.minio.rootPassword) 8) -}} + {{- fail "MinIO rejects short credentials: minio.rootUser must be at least 3 characters and minio.rootPassword at least 8" -}} + {{- end -}} +{{- end -}} +{{- $minioStorageConfig := printf "minio|minio?accessKey=%s&secretKey=%s" .Values.minio.rootUser .Values.minio.rootPassword -}} {{- $storageConfig := "" -}} {{- if .Values.secrets.storageConfig -}} {{- $storageConfig = .Values.secrets.storageConfig -}} @@ -46,10 +52,12 @@ {{- $s3Params = printf "%s&bucketPrefix=%s" $s3Params .Values.storage.s3.bucketPrefix -}} {{- end -}} {{- $storageConfig = printf "s3|%s?%s" .Values.storage.s3.endpoint $s3Params -}} +{{- else if eq (include "huly.minioEnabled" .) "true" -}} + {{- $storageConfig = $minioStorageConfig -}} {{- else if and $hasExisting (hasKey $existing.data "STORAGE_CONFIG") -}} {{- $storageConfig = index $existing.data "STORAGE_CONFIG" | b64dec -}} {{- else -}} - {{- $storageConfig = printf "minio|minio?accessKey=%s&secretKey=%s" (randAlphaNum 20) (randAlphaNum 40) -}} + {{- $storageConfig = $minioStorageConfig -}} {{- end -}} {{- /* CR_DB_URL */ -}} @@ -84,6 +92,10 @@ data: COCKROACH_PASSWORD: {{ $cockroachPwd | b64enc | quote }} REDPANDA_SUPERUSER_PASSWORD: {{ $redpandaPwd | b64enc | quote }} STORAGE_CONFIG: {{ $storageConfig | b64enc | quote }} + {{- if eq (include "huly.minioEnabled" .) "true" }} + MINIO_ROOT_USER: {{ .Values.minio.rootUser | b64enc | quote }} + MINIO_ROOT_PASSWORD: {{ .Values.minio.rootPassword | b64enc | quote }} + {{- end }} CR_DB_URL: {{ $crDbUrl | b64enc | quote }} AIBOT_PASSWORD: {{ $aibotPwd | b64enc | quote }} {{- if .Values.aibot.enabled }} diff --git a/helm/huly/values.yaml b/helm/huly/values.yaml index 8febf06..2e2b8ce 100644 --- a/helm/huly/values.yaml +++ b/helm/huly/values.yaml @@ -39,7 +39,8 @@ secrets: # Shared JWT signing secret (auto-generated if empty) serverSecret: "" # Full storage config string override. - # When empty, auto-derived from storage.type + storage.s3.* (or random MinIO creds). + # When empty, auto-derived from storage.type + storage.s3.* (or minio.rootUser / + # minio.rootPassword when using the built-in MinIO). # Format: s3|https://s3.example.com?accessKey=X&secretKey=Y®ion=us-east-1&rootBucket=data # or: minio|minio?accessKey=&secretKey= storageConfig: "" @@ -169,6 +170,12 @@ minio: # Automatically disabled when storage.type=s3 enabled: true image: pgsty/silo + # Root credentials for the built-in MinIO. Passed to MinIO as + # MINIO_ROOT_USER/MINIO_ROOT_PASSWORD and used to build secrets.storageConfig, + # so the two always agree. The defaults are MinIO's own built-in credentials — + # change them for anything beyond a trial install. + rootUser: minioadmin + rootPassword: minioadmin storage: 50Gi storageClassName: "" resources: {}