[Regression / Discussion] Loss of hot-reloaded password rotation after removal of k8s_secret_* in 0.27.4
Maintainers usually reply within 2 days
@sunsingerus is already working on this.
Since Oct 5, 2026.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 38/100
Research direction
Start with docs/security_hardening.md and the ClickHouseInstallation user configuration path that handles valueFrom/secretKeyRef. Reproduce secret rotation followed by reconciliation, checking whether generated files under /etc/clickhouse-server/users.d/ change without restarting pods. Done means the supported rotation behavior is documented or the proposed zero-downtime mechanism is implemented and verified.
Written by the indexing model from the issue text.
Description
Description
In release 0.27.4, support for the k8s_secret_* syntax was removed in favor of standard valueFrom / secretKeyRef references in ClickHouseInstallation user configurations (see Altinity ClickHouse Operator Security Hardening Documentation).
While migrating to secretKeyRef enforces namespace isolation and proper RBAC, it introduces an operational regression regarding password rotation and zero-downtime hot-reloading.
Regression Details
-
Environment Variable Immutability:
WithvalueFrom / secretKeyRef, secret values are passed into theclickhouse-servercontainer as environment variables. The operator then renders XML references using thefrom_envattribute:<password from_env="CONFIGURATION_USERS_ADMIN_PASSWORD"></password>Since Kubernetes environment variables cannot be updated dynamically inside a running container, changing the underlying Kubernetes Secret value has no effect on running ClickHouse processes.
-
Broken Password Rotation Workflow:
- Previous Behavior (
< 0.27.4):- Update the password in the Kubernetes Secret.
- Trigger CHI reconciliation (e.g., updating a
taskIDannotation). - The operator updated the mounted ConfigMap with the new password/hash.
- ClickHouse automatically hot-reloaded the updated XML files from disk without restarting pods.
- Current Behavior (
0.27.4):- Updating the Kubernetes Secret and triggering reconciliation leaves the XML unchanged, as it only references static environment variable names.
- Tested and confirmed: The updated secret value is not picked up until pods are restarted.
- Impact: Rotating a password now requires a full rollout restart of all
clickhouse-serverpods.
- Previous Behavior (
Questions & Feature Suggestions
- Expected Rotation Strategy: Is requiring a full pod rollout restart the intended behavior for password rotation moving forward, or is there a supported method to achieve zero-downtime credential updates?
- Proposal (Secret Volume Mounts): Why not support mounting Kubernetes Secrets directly as files into
/etc/clickhouse-server/users.d/(or a mounted secrets directory) instead of injecting them as environment variables?- Mounting secrets directly would maintain proper RBAC and namespace security while restoring ClickHouse's native file-watching hot-reload capabilities.
- Dominant language
- Go
- Stars
- 2.6k
- Forks
- 577
- Avg merge
- 1d 6h
- Merged PRs (30d)
- 4
Getting set up
- Ships a Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from Altinity/clickhouse-operator
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Altinity/clickhouse-operator#2093 ·
Maintainers usually reply within 2 days
-
Difficulty 3/5 1-2 days Newbie friendliness 68/100
Altinity/clickhouse-operator#2089 ·
Maintainers usually reply within 2 days
-
Difficulty 5/5 Over a week Newbie friendliness 45/100
Altinity/clickhouse-operator#2064 · 3 comments ·
Maintainers usually reply within 2 days
-
big deployment planned for review
Difficulty 4/5 3-5 days Newbie friendliness 52/100
Altinity/clickhouse-operator#2063 ·
Maintainers usually reply within 2 days
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
Altinity/clickhouse-operator#2056 ·
Maintainers usually reply within 2 days
All issues in Altinity/clickhouse-operator
Similar issues
-
[submenu] nil issue on ubuntu 26.04Possibly taken @egoist claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
prime-radiant-inc/evener#3873 ·
Maintainers usually reply within 1 day
-
extract_llm_sweep / cache_aware_summarizer prefix ask 400s when thinking.budget_tokens exceeds PrefixAskMaxTokensPossibly taken @amiddavid claimed this today. Open
Difficulty 1/5 Under an hour Newbie friendliness 85/100
rossoctl/context-guru#405 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 80/100
router-for-me/CLIProxyAPI#6423 ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 2 days