Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

memex-local up fails on a fresh install: the generated overlay sets ingress.tlsSecret without ingress.clusterIssuer

Open Beginner friendly
#6,019 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
78/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
helm
Domain
devops

Research direction

Read deploy/homebrew/share/values.local.yaml and the guard in deploy/helm/templates/memex-portal/ingress.yaml; the issue identifies both files and the missing setting. Add clusterIssuer: "none" to the overlay's ingress block, then add and run a chart-render test using values.local.defaults.yaml and values.local.yaml. Done means the fresh-install values render without an error.

Written by the indexing model from the issue text.

Description

area:hosting bug sev:M

Repository and prior art

  • The defect is in deploy/homebrew/share/values.local.yaml and deploy/helm/templates/memex-portal/ingress.yaml. Both files are in MeshWeaver core.
  • I searched open and closed issues in Systemorph/MeshWeaver for "memex-local tlsSecret issuer" and "memex-local clusterIssuer". I found no existing issue.

Observed behaviour

On a new Mac with no previous local install, memex-local up --from-acr stops at the Helm step. The time was 2026-10-03, about 14:15 CEST.

Error: execution error at (memex/templates/memex-portal/ingress.yaml:6:4): ingress.tlsSecret is "memex-portal-tls" but NO issuer reaches the ingress. Set ingress.clusterIssuer (the fleet's is letsencrypt-prod), or ingress.clusterIssuer=none when that Secret is created by other means. …

No Helm release is installed. The portal does not start.

Cause

  1. Commit f1a181732 (2026-09-15) added a guard to deploy/helm/templates/memex-portal/ingress.yaml. The guard fails the render when ingress.tlsSecret is set and no issuer is set.
  2. The overlay template deploy/homebrew/share/values.local.yaml sets ingress.tlsSecret: "memex-portal-tls". It does not set ingress.clusterIssuer.
  3. memex-local up creates the secret memex-portal-tls itself with mkcert. Locally, clusterIssuer: "none" is therefore the correct value.
  4. ensure_overlay copies the template only when ~/.memex-local/values.local.yaml does not exist. Existing installs keep their old overlay. Every new install gets the defective overlay.

Affected version: Homebrew memex-local 0.2.16194. The overlay template on main (2baaf9ef4) has the same content.

Workaround

Add one line to the ingress block in ~/.memex-local/values.local.yaml:

ingress:
  enabled: true
  host: "memex.localhost"
  tlsSecret: "memex-portal-tls"
  clusterIssuer: "none"

After this change, helm template renders the ingress with the annotation meshweaver.io/tls-secret: "pre-provisioned".

Expected behaviour

A fresh memex-local up installs the Helm release without a manual change to the overlay.

Proposed fix

  1. Add clusterIssuer: "none" to the ingress block in deploy/homebrew/share/values.local.yaml.
  2. Add a test that renders the chart with values.local.defaults.yaml and values.local.yaml, and expects no render error.

Severity

sev:M — easy workaround exists.

🤖 Generated with Claude Code

Dominant language
C#
Stars
12
Forks
5
Avg merge
4h 1m
Merged PRs (30d)
979

Getting set up

  • No Dockerfile or Docker Compose file
  • Has a pull request template
  • No contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from Systemorph/MeshWeaver

All issues in Systemorph/MeshWeaver

Similar issues

More C# issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.