memex-local up fails on a fresh install: the generated overlay sets ingress.tlsSecret without ingress.clusterIssuer
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 78/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- helm
- Domain
- devops
Research direction
Read deploy/homebrew/share/values.local.yaml and the guard in deploy/helm/templates/memex-portal/ingress.yaml; the issue identifies both files and the missing setting. Add clusterIssuer: "none" to the overlay's ingress block, then add and run a chart-render test using values.local.defaults.yaml and values.local.yaml. Done means the fresh-install values render without an error.
Written by the indexing model from the issue text.
Description
Repository and prior art
- The defect is in
deploy/homebrew/share/values.local.yamlanddeploy/helm/templates/memex-portal/ingress.yaml. Both files are in MeshWeaver core. - I searched open and closed issues in Systemorph/MeshWeaver for "memex-local tlsSecret issuer" and "memex-local clusterIssuer". I found no existing issue.
Observed behaviour
On a new Mac with no previous local install, memex-local up --from-acr stops at the Helm step. The time was 2026-10-03, about 14:15 CEST.
Error: execution error at (memex/templates/memex-portal/ingress.yaml:6:4): ingress.tlsSecret is "memex-portal-tls" but NO issuer reaches the ingress. Set ingress.clusterIssuer (the fleet's is letsencrypt-prod), or ingress.clusterIssuer=none when that Secret is created by other means. …
No Helm release is installed. The portal does not start.
Cause
- Commit f1a181732 (2026-09-15) added a guard to
deploy/helm/templates/memex-portal/ingress.yaml. The guard fails the render wheningress.tlsSecretis set and no issuer is set. - The overlay template
deploy/homebrew/share/values.local.yamlsetsingress.tlsSecret: "memex-portal-tls". It does not setingress.clusterIssuer. memex-local upcreates the secretmemex-portal-tlsitself with mkcert. Locally,clusterIssuer: "none"is therefore the correct value.ensure_overlaycopies the template only when~/.memex-local/values.local.yamldoes not exist. Existing installs keep their old overlay. Every new install gets the defective overlay.
Affected version: Homebrew memex-local 0.2.16194. The overlay template on main (2baaf9ef4) has the same content.
Workaround
Add one line to the ingress block in ~/.memex-local/values.local.yaml:
ingress:
enabled: true
host: "memex.localhost"
tlsSecret: "memex-portal-tls"
clusterIssuer: "none"
After this change, helm template renders the ingress with the annotation meshweaver.io/tls-secret: "pre-provisioned".
Expected behaviour
A fresh memex-local up installs the Helm release without a manual change to the overlay.
Proposed fix
- Add
clusterIssuer: "none"to theingressblock indeploy/homebrew/share/values.local.yaml. - Add a test that renders the chart with
values.local.defaults.yamlandvalues.local.yaml, and expects no render error.
Severity
sev:M — easy workaround exists.
🤖 Generated with Claude Code
- Dominant language
- C#
- Stars
- 12
- Forks
- 5
- Avg merge
- 4h 1m
- Merged PRs (30d)
- 979
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from Systemorph/MeshWeaver
-
area:search documentation
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Systemorph/MeshWeaver#6030 ·
Maintainers usually reply within 1 day
-
ApiTokenService.RevokeToken posts its revocation SaveMeshNodeRequest from the mesh (router) hub instead of a node-operation hubPossibly taken A pull request linked to this issue is open or already merged. Openbug sev:M
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Systemorph/MeshWeaver#6026 · 3 comments ·
Maintainers usually reply within 1 day
-
bug sev:L
Difficulty 1/5 1-3 hours Newbie friendliness 76/100
Systemorph/MeshWeaver#6011 · 1 comment ·
Maintainers usually reply within 1 day
-
bug sev:B
Difficulty 4/5 3-5 days Newbie friendliness 12/100
Systemorph/MeshWeaver#6343 ·
Maintainers usually reply within 1 day
-
bug sev:L
Difficulty 4/5 3-5 days Newbie friendliness 30/100
Systemorph/MeshWeaver#6307 · 2 comments ·
Maintainers usually reply within 1 day
All issues in Systemorph/MeshWeaver
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
PCL-Community/PCL-CE#3658 ·
Maintainers usually reply within 1 day
-
Deploy & Patch-issues opprettes ikke: create-pnd-issues.yml har feilet hver uke siden 2025-09-08Open
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Altinn/altinn-auth#4359 ·
Maintainers usually reply within 1 day
-
type/automation type/tech-debt
Difficulty 1/5 Under an hour Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
no-stack-trace
Difficulty 2/5 1-3 hours Newbie friendliness 83/100
Maintainers usually reply within 1 day
-
S: Untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
project-wayfarer/wayfarer-14#1650 ·
Maintainers usually reply within 2 days