Add ENCODE_KEY helm values inputs
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 35/100
- Issue type
- Feature
- Clarity
- Clearly specified
- Activity status
- Stale
- Tech stack
- helm, kubernetes
- Domain
- devops, infrastructure
Research direction
Start with the chart's default values file and review how values are passed to the lake container. Add the documented encodeKey secretName and secretKey inputs, including the provided guidance about ENCODE_KEY and persistence. Done means users can configure the encryption key through a Kubernetes Secret and the default values clearly explain the fallback behavior.
Written by the indexing model from the issue text.
Description
We recently found out the hard way about the encKey used to encrypt things in the database. It would be helpful for users deploying on kubernetes if the default values file contained references to this feature so that it is more obvious that it can be set (rather than generated by a container that may not persist).
My suggestion is to add inputs in the values file like:
# This is the string used to encrypt sensitive things like PATs in the database.
# Alternatively, you may supply this value to the `lake` container directly as environment variable `ENCODE_KEY`
# If unset, a key will be created dynamically, in which case you should retrieve it and store it somewhere secure and persistent
encodeKey:
secretName: "" # the name of the Secret containing this encryption key
secretKey: "" # the name of the key within that Secret which contains the encryption key as its value
- Dominant language
- Go Template
- Stars
- 52
- Forks
- 71
- Avg merge
- 16h 15m
- Merged PRs (30d)
- 1
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/devlake-helm-chart
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
apache/devlake-helm-chart#367 · 6 comments · 2 reactions ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
apache/devlake-helm-chart#366 · 1 comment ·
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
apache/devlake-helm-chart#381 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
apache/devlake-helm-chart#374 · 1 comment ·
-
Difficulty 3/5 1-2 days Newbie friendliness 35/100
apache/devlake-helm-chart#373 · 1 comment ·
All issues in apache/devlake-helm-chart
Similar issues
-
deployment release-lag
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
nolte/kamerplanter#2047 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
plengauer/DXGIOutputDuplication#81 ·
Maintainers usually reply within 1 day
-
omarchy-windows-vm launch fails with false 'Failed to start Windows VM' when VM is already runningOpen
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
Maintainers usually reply within 1 day
-
kind/engineering pulumi/pulumi-terraform Task Workflow Failure
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
pulumi/pulumi-terraform#1215 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
agilepathway/label-checker#710 · 2 comments ·
Maintainers usually reply within 1 day