Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Feature Request]: use random passwords by default

Open
#329 4 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
45/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Stale
Tech stack
helm, kubernetes

Research direction

Start by inspecting the chart values for lake.encryptionSecret.secret, mysql.username, mysql.password, and the ui.basicAuth settings, then compare them with the existing Grafana secret workflow. Render the chart to verify random credentials, enabled UI authentication, and Secret objects containing the values requested by users.

Written by the indexing model from the issue text.

Description

This helm chart currently deploys a very insecure devlake instance by default: authentication for the UI is disabled, DB passwords are hardcoded while the user is asked to generate the cumbersome encryption key manually which is exported as an env var and lost immediately anyways.

This makes the setup quite vulnerable by so I propose populating all access credentials with random values if they are not explicitly set and have the user retrieve them from the created secret objects if needed. This is already the workflow for Grafana and works just fine.

Specifically:

Value Current default Proposed default
lake.encryptionSecret.secret manually provided by user random
mysql.username merico random
mysql.password merico random
ui.basicAuth.enabled false true
ui.basicAuth.password - random
Dominant language
Go Template
Stars
52
Forks
71
Avg merge
16h 15m
Merged PRs (30d)
1

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/devlake-helm-chart

All issues in apache/devlake-helm-chart

Similar issues

More DevOps issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.