[Feature Request]: use random passwords by default
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 45/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- helm, kubernetes
- Domain
- infrastructure, security
Research direction
Start by inspecting the chart values for lake.encryptionSecret.secret, mysql.username, mysql.password, and the ui.basicAuth settings, then compare them with the existing Grafana secret workflow. Render the chart to verify random credentials, enabled UI authentication, and Secret objects containing the values requested by users.
Written by the indexing model from the issue text.
Description
This helm chart currently deploys a very insecure devlake instance by default: authentication for the UI is disabled, DB passwords are hardcoded while the user is asked to generate the cumbersome encryption key manually which is exported as an env var and lost immediately anyways.
This makes the setup quite vulnerable by so I propose populating all access credentials with random values if they are not explicitly set and have the user retrieve them from the created secret objects if needed. This is already the workflow for Grafana and works just fine.
Specifically:
| Value | Current default | Proposed default |
|---|---|---|
lake.encryptionSecret.secret |
manually provided by user | random |
mysql.username |
merico | random |
mysql.password |
merico | random |
ui.basicAuth.enabled |
false | true |
ui.basicAuth.password |
- | random |
- Dominant language
- Go Template
- Stars
- 52
- Forks
- 71
- Avg merge
- 16h 15m
- Merged PRs (30d)
- 1
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/devlake-helm-chart
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
apache/devlake-helm-chart#367 · 6 comments · 2 reactions ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
apache/devlake-helm-chart#366 · 1 comment ·
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
apache/devlake-helm-chart#381 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
apache/devlake-helm-chart#374 · 1 comment ·
-
Difficulty 3/5 1-2 days Newbie friendliness 35/100
apache/devlake-helm-chart#373 · 1 comment ·
All issues in apache/devlake-helm-chart
Similar issues
-
priority: P3 type: devops
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
jiegui2025/hwspec#57 ·
Maintainers usually reply within 1 day
-
area: release bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
TMHSDigital/subenum#102 ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 1 day
-
ai-inspected
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
dockur/windows-arm#611 · 3 comments · 1 reaction ·