Grafana Admin Credentials Sourcing from PVC Instead of Secret
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- helm, kubernetes
- Domain
- devops, infrastructure
Research direction
Start with the values.yaml configuration and reproduce the deployment using the documented helm upgrade --install command. Inspect the rendered chart configuration and the existing PVC state to determine which credential source is used. Done means a deployment with an existing PVC authenticates with the credentials from devlake-grafana-secret.
Written by the indexing model from the issue text.
Description
Description:
We are using DevLake's Helm chart to deploy Grafana in our Kubernetes cluster. However, despite configuring Grafana to use a pre-existing Kubernetes secret for the admin credentials, it appears that Grafana is still sourcing the admin credentials from the PVC. This is causing login issues where the password from the PVC is used instead of the password stored in the secret.
Steps to Reproduce:
Deployment Configuration: We have the following configuration in values.yaml:
persistence:
type: pvc
enabled: false
# storageClassName: default
accessModes:
- ReadWriteOnce
size: 10Gi
# annotations: {}
finalizers:
- kubernetes.io/pvc-protection
admin:
existingSecret: "devlake-grafana-secret"
userKey: admin-user
passwordKey: admin-password
Secret Creation: We have already created the secret (devlake-grafana-secret) with the following credentials:
kubectl create secret generic devlake-grafana-secret \
--from-literal=admin-user="admin" \
--from-literal=admin-password="yourStrongPassword"
Deployment: We then deploy or upgrade the Helm chart using the following command:
helm upgrade --install devlake-grafana grafana/grafana -f values.yaml
Login Attempt: After deployment, when we try to log in to Grafana using the admin user and the password (yourStrongPassword), we are unable to authenticate.
Expected Behavior:
- Use the admin credentials from the Kubernetes secret (devlake-grafana-secret) as configured in the values.yaml.
- Not use the credentials from the PVC, which are incorrect or outdated.
Actual Behavior:
Despite correctly configuring the secret in the values.yaml file, Grafana seems to be sourcing the admin credentials from the PVC, causing a failed login with the password stored in the PVC instead of the password defined in the secret.
I mentioned that it's using the PVC values because the PVC wasn’t deleted. The password currently working is the one that was set during the initial installation.
Impact:
Inability to login with the expected admin credentials (from the secret).
We are unable to authenticate as the admin user using the correct credentials.
Environment:
DevLake Version: 1.0.3-beta1
- Dominant language
- Go Template
- Stars
- 52
- Forks
- 71
- Avg merge
- 16h 15m
- Merged PRs (30d)
- 1
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/devlake-helm-chart
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
apache/devlake-helm-chart#367 · 6 comments · 2 reactions ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
apache/devlake-helm-chart#366 · 1 comment ·
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
apache/devlake-helm-chart#381 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
apache/devlake-helm-chart#374 · 1 comment ·
-
Difficulty 3/5 1-2 days Newbie friendliness 35/100
apache/devlake-helm-chart#373 · 1 comment ·
All issues in apache/devlake-helm-chart
Similar issues
-
omarchy-windows-vm launch fails with false 'Failed to start Windows VM' when VM is already runningOpen
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
Maintainers usually reply within 1 day
-
kind/engineering pulumi/pulumi-terraform Task Workflow Failure
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
pulumi/pulumi-terraform#1215 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
agilepathway/label-checker#710 · 2 comments ·
Maintainers usually reply within 1 day
-
ci OpenScPCA admin
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
AlexsLemonade/OpenScPCA-analysis#1436 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Cocoanetics/SwiftBash#95 ·