Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Grafana Admin Credentials Sourcing from PVC Instead of Secret

Open
#343 1 comment 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
helm, kubernetes

Research direction

Start with the values.yaml configuration and reproduce the deployment using the documented helm upgrade --install command. Inspect the rendered chart configuration and the existing PVC state to determine which credential source is used. Done means a deployment with an existing PVC authenticates with the credentials from devlake-grafana-secret.

Written by the indexing model from the issue text.

Description

Description:

We are using DevLake's Helm chart to deploy Grafana in our Kubernetes cluster. However, despite configuring Grafana to use a pre-existing Kubernetes secret for the admin credentials, it appears that Grafana is still sourcing the admin credentials from the PVC. This is causing login issues where the password from the PVC is used instead of the password stored in the secret.

Steps to Reproduce:
Deployment Configuration: We have the following configuration in values.yaml:

persistence:
  type: pvc
  enabled: false
  # storageClassName: default
  accessModes:
    - ReadWriteOnce
  size: 10Gi
  # annotations: {}
  finalizers:
    - kubernetes.io/pvc-protection

  
admin:
  existingSecret: "devlake-grafana-secret"
  userKey: admin-user
  passwordKey: admin-password

Secret Creation: We have already created the secret (devlake-grafana-secret) with the following credentials:

kubectl create secret generic devlake-grafana-secret \
  --from-literal=admin-user="admin" \
  --from-literal=admin-password="yourStrongPassword"

Deployment: We then deploy or upgrade the Helm chart using the following command:

helm upgrade --install devlake-grafana grafana/grafana -f values.yaml
Login Attempt: After deployment, when we try to log in to Grafana using the admin user and the password (yourStrongPassword), we are unable to authenticate.

Expected Behavior:

  • Use the admin credentials from the Kubernetes secret (devlake-grafana-secret) as configured in the values.yaml.
  • Not use the credentials from the PVC, which are incorrect or outdated.

Actual Behavior:
Despite correctly configuring the secret in the values.yaml file, Grafana seems to be sourcing the admin credentials from the PVC, causing a failed login with the password stored in the PVC instead of the password defined in the secret.
I mentioned that it's using the PVC values because the PVC wasn’t deleted. The password currently working is the one that was set during the initial installation.

Impact:
Inability to login with the expected admin credentials (from the secret).
We are unable to authenticate as the admin user using the correct credentials.

Environment:
DevLake Version: 1.0.3-beta1

Dominant language
Go Template
Stars
52
Forks
71
Avg merge
16h 15m
Merged PRs (30d)
1

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/devlake-helm-chart

All issues in apache/devlake-helm-chart

Similar issues

More DevOps issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.