nextcloud.openmetrics.allowedClients is silently ignored unless nextcloud.configs is set
評価
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 初心者へのやさしさ
- 78/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- helm, kubernetes
- 領域
- devops, infrastructure
調査の方向性
Read charts/nextcloud/templates/_helpers.tpl and templates/config.yaml, focusing on the defaultConfigs guard and ConfigMap rendering. Render the chart with openmetrics.allowedClients set while nextcloud.configs is empty, then verify that helm-metrics.config.php is mounted and the setting is available to Nextcloud without unrelated configuration.
索引モデルが issue の本文から書いたものです。
説明
Describe the bug
nextcloud.openmetrics.allowedClients renders OPENMETRICS_ALLOWED_CLIENTS into the app
container, but nothing in the pod ever reads it. The only reader is
files/defaultConfigs/helm-metrics.config.php.tpl, and the defaultConfigs files are only
mounted when nextcloud.configs is non-empty
(_helpers.tpl#L431);
templates/config.yaml renders no ConfigMap at all otherwise.
So with the chart's default nextcloud.configs: {}, setting allowedClients does nothing:
Nextcloud keeps its built-in default of 127.0.0.1 only, and Prometheus is refused with 403.
This is the same gate reported in #761, but it bites differently here. The argument there for
keeping it — "normally you do not need the defaultConfig, because the files are already part of
the container image" — does not hold for helm-metrics.config.php. Like imaginary.config.php,
it is a chart file, not one of nextcloud/docker's.
There is no image copy to fall back on, so nextcloud.openmetrics.allowedClients cannot work on
its own under any configuration.
It also affects the chart's own defaults: prometheus.serviceMonitor selects the app Service as
well as the exporter Service, so an out-of-the-box metrics.enabled: true +
prometheus.serviceMonitor.enabled: true install scrapes /metrics on the app pod, gets a 403,
and sits with a permanently down target firing TargetDown.
Steps to reproduce
nextcloud:
openmetrics:
allowedClients:
- "127.0.0.1"
- "10.244.0.0/16" # your pod CIDR
metrics:
enabled: true
prometheus:
serviceMonitor:
enabled: true
$ kubectl exec deploy/nextcloud -c nextcloud -- sh -c 'echo $OPENMETRICS_ALLOWED_CLIENTS'
127.0.0.1,10.244.0.0/16
$ kubectl exec deploy/nextcloud -c nextcloud -- ls /var/www/html/config/
apache-pretty-urls.config.php apcu.config.php apps.config.php autoconfig.php
config.php config.sample.php redis.config.php reverse-proxy.config.php
s3.config.php smtp.config.php swift.config.php upgrade-disable-web.config.php
# no helm-metrics.config.php
$ kubectl exec deploy/nextcloud -c nextcloud -- sh -c 'cd /var/www/html && php occ config:system:get openmetrics_allowed_clients'
# unset
$ # from a pod whose IP is inside the CIDR above
$ curl -o /dev/null -w '%{http_code}\n' http://<nextcloud-pod-ip>:80/metrics
403
Adding any entry to nextcloud.configs makes it work, which is the tell.
Expected behaviour
Setting nextcloud.openmetrics.allowedClients configures openmetrics_allowed_clients, without
also having to set an unrelated value.
Possible fix
Drop the {{- if .Values.nextcloud.configs }} guard around the defaultConfigs loop in
_helpers.tpl and around the ConfigMap in config.yaml, as #761 asks. At minimum,
helm-metrics.config.php and imaginary.config.php need to mount whenever they are enabled,
since neither exists in the container image.
Versions
- Chart 9.3.0 (the guard is still on
main) - Nextcloud 34.0.4,
apacheflavor - Kubernetes 1.37.0, kube-prometheus-stack
- 主要言語
- Go Template
- スター
- 536
- フォーク
- 316
- 平均マージ
- 4日 16時間
- マージ済み PR(30日)
- 2
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
nextcloud/helm のほかの issue
-
No native support for REDIS_USER enviroment var対応中かも @jholmes802 が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
-
External Redis not working: redis-session.ini: Permission denied対応中かも @antoinetran が 21 日前に担当しました。 オープン
難易度 3/5 1〜2日 初心者へのやさしさ 55/100
-
難易度 3/5 1〜2日 初心者へのやさしさ 55/100
似ている issue
-
難易度 1/5 1時間未満 初心者へのやさしさ 85/100
FinanceFlash/unvibecode#203 ·
メンテナーはふだん 1 日以内に返信
-
Sanity on ansible-core devel fails: ignore-2.23.txt references the removed import-3.9 test対応中かも @yurnov が今日担当しました。 オープンneeds_triage
難易度 1/5 1時間未満 初心者へのやさしさ 91/100
ansible-collections/kubernetes.core#1275 ·
メンテナーはふだん 1 日以内に返信
-
bug milestone-qa
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
lognorman20/monaco#3995 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
gnosis/gnosis_vpn#540 ·
メンテナーはふだん 1 日以内に返信