plane-enterprise: live-exporter loses LIVE_SERVER_SECRET_KEY when external_secrets.app_keys_existingSecret is set
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 1/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 94/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- helm
- Domain
- devops, infrastructure
Research direction
Start with live-exporter.deployment.yaml and compare its envFrom entries with live.deployment.yaml, especially the plane.appKeysSecretRef include. Render the chart with external_secrets.app_keys_existingSecret set and verify that live-exporter receives LIVE_SERVER_SECRET_KEY from the app-keys Secret. Done means the key is retained with the hook enabled and existing containers remain unchanged.
Written by the indexing model from the issue text.
Description
Summary
With external_secrets.app_keys_existingSecret set, the chart stops emitting the shared
signing keys in its own Secrets (as documented), including LIVE_SERVER_SECRET_KEY in
<release>-live-secrets. Consumers are expected to pick the key up from the app-keys
Secret via plane.appKeysSecretRef.
live.deployment.yaml includes plane.appKeysSecretRef (last in envFrom), but
live-exporter.deployment.yaml does not. live-exporter mounts <release>-live-secrets,
so as soon as the app-keys hook is enabled it silently loses LIVE_SERVER_SECRET_KEY.
The comment next to the include in live.deployment.yaml describes the consequence:
the app and live copies of LIVE_SERVER_SECRET_KEY must agree "or live-server auth
fails with nothing logged". For live-exporter the key is not merely different but absent.
Affected versions
- plane-enterprise 3.8.0 (appVersion 3.2.2) — reproduced
masterat chart 3.10.0 (appVersion 3.3.0) — the template is unchanged, still no include
Reproduction
- Render with the app-keys hook enabled, e.g.
helm template plane-app plane/plane-enterprise --version 3.8.0 -f values.yaml
withexternal_secrets.app_keys_existingSecret: plane-ext-app-keysand the six keys
(SECRET_KEY,AES_SECRET_KEY,LIVE_SERVER_SECRET_KEY,PI_INTERNAL_SECRET,
SILO_HMAC_SECRET_KEY,CURSOR_WEBHOOK_SECRET) supplied in that Secret. - Resolve the effective environment of the
live-exportercontainer (envFrom in order,
then env) and compare it with a render without the hook. - Result:
LIVE_SERVER_SECRET_KEYis missing from live-exporter. Every other container
keeps it.
Fix
Add the include as the last envFrom entry, mirroring live.deployment.yaml:
{{- with (include "plane.otel.envFrom" $) }}{{ . | nindent 10 }}{{- end }}
+ {{- /* LAST in envFrom, as in live.deployment.yaml: live-exporter reads the
+ live-secrets copy of LIVE_SERVER_SECRET_KEY, which the chart stops
+ emitting once app_keys_existingSecret is set. */}}
+ {{- include "plane.appKeysSecretRef" . }}
env:
Verified by rendering the patched chart: live-exporter keeps LIVE_SERVER_SECRET_KEY
with the identical value; no container loses any variable.
Workaround until released
extraEnv:
- name: LIVE_SERVER_SECRET_KEY
valueFrom:
secretKeyRef:
name: <app-keys-secret>
key: LIVE_SERVER_SECRET_KEY
Verified the same way against the unpatched 3.8.0 chart.
- Dominant language
- Go Template
- Stars
- 22
- Forks
- 31
- Avg merge
- 23h 42m
- Merged PRs (30d)
- 12
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from makeplane/helm-charts
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
makeplane/helm-charts#275 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
makeplane/helm-charts#220 ·
Maintainers usually reply within 1 day
-
Difficulty 3/5 1-2 days Newbie friendliness 68/100
makeplane/helm-charts#318 ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
makeplane/helm-charts#274 ·
Maintainers usually reply within 1 day
-
plane-enterprise: AMQP broker stability gaps cause silent task dispatch failures in KubernetesMay be free again @akshat5302 claimed this 92 days ago, and no pull request is open. Open
makeplane/helm-charts#261 · 1 comment · 1 assignee ·
Maintainers usually reply within 1 day
All issues in makeplane/helm-charts
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
rossoctl/context-guru#366 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
aws-samples/sample-pacer#76 ·
Maintainers usually reply within 1 day
-
UX
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
ProfessionalWiki/NeoWiki#1570 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100