nextcloud.openmetrics.allowedClients is silently ignored unless nextcloud.configs is set
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 78/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- helm, kubernetes
- Lĩnh vực
- devops, infrastructure
Hướng nghiên cứu
Read charts/nextcloud/templates/_helpers.tpl and templates/config.yaml, focusing on the defaultConfigs guard and ConfigMap rendering. Render the chart with openmetrics.allowedClients set while nextcloud.configs is empty, then verify that helm-metrics.config.php is mounted and the setting is available to Nextcloud without unrelated configuration.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Describe the bug
nextcloud.openmetrics.allowedClients renders OPENMETRICS_ALLOWED_CLIENTS into the app
container, but nothing in the pod ever reads it. The only reader is
files/defaultConfigs/helm-metrics.config.php.tpl, and the defaultConfigs files are only
mounted when nextcloud.configs is non-empty
(_helpers.tpl#L431);
templates/config.yaml renders no ConfigMap at all otherwise.
So with the chart's default nextcloud.configs: {}, setting allowedClients does nothing:
Nextcloud keeps its built-in default of 127.0.0.1 only, and Prometheus is refused with 403.
This is the same gate reported in #761, but it bites differently here. The argument there for
keeping it — "normally you do not need the defaultConfig, because the files are already part of
the container image" — does not hold for helm-metrics.config.php. Like imaginary.config.php,
it is a chart file, not one of nextcloud/docker's.
There is no image copy to fall back on, so nextcloud.openmetrics.allowedClients cannot work on
its own under any configuration.
It also affects the chart's own defaults: prometheus.serviceMonitor selects the app Service as
well as the exporter Service, so an out-of-the-box metrics.enabled: true +
prometheus.serviceMonitor.enabled: true install scrapes /metrics on the app pod, gets a 403,
and sits with a permanently down target firing TargetDown.
Steps to reproduce
nextcloud:
openmetrics:
allowedClients:
- "127.0.0.1"
- "10.244.0.0/16" # your pod CIDR
metrics:
enabled: true
prometheus:
serviceMonitor:
enabled: true
$ kubectl exec deploy/nextcloud -c nextcloud -- sh -c 'echo $OPENMETRICS_ALLOWED_CLIENTS'
127.0.0.1,10.244.0.0/16
$ kubectl exec deploy/nextcloud -c nextcloud -- ls /var/www/html/config/
apache-pretty-urls.config.php apcu.config.php apps.config.php autoconfig.php
config.php config.sample.php redis.config.php reverse-proxy.config.php
s3.config.php smtp.config.php swift.config.php upgrade-disable-web.config.php
# no helm-metrics.config.php
$ kubectl exec deploy/nextcloud -c nextcloud -- sh -c 'cd /var/www/html && php occ config:system:get openmetrics_allowed_clients'
# unset
$ # from a pod whose IP is inside the CIDR above
$ curl -o /dev/null -w '%{http_code}\n' http://<nextcloud-pod-ip>:80/metrics
403
Adding any entry to nextcloud.configs makes it work, which is the tell.
Expected behaviour
Setting nextcloud.openmetrics.allowedClients configures openmetrics_allowed_clients, without
also having to set an unrelated value.
Possible fix
Drop the {{- if .Values.nextcloud.configs }} guard around the defaultConfigs loop in
_helpers.tpl and around the ConfigMap in config.yaml, as #761 asks. At minimum,
helm-metrics.config.php and imaginary.config.php need to mount whenever they are enabled,
since neither exists in the container image.
Versions
- Chart 9.3.0 (the guard is still on
main) - Nextcloud 34.0.4,
apacheflavor - Kubernetes 1.37.0, kube-prometheus-stack
- Ngôn ngữ chính
- Go Template
- Star
- 536
- Fork
- 316
- Merge trung bình
- 4 ngày 16 giờ
- Pull request đã merge (30 ngày)
- 2
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của nextcloud/helm
-
No native support for REDIS_USER enviroment varCó thể đã có người làm @jholmes802 đã nhận 1 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
-
Failed to inspect imageĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
-
External Redis not working: redis-session.ini: Permission deniedCó thể đã có người làm @antoinetran đã nhận 22 ngày trước. Đang mở
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 55/100
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 55/100
Tất cả issue của nextcloud/helm
Issue tương tự
-
[Bug] create-before-destroy replacements are omitted from driftCó thể đã có người làm @Lostmanu đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
InditexTech/kumoss#318 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Deploy & Patch-issues opprettes ikke: create-pnd-issues.yml har feilet hver uke siden 2025-09-08Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
Altinn/altinn-auth#4359 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
WingedGuardian/GENesis-AGI#3126 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
aws-samples/appmod-blueprints#972 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
The CSS is not lintedĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
WordPress/presence-api#807 ·
Maintainer thường phản hồi trong vòng 1 ngày