nextcloud.openmetrics.allowedClients is silently ignored unless nextcloud.configs is set
评估
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 新手友好度
- 78/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- helm, kubernetes
- 领域
- devops, infrastructure
调研方向
Read charts/nextcloud/templates/_helpers.tpl and templates/config.yaml, focusing on the defaultConfigs guard and ConfigMap rendering. Render the chart with openmetrics.allowedClients set while nextcloud.configs is empty, then verify that helm-metrics.config.php is mounted and the setting is available to Nextcloud without unrelated configuration.
由索引模型根据 Issue 内容生成。
描述
Describe the bug
nextcloud.openmetrics.allowedClients renders OPENMETRICS_ALLOWED_CLIENTS into the app
container, but nothing in the pod ever reads it. The only reader is
files/defaultConfigs/helm-metrics.config.php.tpl, and the defaultConfigs files are only
mounted when nextcloud.configs is non-empty
(_helpers.tpl#L431);
templates/config.yaml renders no ConfigMap at all otherwise.
So with the chart's default nextcloud.configs: {}, setting allowedClients does nothing:
Nextcloud keeps its built-in default of 127.0.0.1 only, and Prometheus is refused with 403.
This is the same gate reported in #761, but it bites differently here. The argument there for
keeping it — "normally you do not need the defaultConfig, because the files are already part of
the container image" — does not hold for helm-metrics.config.php. Like imaginary.config.php,
it is a chart file, not one of nextcloud/docker's.
There is no image copy to fall back on, so nextcloud.openmetrics.allowedClients cannot work on
its own under any configuration.
It also affects the chart's own defaults: prometheus.serviceMonitor selects the app Service as
well as the exporter Service, so an out-of-the-box metrics.enabled: true +
prometheus.serviceMonitor.enabled: true install scrapes /metrics on the app pod, gets a 403,
and sits with a permanently down target firing TargetDown.
Steps to reproduce
nextcloud:
openmetrics:
allowedClients:
- "127.0.0.1"
- "10.244.0.0/16" # your pod CIDR
metrics:
enabled: true
prometheus:
serviceMonitor:
enabled: true
$ kubectl exec deploy/nextcloud -c nextcloud -- sh -c 'echo $OPENMETRICS_ALLOWED_CLIENTS'
127.0.0.1,10.244.0.0/16
$ kubectl exec deploy/nextcloud -c nextcloud -- ls /var/www/html/config/
apache-pretty-urls.config.php apcu.config.php apps.config.php autoconfig.php
config.php config.sample.php redis.config.php reverse-proxy.config.php
s3.config.php smtp.config.php swift.config.php upgrade-disable-web.config.php
# no helm-metrics.config.php
$ kubectl exec deploy/nextcloud -c nextcloud -- sh -c 'cd /var/www/html && php occ config:system:get openmetrics_allowed_clients'
# unset
$ # from a pod whose IP is inside the CIDR above
$ curl -o /dev/null -w '%{http_code}\n' http://<nextcloud-pod-ip>:80/metrics
403
Adding any entry to nextcloud.configs makes it work, which is the tell.
Expected behaviour
Setting nextcloud.openmetrics.allowedClients configures openmetrics_allowed_clients, without
also having to set an unrelated value.
Possible fix
Drop the {{- if .Values.nextcloud.configs }} guard around the defaultConfigs loop in
_helpers.tpl and around the ConfigMap in config.yaml, as #761 asks. At minimum,
helm-metrics.config.php and imaginary.config.php need to mount whenever they are enabled,
since neither exists in the container image.
Versions
- Chart 9.3.0 (the guard is still on
main) - Nextcloud 34.0.4,
apacheflavor - Kubernetes 1.37.0, kube-prometheus-stack
- 主要语言
- Go Template
- 星标
- 536
- 派生
- 316
- 平均合并
- 4 天 16 小时
- 30 天内合并 PR
- 2
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
nextcloud/helm 的其他 Issue
-
No native support for REDIS_USER enviroment var可能已有人在做 @jholmes802 于 1 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 70/100
-
难度 2/5 1-3 小时 新手友好度 72/100
-
难度 2/5 1-3 小时 新手友好度 68/100
-
External Redis not working: redis-session.ini: Permission denied可能已有人在做 @antoinetran 于 22 天前认领。 未关闭
难度 3/5 1-2 天 新手友好度 55/100
-
难度 3/5 1-2 天 新手友好度 55/100
相似的 Issue
-
Deploy & Patch-issues opprettes ikke: create-pnd-issues.yml har feilet hver uke siden 2025-09-08未关闭
难度 2/5 1-3 小时 新手友好度 62/100
Altinn/altinn-auth#4359 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 82/100
aws-samples/appmod-blueprints#972 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 70/100
WordPress/presence-api#807 ·
维护者通常 1 天内回复
-
lens:agent lens:process process
难度 2/5 1-3 小时 新手友好度 78/100
thebristolsound/birdbrain#1771 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复