Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

nextcloud.openmetrics.allowedClients is silently ignored unless nextcloud.configs is set

未关闭
#887 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

@JanWelker 已经在做这个了。

开始于 2026年9月21日。

  • #888 来自 @JanWelker —— 未关闭

评估

难度
3/5
预计耗时
1-2 天
新手友好度
78/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
活跃
技术栈
helm, kubernetes

调研方向

Read charts/nextcloud/templates/_helpers.tpl and templates/config.yaml, focusing on the defaultConfigs guard and ConfigMap rendering. Render the chart with openmetrics.allowedClients set while nextcloud.configs is empty, then verify that helm-metrics.config.php is mounted and the setting is available to Nextcloud without unrelated configuration.

由索引模型根据 Issue 内容生成。

描述

Describe the bug

nextcloud.openmetrics.allowedClients renders OPENMETRICS_ALLOWED_CLIENTS into the app
container, but nothing in the pod ever reads it. The only reader is
files/defaultConfigs/helm-metrics.config.php.tpl, and the defaultConfigs files are only
mounted when nextcloud.configs is non-empty
(_helpers.tpl#L431);
templates/config.yaml renders no ConfigMap at all otherwise.

So with the chart's default nextcloud.configs: {}, setting allowedClients does nothing:
Nextcloud keeps its built-in default of 127.0.0.1 only, and Prometheus is refused with 403.

This is the same gate reported in #761, but it bites differently here. The argument there for
keeping it — "normally you do not need the defaultConfig, because the files are already part of
the container image" — does not hold for helm-metrics.config.php. Like imaginary.config.php,
it is a chart file, not one of nextcloud/docker's.
There is no image copy to fall back on, so nextcloud.openmetrics.allowedClients cannot work on
its own under any configuration.

It also affects the chart's own defaults: prometheus.serviceMonitor selects the app Service as
well as the exporter Service, so an out-of-the-box metrics.enabled: true +
prometheus.serviceMonitor.enabled: true install scrapes /metrics on the app pod, gets a 403,
and sits with a permanently down target firing TargetDown.

Steps to reproduce
nextcloud:
  openmetrics:
    allowedClients:
      - "127.0.0.1"
      - "10.244.0.0/16"   # your pod CIDR
metrics:
  enabled: true
prometheus:
  serviceMonitor:
    enabled: true
$ kubectl exec deploy/nextcloud -c nextcloud -- sh -c 'echo $OPENMETRICS_ALLOWED_CLIENTS'
127.0.0.1,10.244.0.0/16

$ kubectl exec deploy/nextcloud -c nextcloud -- ls /var/www/html/config/
apache-pretty-urls.config.php  apcu.config.php  apps.config.php  autoconfig.php
config.php  config.sample.php  redis.config.php  reverse-proxy.config.php
s3.config.php  smtp.config.php  swift.config.php  upgrade-disable-web.config.php
# no helm-metrics.config.php

$ kubectl exec deploy/nextcloud -c nextcloud -- sh -c 'cd /var/www/html && php occ config:system:get openmetrics_allowed_clients'
# unset

$ # from a pod whose IP is inside the CIDR above
$ curl -o /dev/null -w '%{http_code}\n' http://<nextcloud-pod-ip>:80/metrics
403

Adding any entry to nextcloud.configs makes it work, which is the tell.

Expected behaviour

Setting nextcloud.openmetrics.allowedClients configures openmetrics_allowed_clients, without
also having to set an unrelated value.

Possible fix

Drop the {{- if .Values.nextcloud.configs }} guard around the defaultConfigs loop in
_helpers.tpl and around the ConfigMap in config.yaml, as #761 asks. At minimum,
helm-metrics.config.php and imaginary.config.php need to mount whenever they are enabled,
since neither exists in the container image.

Versions
  • Chart 9.3.0 (the guard is still on main)
  • Nextcloud 34.0.4, apache flavor
  • Kubernetes 1.37.0, kube-prometheus-stack
主要语言
Go Template
星标
536
派生
316
平均合并
4 天 16 小时
30 天内合并 PR
2

环境准备

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

nextcloud/helm 的其他 Issue

查看 nextcloud/helm 的全部 Issue

相似的 Issue

更多 DevOps Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。