diff --git a/.github/workflows/helm_ci.yml b/.github/workflows/helm_ci.yml index f2740f4b1..b26451f5a 100644 --- a/.github/workflows/helm_ci.yml +++ b/.github/workflows/helm_ci.yml @@ -116,6 +116,21 @@ jobs: grep -q "security-config" /tmp/security.yaml echo "Security configuration renders correctly" + echo "=== Testing secure bucket-creation hook certificate mounts ===" + helm template test $CHART_DIR \ + --show-only templates/shared/post-install-bucket-hook.yaml \ + --set s3.enabled=true \ + --set 's3.createBuckets[0].name=data' \ + --set global.seaweedfs.enableSecurity=true \ + > /tmp/security-bucket-hook.yaml + test "$(grep -cE '^[[:space:]]*- name: ca-cert$' /tmp/security-bucket-hook.yaml)" -eq 2 + test "$(grep -cE '^[[:space:]]*- name: client-cert$' /tmp/security-bucket-hook.yaml)" -eq 2 + grep -q 'mountPath: /usr/local/share/ca-certificates/ca/' /tmp/security-bucket-hook.yaml + grep -q 'mountPath: /usr/local/share/ca-certificates/client/' /tmp/security-bucket-hook.yaml + grep -q 'secretName: test-seaweedfs-ca-cert' /tmp/security-bucket-hook.yaml + grep -q 'secretName: test-seaweedfs-client-cert' /tmp/security-bucket-hook.yaml + echo "Secure bucket-creation hook mounts its CA and client certificate" + echo "" echo "=== Testing admin.allowInsecureBind satisfies the admin auth render guard ===" helm template test $CHART_DIR --set admin.enabled=true --set admin.allowInsecureBind=true \ diff --git a/k8s/charts/seaweedfs/templates/shared/post-install-bucket-hook.yaml b/k8s/charts/seaweedfs/templates/shared/post-install-bucket-hook.yaml index 756590a69..f3722758b 100644 --- a/k8s/charts/seaweedfs/templates/shared/post-install-bucket-hook.yaml +++ b/k8s/charts/seaweedfs/templates/shared/post-install-bucket-hook.yaml @@ -222,6 +222,14 @@ spec: mountPath: /etc/seaweedfs/security.toml subPath: security.toml {{- end }} + {{- if .Values.global.seaweedfs.enableSecurity }} + - name: ca-cert + readOnly: true + mountPath: /usr/local/share/ca-certificates/ca/ + - name: client-cert + readOnly: true + mountPath: /usr/local/share/ca-certificates/client/ + {{- end }} {{- end }} ports: - containerPort: {{ .Values.master.port }} @@ -257,5 +265,13 @@ spec: configMap: name: {{ include "seaweedfs.fullname" . }}-security-config {{- end }} + {{- if .Values.global.seaweedfs.enableSecurity }} + - name: ca-cert + secret: + secretName: {{ include "seaweedfs.fullname" . }}-ca-cert + - name: client-cert + secret: + secretName: {{ include "seaweedfs.fullname" . }}-client-cert + {{- end }} {{- end }} {{- end }}