mirror of
https://github.com/pgsty/minio.git
synced 2026-08-09 15:53:28 +03:00
e071bb77e4
helm/minio becomes helm/silo: chart name silo, version 6.0.0 -> 7.0.0, the MinIO wordmark icon replaced with the project's own, image.repository and mcImage.repository pointing at pgsty/silo, and the container command changed to silo. User-visible titles, comments and documentation links are rebranded. The MINIO_* environment variables and every existing values key are kept - the first Silo chart is a rename, not a values-schema migration. The hard problem is that a chart rename normally rewrites Kubernetes resource identity, and a StatefulSet's selector and volumeClaimTemplate are immutable. An existing release upgraded carelessly would either fail or orphan its PVCs. Two things address that: - Templates no longer derive the container name from .Chart.Name. It comes from a helper, so nameOverride can pin it, which means an existing release can be upgraded with nameOverride=minio, fullnameOverride=<existing-fullname> and serviceAccount.name=minio-sa and render byte-stable identity while switching chart and image. - helm-migration-guard and verify-helm-migration.sh make that a gate rather than a documented hope. The script lints the chart, renders it in distributed and standalone modes plus the optional templates, then renders the legacy chart from a pinned commit and the new chart with those three overrides and compares resource identity. The guard additionally rejects any rendered container still pulling pgsty/minio or invoking /usr/bin/minio. It runs through a pinned alpine/helm image when helm is not installed locally, so the gate does not depend on the developer's machine. Currently green over 7 compared resources. Rollback is asymmetric and the README says so: the old chart with the new image survives via the entrypoint argv shim, but the new chart with an old MinIO image does not, because `silo server` is not a command that binary knows. Only `helm rollback` is supported, never an image-only downgrade. Not addressed here: the default image tag is pgsty/silo:RELEASE.2026-08-04T00-00-00Z, which does not exist yet. The chart must not be published until the first Silo image is pushed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
107 lines
3.4 KiB
Plaintext
107 lines
3.4 KiB
Plaintext
#!/bin/sh
|
|
set -e ; # Have script exit in the event of a failed command.
|
|
|
|
{{- if .Values.configPathmc }}
|
|
MC_CONFIG_DIR="{{ .Values.configPathmc }}"
|
|
MC="/usr/bin/mc --insecure --config-dir ${MC_CONFIG_DIR}"
|
|
{{- else }}
|
|
MC="/usr/bin/mc --insecure"
|
|
{{- end }}
|
|
|
|
# AccessKey and secretkey credentials file are added to prevent shell execution errors caused by special characters.
|
|
# Special characters for example : ',",<,>,{,}
|
|
MINIO_ACCESSKEY_SECRETKEY_TMP="/tmp/accessKey_and_secretKey_svcacct_tmp"
|
|
|
|
# connectToSilo
|
|
# Use a check-sleep-check loop to wait for Silo service to be available
|
|
connectToSilo() {
|
|
SCHEME=$1
|
|
ATTEMPTS=0 ; LIMIT=29 ; # Allow 30 attempts
|
|
set -e ; # fail if we can't read the keys.
|
|
ACCESS=$(cat /config/rootUser) ; SECRET=$(cat /config/rootPassword) ;
|
|
set +e ; # The connections to Silo are allowed to fail.
|
|
echo "Connecting to Silo server: $SCHEME://$MINIO_ENDPOINT:$MINIO_PORT" ;
|
|
MC_COMMAND="${MC} alias set mysilo $SCHEME://$MINIO_ENDPOINT:$MINIO_PORT $ACCESS $SECRET" ;
|
|
$MC_COMMAND ;
|
|
STATUS=$? ;
|
|
until [ $STATUS = 0 ]
|
|
do
|
|
ATTEMPTS=`expr $ATTEMPTS + 1` ;
|
|
echo \"Failed attempts: $ATTEMPTS\" ;
|
|
if [ $ATTEMPTS -gt $LIMIT ]; then
|
|
exit 1 ;
|
|
fi ;
|
|
sleep 2 ; # 2 second intervals between attempts
|
|
$MC_COMMAND ;
|
|
STATUS=$? ;
|
|
done ;
|
|
set -e ; # reset `e` as active
|
|
return 0
|
|
}
|
|
|
|
# checkSvcacctExists ()
|
|
# Check if the svcacct exists, by using the exit code of `mc admin user svcacct info`
|
|
checkSvcacctExists() {
|
|
CMD=$(${MC} admin user svcacct info mysilo $(head -1 $MINIO_ACCESSKEY_SECRETKEY_TMP) > /dev/null 2>&1)
|
|
return $?
|
|
}
|
|
|
|
# createSvcacct ($user)
|
|
createSvcacct () {
|
|
USER=$1
|
|
FILENAME=$2
|
|
#check accessKey_and_secretKey_tmp file
|
|
if [[ ! -f $MINIO_ACCESSKEY_SECRETKEY_TMP ]];then
|
|
echo "credentials file does not exist"
|
|
return 1
|
|
fi
|
|
if [[ $(cat $MINIO_ACCESSKEY_SECRETKEY_TMP|wc -l) -ne 2 ]];then
|
|
echo "credentials file is invalid"
|
|
rm -f $MINIO_ACCESSKEY_SECRETKEY_TMP
|
|
return 1
|
|
fi
|
|
SVCACCT=$(head -1 $MINIO_ACCESSKEY_SECRETKEY_TMP)
|
|
# Create the svcacct if it does not exist
|
|
if ! checkSvcacctExists ; then
|
|
echo "Creating svcacct '$SVCACCT'"
|
|
# Check if policy file is define
|
|
if [ -z $FILENAME ]; then
|
|
${MC} admin user svcacct add --access-key $(head -1 $MINIO_ACCESSKEY_SECRETKEY_TMP) --secret-key $(tail -n1 $MINIO_ACCESSKEY_SECRETKEY_TMP) mysilo $USER
|
|
else
|
|
${MC} admin user svcacct add --access-key $(head -1 $MINIO_ACCESSKEY_SECRETKEY_TMP) --secret-key $(tail -n1 $MINIO_ACCESSKEY_SECRETKEY_TMP) --policy /config/$FILENAME.json mysilo $USER
|
|
fi
|
|
else
|
|
echo "Svcacct '$SVCACCT' already exists."
|
|
fi
|
|
#clean up credentials files.
|
|
rm -f $MINIO_ACCESSKEY_SECRETKEY_TMP
|
|
}
|
|
|
|
# Try connecting to Silo instance
|
|
{{- if .Values.tls.enabled }}
|
|
scheme=https
|
|
{{- else }}
|
|
scheme=http
|
|
{{- end }}
|
|
connectToSilo $scheme
|
|
|
|
{{ if .Values.svcaccts }}
|
|
{{ $global := . }}
|
|
# Create the svcaccts
|
|
{{- range $idx, $svc := .Values.svcaccts }}
|
|
echo {{ tpl .accessKey $global }} > $MINIO_ACCESSKEY_SECRETKEY_TMP
|
|
{{- if .existingSecret }}
|
|
cat /config/secrets-svc/{{ tpl .existingSecret $global }}/{{ tpl .existingSecretKey $global }} >> $MINIO_ACCESSKEY_SECRETKEY_TMP
|
|
# Add a new line if it doesn't exist
|
|
echo >> $MINIO_ACCESSKEY_SECRETKEY_TMP
|
|
{{ else }}
|
|
echo {{ .secretKey }} >> $MINIO_ACCESSKEY_SECRETKEY_TMP
|
|
{{- end }}
|
|
{{- if $svc.policy}}
|
|
createSvcacct {{ .user }} svc_policy_{{ $idx }}
|
|
{{ else }}
|
|
createSvcacct {{ .user }}
|
|
{{- end }}
|
|
{{- end }}
|
|
{{- end }}
|