Repository navigation
chore(rustfs): bump rustfs chart to 1.0.1 - #1369
Merged
Merged
Conversation
aivong-openhands
marked this pull request as ready for review
October 8, 2026 20:44
aivong-openhands
requested review from
dylan-openhands,
jlav and
mamoodi
as code owners
October 8, 2026 20:44
dylan-openhands
approved these changes
Oct 8, 2026
dylan-openhands
left a comment
Contributor
There was a problem hiding this comment.
I think a court of law might take issue with the usage of "bump" here 😉
I'm approving but doublecheck me on the safety of the assumption that rustfs is optional, not widely used and therefore unlikely to break things
Contributor
Author
Yes rustfs is optional and not on any customer facing install as we were trying to replace minio with it but never completed that migration 😅 |
Contributor
|
🚀 Released in openhands/0.80.0. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The optional
rustfssubchart is pinned to rustfs chart 0.10.0, whose default imagerustfs/rustfs:1.0.0-beta.10has 2 high findings with fixes available in Trivy (CVE-2026-14456 in Alpinelibssl3/libcrypto33.5.7). This moves the dependency to rustfs chart 1.0.1, which shipsrustfs/rustfs:1.0.1, the current stable release, at 0 critical / 0 high. RustFS isenabled: falseby default and kept for a planned storage migration, so default installs render nothing different.Every key under
rustfs:invalues.yamlstill exists in chart 1.0.1. The chart's 1.0.1 changes beyond 1.0.0 are in ingress and Gateway API hostnames, whichrustfs.ingress.enabled: falsekeeps off.Validation
rustfs/rustfs:1.0.0-beta.10reports 0 critical / 2 high (both fixable);rustfs/rustfs:1.0.1reports 0 critical / 0 high.helm lintpasses withrustfs.enabled=true. Compared with chart 0.10.0, the rendered RustFS resources are the same eight objects with the same names (includingService/oh-rustfs-svc), and the only manifest change is the image tag.rustfs/rustfs:1.0.1, run with the rendered config, credentials and security context (uid 10001, read-only root filesystem, all capabilities dropped), served bucket create, put, get, list and delete through the AWS CLI with no server errors, same as1.0.0-beta.10.Helm Chart Checklist
rustfs.*keys set invalues.yamlexist in chart 1.0.1.This PR was drafted by an AI agent on behalf of the user.