Skip to content

chore(rustfs): bump rustfs chart to 1.0.1 - #1369

Merged
aivong-openhands merged 1 commit into
mainfrom
chore/rustfs-chart-1.0.1
Oct 9, 2026
Merged

aivong-openhands merged 1 commit into
mainfrom
chore/rustfs-chart-1.0.1

Conversation

@aivong-openhands

Copy link
Copy Markdown
Contributor

Why

The optional rustfs subchart is pinned to rustfs chart 0.10.0, whose default image rustfs/rustfs:1.0.0-beta.10 has 2 high findings with fixes available in Trivy (CVE-2026-14456 in Alpine libssl3/libcrypto3 3.5.7). This moves the dependency to rustfs chart 1.0.1, which ships rustfs/rustfs:1.0.1, the current stable release, at 0 critical / 0 high. RustFS is enabled: false by default and kept for a planned storage migration, so default installs render nothing different.

Every key under rustfs: in values.yaml still exists in chart 1.0.1. The chart's 1.0.1 changes beyond 1.0.0 are in ingress and Gateway API hostnames, which rustfs.ingress.enabled: false keeps off.

Validation

  • Trivy — rustfs/rustfs:1.0.0-beta.10 reports 0 critical / 2 high (both fixable); rustfs/rustfs:1.0.1 reports 0 critical / 0 high.
  • Render — helm lint passes with rustfs.enabled=true. Compared with chart 0.10.0, the rendered RustFS resources are the same eight objects with the same names (including Service/oh-rustfs-svc), and the only manifest change is the image tag.
  • S3 smoke test — rustfs/rustfs:1.0.1, run with the rendered config, credentials and security context (uid 10001, read-only root filesystem, all capabilities dropped), served bucket create, put, get, list and delete through the AWS CLI with no server errors, same as 1.0.0-beta.10.

Helm Chart Checklist

  • I have tested the chart upgrade path from the previous version — the subchart is disabled by default; with it enabled, only the image tag changes in the rendered manifests.
  • I have verified backwards compatibility with existing values.yaml configurations — all rustfs.* keys set in values.yaml exist in chart 1.0.1.
  • I have updated the chart's README.md if there are any breaking changes or new required values — no new required values.

This PR was drafted by an AI agent on behalf of the user.

@github-actions github-actions Bot added the type: chore Maintenance / chores label Oct 8, 2026
@aivong-openhands
aivong-openhands marked this pull request as ready for review October 8, 2026 20:44

@dylan-openhands dylan-openhands left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think a court of law might take issue with the usage of "bump" here 😉

I'm approving but doublecheck me on the safety of the assumption that rustfs is optional, not widely used and therefore unlikely to break things

@aivong-openhands

Copy link
Copy Markdown
Contributor Author

I think a court of law might take issue with the usage of "bump" here 😉

I'm approving but doublecheck me on the safety of the assumption that rustfs is optional, not widely used and therefore unlikely to break things

Yes rustfs is optional and not on any customer facing install as we were trying to replace minio with it but never completed that migration 😅

@aivong-openhands
aivong-openhands merged commit 5dfe60d into main Oct 9, 2026
24 checks passed
@aivong-openhands
aivong-openhands deleted the chore/rustfs-chart-1.0.1 branch October 9, 2026 11:08
@openhands-release-bot openhands-release-bot Bot added the released: openhands/0.80.0 Shipped in openhands/0.80.0 label Oct 9, 2026
@openhands-release-bot

Copy link
Copy Markdown
Contributor

🚀 Released in openhands/0.80.0.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

released: openhands/0.80.0 Shipped in openhands/0.80.0 type: chore Maintenance / chores

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants