From 9a089719561a4bd7cac8336999d1b48972337400 Mon Sep 17 00:00:00 2001 From: Arnob Kumar Saha Date: Sun, 13 Sep 2026 13:02:07 +0600 Subject: [PATCH 1/2] Fix broken template references in minio and s3proxy routes minio's HTTPRoute referenced service-backend helpers that do not exist in that chart, and both charts resolved the backend Service name from the range scope instead of the root, so `helm template` failed outright whenever gateway.enabled was set. The s3proxy BackendTLSPolicy also validated against gateway.hosts[0], which is a {host, paths} map, not a string. Use the same hostname the backend certificate is issued for (ace/templates/ingress/certificate.yaml), following route-nats.yaml. Signed-off-by: Arnob Kumar Saha --- charts/minio/templates/httproute.yaml | 6 +++--- charts/s3proxy/templates/httproute.yaml | 8 ++++++-- 2 files changed, 9 insertions(+), 5 deletions(-) diff --git a/charts/minio/templates/httproute.yaml b/charts/minio/templates/httproute.yaml index 343de09de..f16303f2c 100644 --- a/charts/minio/templates/httproute.yaml +++ b/charts/minio/templates/httproute.yaml @@ -1,5 +1,5 @@ {{- if (index .Values "gateway" "enabled") }} -{{- $fullName := include "service-backend.fullname" . -}} +{{- $fullName := include "minio.fullname" . -}} {{- $svcPort := .Values.service.port -}} apiVersion: gateway.networking.k8s.io/v1 @@ -8,7 +8,7 @@ metadata: name: {{ include "minio.fullname" . }} namespace: {{ .Release.Namespace }} labels: - {{- include "service-backend.labels" . | nindent 4 }} + {{- include "minio.labels" . | nindent 4 }} {{- with .Values.gateway.annotations }} annotations: {{- toYaml . | nindent 4 }} @@ -45,7 +45,7 @@ spec: backendRefs: - group: "" kind: Service - name: {{ include "minio.fullname" . }} + name: {{ $fullName }} namespace: {{ $.Release.Namespace }} port: {{ $svcPort }} weight: 1 diff --git a/charts/s3proxy/templates/httproute.yaml b/charts/s3proxy/templates/httproute.yaml index e389d10be..6c482eeb8 100644 --- a/charts/s3proxy/templates/httproute.yaml +++ b/charts/s3proxy/templates/httproute.yaml @@ -44,7 +44,7 @@ spec: backendRefs: - group: "" kind: Service - name: {{ include "s3proxy.fullname" . }} + name: {{ include "s3proxy.fullname" $ }} namespace: {{ $.Release.Namespace }} port: {{ $.Values.service.port }} weight: 1 @@ -67,7 +67,11 @@ spec: - group: "" kind: Secret name: {{ include "ace.fullname" . }}-gw-cert - hostname: {{ index .Values.gateway.hosts 0 }} + {{- if eq (index .Values "global" "platform" "hostType") "ip" }} + hostname: {{ include "ace.fullname" . }}-s3proxy + {{- else }} + hostname: {{ .Values.global.platform.host }} + {{- end }} {{- end }} --- From bd26b36a89937b33a5df49a369bcc3745c171f54 Mon Sep 17 00:00:00 2001 From: Arnob Kumar Saha Date: Sun, 13 Sep 2026 13:17:57 +0600 Subject: [PATCH 2/2] Select the acme CA for s3proxy BackendTLSPolicy validation s3proxy serves the same secret as nats (lib-selfhost picks ace-gw-cert for both when the gateway is enabled), so it needs the same CA. A letsencrypt-issued secret carries no usable ca.crt, which is why the ISRG root lives in a separate secret; mirror the switch route-nats.yaml already makes. Signed-off-by: Arnob Kumar Saha --- charts/s3proxy/templates/httproute.yaml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/charts/s3proxy/templates/httproute.yaml b/charts/s3proxy/templates/httproute.yaml index 6c482eeb8..cb1849a8f 100644 --- a/charts/s3proxy/templates/httproute.yaml +++ b/charts/s3proxy/templates/httproute.yaml @@ -64,9 +64,17 @@ spec: name: {{ include "ace.fullname" . }}-s3proxy validation: caCertificateRefs: + {{- if and + (or (eq .Values.global.infra.tls.issuer "letsencrypt") (eq .Values.global.infra.tls.issuer "letsencrypt-staging")) + (index .Values "gateway" "enabled") }} + - group: "" + kind: Secret + name: {{ include "ace.fullname" . }}-acme-ca-cert + {{- else }} - group: "" kind: Secret name: {{ include "ace.fullname" . }}-gw-cert + {{- end }} {{- if eq (index .Values "global" "platform" "hostType") "ip" }} hostname: {{ include "ace.fullname" . }}-s3proxy {{- else }}