Storage Configuration
The chart includes RustFS, a Rust S3-compatible object store, and initializes its private metadata, content and log buckets. The API issues temporary credentials whose session policy restricts the object prefixes available to each execution.
Bundled RustFS
Section titled “Bundled RustFS”storage.provider=s3 and rustfs.enabled=true are the defaults. Setup generates
separate credentials for:
| Identity | Where it is used |
|---|---|
| RustFS root | Storage server and initialization Job only |
| Application API | Trusted API access to the configured buckets |
| STS issuer | Temporary-credential issuance with a narrower session policy |
| Execution session | Only the signed execution’s granted storage operations and prefixes |
The initializer creates three distinct private buckets, IAM users and policies, browser CORS, and temporary-content cleanup. It checks existing policy/user drift instead of silently replacing access rules. API Pods wait for the release’s initialization Job before starting.
RustFS is pinned to 1.0.0-rc.5 by digest. This chart runs one persistent RustFS
Pod, with a default 100 GiB PVC. It does not provide storage host failover.
Multiple API or object-gateway replicas do not change that storage topology.
Use a separately operated and qualified distributed store when that availability
boundary is insufficient.
Public, internal and STS endpoints
Section titled “Public, internal and STS endpoints”storage: provider: s3 s3: publicEndpoint: https://s3.flow-like.example.com existingSecret: flow-like-storage runtimeCredentialsProvider: rustfs stsSessionTtlSeconds: 7200 usePathStyle: true
executionManager: objectStoreTlsGateway: true
rustfs: enabled: true existingSecret: flow-like-rustfs-root gateway: ingress: enabled: true className: nginx host: s3.flow-like.example.com tls: - secretName: flow-like-s3-tls hosts: - s3.flow-like.example.comUse generated Secret references or replace the names with your managed Secrets. With bundled RustFS, the chart derives the internal storage and STS origins.
The public object gateway exposes bucket data and blocks root, STS and administration routes. The public origin must resolve and be reachable from both browsers and Pods. Presigned requests are bound to that host and path; preserve them through ingress and TLS termination. A Kubernetes-only Service DNS name is unsuitable for browser downloads.
An HTTPS tunnel cannot inspect paths. Set
executionManager.objectStoreTlsGateway=true only when the HTTPS endpoint
itself enforces the bucket-only boundary. Prefix permissions remain the object
store’s responsibility.
Bucket layout and credentials
Section titled “Bucket layout and credentials”The isolated manager requires distinct metadata, content and log buckets. Configure
their names with storage.s3.metaBucket, contentBucket and logBucket.
Defaults are flow-like-meta, flow-like-content and flow-like-logs.
The Secret named by storage.s3.existingSecret contains:
AWS_ACCESS_KEY_IDAWS_SECRET_ACCESS_KEYSTS_ISSUER_ACCESS_KEYSTS_ISSUER_SECRET_KEYThe root Secret contains RUSTFS_ROOT_USER and RUSTFS_ROOT_PASSWORD. Setup
creates both Secrets and their matching values. Public endpoints, bucket names
and region belong in Helm values.
The API derives temporary grants for the application’s metadata, content, temporary files and logs. A gateway origin allowlist alone does not enforce those prefixes. The provider must reject access outside the session policy, including cross-prefix copy operations and requests missing their session token.
Credential lifetime
Section titled “Credential lifetime”The default session request is 7,200 seconds. A one-hour execution with the default queue, startup, terminal, cleanup and credential margin needs at least 4,140 seconds remaining when credentials are checked out.
The API verifies the provider’s returned expiration, including cached credentials. For external AWS STS, configure a role session duration that covers the requested budget. A role-chained one-hour session cannot cover a full hour of execution plus these allowances. The current execution path does not renew credentials during a running workflow.
External S3-compatible storage
Section titled “External S3-compatible storage”To replace RustFS, disable its workload and supply the complete endpoint and credential contract:
rustfs: enabled: falsestorage: provider: s3 s3: publicEndpoint: https://objects.example.com internalEndpoint: https://objects.internal.example.com stsEndpoint: https://sts.internal.example.com existingSecret: flow-like-storage runtimeCredentialsProvider: rustfs stsSessionTtlSeconds: 7200 usePathStyle: trueexecutionManager: objectStoreTlsGateway: trueReplace the example endpoints with the provider’s actual configuration.
runtimeCredentialsProvider selects the rustfs or aws STS policy dialect.
Configure storage.s3.runtimeRoleArn when selecting AWS AssumeRole; RustFS does
not require an AWS IAM role.
S3 data API compatibility does not establish support for prefix-scoped STS
sessions; qualify the exact provider, version and policy implementation.
For setup-generated external storage configuration, export
RUSTFS_ENABLED=false, S3_PUBLIC_ENDPOINT, S3_INTERNAL_ENDPOINT,
STS_ENDPOINT_URL, the four credential variables above, and optionally
S3_STS_PROVIDER, before running setup. The helper does not create external
buckets or provider IAM resources.
Private external endpoints may need
networkPolicy.executionGatewayExtraEgress for gateways and
networkPolicy.controlPlaneExtraEgress for the API.
Other provider blocks
Section titled “Other provider blocks”The API build includes AWS, Azure, GCP and R2 credential implementations.
The current isolated chart supports the S3 configuration described above.
The separate storage.aws, storage.azure, storage.gcp and
storage.r2 blocks remain available for explicitly trusted shared execution.
For those provider blocks, use an existing storage Secret matching
helm/templates/runtime-secrets.yaml. R2 additionally needs R2_API_TOKEN;
the generated R2 Secret does not include it. For AWS workload identity, omit
static key entries entirely rather than setting them to empty strings.
GCP service-account JSON is passed as JSON text to
GOOGLE_APPLICATION_CREDENTIALS_JSON, without an extra base64 layer.
See Storage Providers for provider-specific grants, including customer-managed AWS KMS keys.
Verify and recover
Section titled “Verify and recover”kubectl get pods,jobs,pvc -n flow-likekubectl logs -n flow-like -l app.kubernetes.io/component=object-store-inithelm test flow-like -n flow-like --logsRun the Helm test against a disposable or backed-up store. It exercises scoped STS, sibling-prefix and copy-source denial, missing session tokens, administration routes and presigned URLs, then removes its unique temporary prefixes. It does not test expiry, failover or application throughput.
The shared storage verification contract lists the complete probes and additional expiry, long-run and IAM-restore qualification. Repeat it when changing the exact store version, policy, public endpoint or issuer identity. Killing a sandbox does not instantly revoke credentials it has exported; session expiry remains part of storage isolation.
Preserve the PVC and IAM credentials on upgrade. Investigate initializer drift errors before changing users or policies. Restore storage data and credentials consistently with the database and retained execution state.