Skip to content

Storage Configuration

The chart includes RustFS, a Rust S3-compatible object store, and initializes its private metadata, content and log buckets. The API issues temporary credentials whose session policy restricts the object prefixes available to each execution.

storage.provider=s3 and rustfs.enabled=true are the defaults. Setup generates separate credentials for:

IdentityWhere it is used
RustFS rootStorage server and initialization Job only
Application APITrusted API access to the configured buckets
STS issuerTemporary-credential issuance with a narrower session policy
Execution sessionOnly the signed execution’s granted storage operations and prefixes

The initializer creates three distinct private buckets, IAM users and policies, browser CORS, and temporary-content cleanup. It checks existing policy/user drift instead of silently replacing access rules. API Pods wait for the release’s initialization Job before starting.

RustFS is pinned to 1.0.0-rc.5 by digest. This chart runs one persistent RustFS Pod, with a default 100 GiB PVC. It does not provide storage host failover. Multiple API or object-gateway replicas do not change that storage topology. Use a separately operated and qualified distributed store when that availability boundary is insufficient.

storage:
provider: s3
s3:
publicEndpoint: https://s3.flow-like.example.com
existingSecret: flow-like-storage
runtimeCredentialsProvider: rustfs
stsSessionTtlSeconds: 7200
usePathStyle: true
executionManager:
objectStoreTlsGateway: true
rustfs:
enabled: true
existingSecret: flow-like-rustfs-root
gateway:
ingress:
enabled: true
className: nginx
host: s3.flow-like.example.com
tls:
- secretName: flow-like-s3-tls
hosts:
- s3.flow-like.example.com

Use generated Secret references or replace the names with your managed Secrets. With bundled RustFS, the chart derives the internal storage and STS origins.

The public object gateway exposes bucket data and blocks root, STS and administration routes. The public origin must resolve and be reachable from both browsers and Pods. Presigned requests are bound to that host and path; preserve them through ingress and TLS termination. A Kubernetes-only Service DNS name is unsuitable for browser downloads.

An HTTPS tunnel cannot inspect paths. Set executionManager.objectStoreTlsGateway=true only when the HTTPS endpoint itself enforces the bucket-only boundary. Prefix permissions remain the object store’s responsibility.

The isolated manager requires distinct metadata, content and log buckets. Configure their names with storage.s3.metaBucket, contentBucket and logBucket. Defaults are flow-like-meta, flow-like-content and flow-like-logs.

The Secret named by storage.s3.existingSecret contains:

AWS_ACCESS_KEY_ID
AWS_SECRET_ACCESS_KEY
STS_ISSUER_ACCESS_KEY
STS_ISSUER_SECRET_KEY

The root Secret contains RUSTFS_ROOT_USER and RUSTFS_ROOT_PASSWORD. Setup creates both Secrets and their matching values. Public endpoints, bucket names and region belong in Helm values.

The API derives temporary grants for the application’s metadata, content, temporary files and logs. A gateway origin allowlist alone does not enforce those prefixes. The provider must reject access outside the session policy, including cross-prefix copy operations and requests missing their session token.

The default session request is 7,200 seconds. A one-hour execution with the default queue, startup, terminal, cleanup and credential margin needs at least 4,140 seconds remaining when credentials are checked out.

The API verifies the provider’s returned expiration, including cached credentials. For external AWS STS, configure a role session duration that covers the requested budget. A role-chained one-hour session cannot cover a full hour of execution plus these allowances. The current execution path does not renew credentials during a running workflow.

To replace RustFS, disable its workload and supply the complete endpoint and credential contract:

rustfs:
enabled: false
storage:
provider: s3
s3:
publicEndpoint: https://objects.example.com
internalEndpoint: https://objects.internal.example.com
stsEndpoint: https://sts.internal.example.com
existingSecret: flow-like-storage
runtimeCredentialsProvider: rustfs
stsSessionTtlSeconds: 7200
usePathStyle: true
executionManager:
objectStoreTlsGateway: true

Replace the example endpoints with the provider’s actual configuration. runtimeCredentialsProvider selects the rustfs or aws STS policy dialect. Configure storage.s3.runtimeRoleArn when selecting AWS AssumeRole; RustFS does not require an AWS IAM role. S3 data API compatibility does not establish support for prefix-scoped STS sessions; qualify the exact provider, version and policy implementation.

For setup-generated external storage configuration, export RUSTFS_ENABLED=false, S3_PUBLIC_ENDPOINT, S3_INTERNAL_ENDPOINT, STS_ENDPOINT_URL, the four credential variables above, and optionally S3_STS_PROVIDER, before running setup. The helper does not create external buckets or provider IAM resources.

Private external endpoints may need networkPolicy.executionGatewayExtraEgress for gateways and networkPolicy.controlPlaneExtraEgress for the API.

The API build includes AWS, Azure, GCP and R2 credential implementations. The current isolated chart supports the S3 configuration described above. The separate storage.aws, storage.azure, storage.gcp and storage.r2 blocks remain available for explicitly trusted shared execution.

For those provider blocks, use an existing storage Secret matching helm/templates/runtime-secrets.yaml. R2 additionally needs R2_API_TOKEN; the generated R2 Secret does not include it. For AWS workload identity, omit static key entries entirely rather than setting them to empty strings. GCP service-account JSON is passed as JSON text to GOOGLE_APPLICATION_CREDENTIALS_JSON, without an extra base64 layer.

See Storage Providers for provider-specific grants, including customer-managed AWS KMS keys.

Terminal window
kubectl get pods,jobs,pvc -n flow-like
kubectl logs -n flow-like -l app.kubernetes.io/component=object-store-init
helm test flow-like -n flow-like --logs

Run the Helm test against a disposable or backed-up store. It exercises scoped STS, sibling-prefix and copy-source denial, missing session tokens, administration routes and presigned URLs, then removes its unique temporary prefixes. It does not test expiry, failover or application throughput.

The shared storage verification contract lists the complete probes and additional expiry, long-run and IAM-restore qualification. Repeat it when changing the exact store version, policy, public endpoint or issuer identity. Killing a sandbox does not instantly revoke credentials it has exported; session expiry remains part of storage isolation.

Preserve the PVC and IAM credentials on upgrade. Investigate initializer drift errors before changing users or policies. Restore storage data and credentials consistently with the database and retained execution state.