From 29335905023718687f27fab96d37cc1b730290ea Mon Sep 17 00:00:00 2001 From: shlomiko Date: Sun, 23 Aug 2026 15:39:49 +0300 Subject: [PATCH 1/2] fix(helm): set SSL_CERT_FILE alongside REQUESTS_CA_BUNDLE when root-ca is mounted Co-Authored-By: Claude Fable 5 --- helm/templates/mapproxy/mapproxy-container.yaml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/helm/templates/mapproxy/mapproxy-container.yaml b/helm/templates/mapproxy/mapproxy-container.yaml index ad14793..b499d89 100644 --- a/helm/templates/mapproxy/mapproxy-container.yaml +++ b/helm/templates/mapproxy/mapproxy-container.yaml @@ -20,6 +20,8 @@ value: {{ printf "%s/%s" .Values.global.ca.path .Values.global.ca.key | quote }} - name: NODE_EXTRA_CA_CERTS value: {{ printf "%s/%s" .Values.global.ca.path .Values.global.ca.key | quote }} + - name: SSL_CERT_FILE + value: {{ printf "%s/%s" .Values.global.ca.path .Values.global.ca.key | quote }} {{- end }} {{- if eq (upper $storage.tilesStorageProvider) "S3" }} - name: AWS_ACCESS_KEY_ID From 47e51a6a8a4a0e3ef4ee3dc48770a1b9aacf97c4 Mon Sep 17 00:00:00 2001 From: shlomiko Date: Sun, 23 Aug 2026 15:55:40 +0300 Subject: [PATCH 2/2] refactor(helm): dedupe CA cert path printf into a single template variable Co-Authored-By: Claude Fable 5 --- helm/templates/mapproxinator/mapproxinator-container.yaml | 5 +++-- helm/templates/mapproxy/mapproxy-container.yaml | 7 ++++--- 2 files changed, 7 insertions(+), 5 deletions(-) diff --git a/helm/templates/mapproxinator/mapproxinator-container.yaml b/helm/templates/mapproxinator/mapproxinator-container.yaml index b034995..54ddd47 100644 --- a/helm/templates/mapproxinator/mapproxinator-container.yaml +++ b/helm/templates/mapproxinator/mapproxinator-container.yaml @@ -2,15 +2,16 @@ {{- $mapproxinatorConfigmapName := include "mapproxinator-configmap.fullname" . -}} {{- $db := (include "common.db.merged" .) | fromYaml }} {{- $storage := (include "common.storage.merged" .) | fromYaml }} +{{- $caCertPath := printf "%s/%s" .Values.global.ca.path .Values.global.ca.key }} - name: mapproxinator image: {{ .cloudProviderDockerRegistryUrl }}{{ .Values.mapproxinator.image.repository }}:{{ .Values.mapproxinator.image.tag }} imagePullPolicy: {{ .Values.imagePullPolicy }} env: {{- if .Values.global.ca.secretName }} - name: REQUESTS_CA_BUNDLE - value: {{ printf "%s/%s" .Values.global.ca.path .Values.global.ca.key | quote }} + value: {{ $caCertPath | quote }} - name: NODE_EXTRA_CA_CERTS - value: {{ printf "%s/%s" .Values.global.ca.path .Values.global.ca.key | quote }} + value: {{ $caCertPath | quote }} {{- end }} - name: INIT_MODE value: "false" diff --git a/helm/templates/mapproxy/mapproxy-container.yaml b/helm/templates/mapproxy/mapproxy-container.yaml index b499d89..83069e3 100644 --- a/helm/templates/mapproxy/mapproxy-container.yaml +++ b/helm/templates/mapproxy/mapproxy-container.yaml @@ -3,6 +3,7 @@ {{- $storage := (include "common.storage.merged" .) | fromYaml }} {{- $fs := (include "common.fs.merged" .) | fromYaml }} {{- $metrics := (include "common.metrics.merged" .) | fromYaml }} +{{- $caCertPath := printf "%s/%s" .Values.global.ca.path .Values.global.ca.key }} - name: mapproxy image: {{ .cloudProviderDockerRegistryUrl }}{{ .Values.mapproxy.image.repository }}:{{ .Values.mapproxy.image.tag }} imagePullPolicy: {{ .Values.imagePullPolicy }} @@ -17,11 +18,11 @@ value: {{ .Values.mapproxy.redis.healthCheckInterval | quote }} {{- if .Values.global.ca.secretName }} - name: REQUESTS_CA_BUNDLE - value: {{ printf "%s/%s" .Values.global.ca.path .Values.global.ca.key | quote }} + value: {{ $caCertPath | quote }} - name: NODE_EXTRA_CA_CERTS - value: {{ printf "%s/%s" .Values.global.ca.path .Values.global.ca.key | quote }} + value: {{ $caCertPath | quote }} - name: SSL_CERT_FILE - value: {{ printf "%s/%s" .Values.global.ca.path .Values.global.ca.key | quote }} + value: {{ $caCertPath | quote }} {{- end }} {{- if eq (upper $storage.tilesStorageProvider) "S3" }} - name: AWS_ACCESS_KEY_ID