You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache Superset Helm Chart模板自定义修改不生效问题求助

问题:自定义Superset Helm Secret未生成且挂载失效

环境与操作

使用Superset Helm Chart 0.12.9,已完成以下操作:

  1. 在templates/目录添加自定义Secret模板
  2. 修改templates/deployment.yaml,添加对应volumes和volumeMounts
  3. 在modified-values.yaml配置相关参数
  4. 执行helm upgrade后,自定义Secret未创建,挂载配置也未生效

自定义配置详情

1. 自定义Secret模板(templates/superset-config-oci-secret.yaml)

apiVersion: v1
kind: Secret
metadata:
  name: {{ template "superset.fullname" . }}-config-oci
  namespace: {{ .Release.Namespace }}
  labels:
    app: {{ template "superset.fullname" . }}
    chart: {{ template "superset.chart" . }}
    release: "{{ .Release.Name }}"
    heritage: "{{ .Release.Service }}"
type: Opaque
stringData:
  {{- if .Values.extraSecretsOci }}
  {{- range $path, $config := .Values.extraSecretsOci }}
  {{ $path }}: |
    {{- tpl $config $ | nindent 4 -}}
  {{- end -}}
  {{- end -}}

注:原模板中.Values.**extraSecretsOci**的加粗符号是语法错误,已修正为.Values.extraSecretsOci

2. 修改后的templates/deployment.yaml相关片段

volumeMounts:
            - name: superset-config
              mountPath: {{ .Values.configMountPath | quote }}
              readOnly: true
            {{- if .Values.extraConfigs }}
            - name: superset-extra-config
              mountPath: {{ .Values.extraConfigMountPath | quote }}
              readOnly: true
            {{- end }}
            - name: superset-config-oci
              mountPath: {{ .Values.configMountPathOci | quote }}
              readOnly: true
volumes:
        - name: superset-config
          secret:
            secretName: {{ tpl .Values.configFromSecret . }}
        {{- if .Values.extraConfigs }}
        - name: superset-extra-config
          configMap:
            name: {{ template "superset.fullname" . }}-extra-config
        {{- end }}
        - name: superset-config-oci
          secret:
            secretName: {{ tpl .Values.configFromSecretOci . }}
        {{- with .Values.extraVolumes }}
          {{- tpl (toYaml .) $ | nindent 8 -}}
        {{- end }}

3. modified-values.yaml配置

extraSecretsOci:
  user_oci.pem: "private_key file"
  config: "config file"

configMountPathOci: "/root/.oci"

configFromSecretOci: superset-config-oci

预期与实际效果

  • 预期:生成包含config和user_oci.pem的superset-config-oci Secret,并挂载到容器/root/.oci路径
  • 实际:Secret未创建,挂载配置未生效

解决步骤

1. 修复Secret模板语法与文件名

  • 确保模板文件存放在templates/目录下,后缀为.yaml/.yml(比如templates/superset-config-oci-secret.yaml),Helm只会渲染该目录下的合法模板文件
  • 移除模板中.Values.extraSecretsOci的多余加粗符号,修正为.Values.extraSecretsOci(原模板中的**是语法错误,会导致Helm无法解析)

2. 验证Helm渲染结果

执行以下命令查看模板渲染后的输出,确认是否生成正确的Secret和Deployment配置:

helm template . -f modified-values.yaml --debug
  • 如果有语法报错,根据提示修复模板问题
  • 检查渲染后的Secret是否包含user_oci.pem和config字段,Deployment的volumes和volumeMounts是否正确引用了Secret

3. 确认Helm升级命令加载了自定义values

执行helm upgrade时必须显式指定自定义values文件,否则配置不会生效:

helm upgrade superset . -f modified-values.yaml -n <你的命名空间>

替换<你的命名空间>为实际使用的Kubernetes命名空间

4. 修正Secret名称匹配问题

模板中生成的Secret名称是{{ template "superset.fullname" . }}-config-oci(会根据release name生成完整名称,比如release名为superset时是superset-config-oci),但如果你的release name不是superset,configFromSecretOci的固定值会导致不匹配。建议修改modified-values.yaml为:

configFromSecretOci: "{{ template "superset.fullname" . }}-config-oci"

这样会自动根据release name生成正确的Secret名称,避免硬编码导致的不匹配。

5. 检查Deployment的容器配置

确认volumeMounts添加到了Superset的所有需要的容器中(比如主容器、worker容器等),如果只添加到了某个容器,其他容器不会生效。

6. 查看Helm发布状态

执行以下命令查看Helm发布的状态和事件,排查是否有部署错误:

helm history superset -n <你的命名空间>
kubectl describe deployment superset -n <你的命名空间>

内容的提问来源于stack exchange,提问作者Mohamed Rhimi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 15:53:17