fix(s3): correct MinIO service port and allow egress
CI / CI (pull_request) Successful in 3m16s

MinIO ClusterIP service listens on port 80 (targetPort 9000).
Config had port 9000 which caused 30s timeout then 502 — gateway
connected to service port 9000 which doesn't exist on the ClusterIP.

Changes:
- configmap.yaml: S3 upstream :9000 → :80
- gateway-config-secret.enc.yaml: same
- network-policy.yaml: add port 80 egress to storage namespace

Verified: S3 adapter now reaches MinIO (403 AccessDenied = auth issue,
not connectivity).
This commit is contained in:
Admin Bot
2026-09-08 09:58:36 -07:00
parent 7e78519499
commit c87463c850
3 changed files with 6 additions and 2 deletions
+1 -1
View File
@@ -113,7 +113,7 @@ data:
- serviceName: s3
upstream:
url: http://minio.storage.svc.cluster.local:9000
url: http://minio.storage.svc.cluster.local:80
timeoutSeconds: 30
auth:
required: false
+1 -1
View File
@@ -91,7 +91,7 @@ stringData:
upstreamPath: /memory/skills
- serviceName: s3
upstream:
url: http://minio.storage.svc.cluster.local:9000
url: http://minio.storage.svc.cluster.local:80
timeoutSeconds: 30
auth:
required: false
+4
View File
@@ -123,10 +123,14 @@ spec:
- protocol: TCP
port: 8080
# Allow to MinIO (S3-compatible storage)
# Service `minio` listens on port 80 (targetPort 9000).
# Headless `minio-cluster-hl` is 9000. Allow both.
- to:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: storage
ports:
- protocol: TCP
port: 80
- protocol: TCP
port: 9000