Bug Reports
Planned

Shared cache chart: enabling authentication alone leaves the cache open

On the shared cache Helm chart, setting auth.enabled: true and nothing else produces a cache with no password, silently.

The chart points the cache resource at a Secret named <release>-redis-auth, but no template in the chart ever creates that Secret, and nothing generates a password. The reference simply dangles. There is no validation to catch it, so the values say authentication is on while the instance keeps accepting unauthenticated connections.

A working configuration needs three values, not one: auth.enabled, plus secret: to render the Secret, plus auth.existingSecret pointing at it. That is what was used to close the platform security gap on 2026-08-19.

Why it matters: this is the exact setting the troubleshooting documentation told people to use. Anyone who set it and moved on would have believed the gap was closed while it was still wide open.

Fix options: generate a password when none is supplied, or fail the render with a clear message when auth.enabled is set without a usable secret source. Failing loudly is much better than a cache that quietly accepts anyone.

0 Comments

Sign in to comment

No comments yet. Be the first to share your thoughts!