Not settings are applied via config.yml during k8s deployment after upgrade

We are using a clone of TrueCharts Vikunja chart ( helm-charts/charts/vikunja at main · EugenMayer/helm-charts · GitHub ) which just introduced external DB settings.

We have been using this chart for a while know, but after upgrading from 0.24.6 to 2.6 we are no longer able to apply any configuration via the values.yml

For example setting

vikunja:
  auth:
    local:
      enabled: false
  openid:
    enabled: true
    providers:
      kw1:
        name: "My IDP"
        authurl: "redacted"
        logouturl: "redacted"
        clientid: "redacted"
        clientsecret: "redacted"
        scope: "openid profile email"
        usernamefallback: false
        emailfallback: false
        forceuserinfo: false
        requireavailability: true

Will still allow local login and open-id is not configured.

We already fix the truechart but that the configuration is mounted to /etc/vikunja/config.yaml and not like it should to /etc/vikunja/config.yml but still, nothing working.

I can check via

kubectl get secret -n vikunja vikunja-config --output json | jq '.data."config.yaml"' -r | base64 -d | grep 'auth:' -A5
auth:
  local:
    enabled: false
  openid:
    enabled: true
    providers:

that the configuration is actually present and formatted the right way and i can see that the volume is mounted

kubectl get pod -n vikunja vikunja-8885d8994-8dzpv --output json | jq '.spec.volumes' | tail -n 10
  },
  {
    "name": "vikunja-config",
    "secret": {
      "defaultMode": 420,
      "optional": false,
      "secretName": "vikunja-config"
    }
  }
]

kubectl get pod -n vikunja vikunja-8885d8994-8dzpv --output json | jq '.spec.containers[0].volumeMounts' | tail -n 10
  {
    "mountPath": "/var/run",
    "name": "varrun"
  },
  {
    "mountPath": "/etc/vikunja/config.yml",
    "name": "vikunja-config",
    "subPath": "config.yaml"
  }
]

I cannot really check the path within the pod since it is distroless.

Can someone point out what could be wrong?

What I tried

  • Setting the log.level to trace via ENV VIKUNJA_LOG_LEVEL: 'trace’did not reveal anything useful
  • Setting ENV VIKUNJA_AUTH_LOCAL_ENABLED: ‘false’ did not switch of local auth also (what has precedence, ENV or config?)
  • Tried to set ENV VIKUNJA_SERVICE_ROOTPATH: /etc/vikunja to ensure the configuration is looked up at the right spot
  • Tried to set fsGroup: 1000 and runAsUser: 1000
  • Tried to compare with the official chart at but could not spot anything significant go-vikunja/helm-chart
  • Tried to triple check the documentation on openid official vikunja documentation

TLTR

Whatever I try to configure via /etc/vikunja/config.yml is not applied

After i tried checking FQDN/api/v1/info is saw that all my values have been actually loaded.

This is when i saw that the frontend was configuring against ‘localhost’ not my actual FQDN.

the reason is, that service.publicurl was not set and this seems to be a new value. Setting this let’s the frontend talk against the actual backend (odd, since there is no localhost … not throwing ANY errors that the downstream backend is missing is very odd by the UI).