Back to Rustfs

RustFS Helm Mode

helm/README.md

1.0.0-rc.128.5 KB
Original Source

RustFS Helm Mode

RustFS helm chart supports standalone and distributed mode.

  • Standalone mode: one pod with one PVC (single node, single disk).
  • Distributed mode (default): multiple pods with multiple PVCs (multiple nodes, multiple disks).

Distributed topology

The distributed topology is defined by two parameters:

  • replicaCount — number of pods (nodes) in the StatefulSet.
  • drivesPerNode — number of data PVCs mounted on each pod.

Total drives in the cluster = replicaCount * drivesPerNode.

When drivesPerNode is left unset, the chart automatically infers a backward-compatible value from each pool's replica count (with pools disabled there is a single pool driven by the top-level replicaCount):

replicaCountInferred drivesPerNodeLegacy equivalent
44old default 4×4
anything else1old 16×1, etc.

You can override the inference by setting drivesPerNode explicitly, e.g. --set drivesPerNode=2 for an 8×2 cluster.

IMPORTANT: Kubernetes does not allow changes to volumeClaimTemplates in an existing StatefulSet. If you want to change drivesPerNode after installation you must delete the StatefulSet (with --cascade=orphan to keep pods and PVCs) and recreate it, or perform a full reinstall.


Upgrade notes

Upgrading from chart versions that did not have drivesPerNode is safe without manual intervention:

  • Existing 4×4 deployments (default replicaCount=4) continue to receive 4 drives per node because the chart infers drivesPerNode=4.
  • Existing 16×1 deployments (replicaCount=16) continue to receive 1 drive per node because the chart infers drivesPerNode=1.

If you previously set replicaCount=16 and now want a different topology, set both replicaCount and drivesPerNode explicitly.

For distributed deployments that use the chart-generated RUSTFS_VOLUMES, localEndpointHost.autoInject defaults to automatic selection. Without secret.existingSecret, the chart injects a private Downward API variable, RUSTFS_CHART_POD_NAME, and uses it to build the pod's fully qualified hostname in RUSTFS_LOCAL_ENDPOINT_HOST. RustFS can then identify local drives without waiting for every peer's DNS record or TCP listener. A user-defined POD_NAME is preserved and does not interfere with the private chart variable. Setting RUSTFS_STARTUP_TOPOLOGY_WAIT_MODE explicitly to bounded, fail-fast, failfast, or strict also keeps legacy DNS-based locality discovery. A dynamically sourced wait mode keeps the legacy path because its value cannot be validated while rendering. Otherwise, Kubernetes auto-detection selects orchestrated startup when RustFS consumes the generated anchor.

An existing Secret is opaque to the chart and may historically contain more than credentials, so the chart does not inject an anchor whenever secret.existingSecret is set. In Kubernetes auto/orchestrated mode, RustFS then derives a DNS-free identity from the kernel hostname when exactly one domain endpoint at the server port has the same full hostname or first label. All-IP topologies retain direct IP locality detection. A domain topology with zero matches retains legacy DNS locality discovery; implicit auto mode bounds that compatibility path by RUSTFS_STARTUP_TOPOLOGY_WAIT_TIMEOUT (180 seconds by default). Multiple matching candidates remain an error. Set RUSTFS_LOCAL_ENDPOINT_HOST explicitly to avoid DNS discovery. For a credentials-only Secret, set localEndpointHost.autoInject=true to add the chart anchor without changing the historical ConfigMap-then-Secret envFrom precedence. If injection is explicitly enabled with an incompatible hidden RUSTFS_VOLUMES, RUSTFS_ADDRESS, or RUSTFS_STARTUP_TOPOLOGY_WAIT_MODE, RustFS also fails during endpoint construction; it does not silently fall back to a different topology.

When config.rustfs.volumes is set explicitly, the chart does not infer a local endpoint identity. RustFS applies the same kernel-hostname inference to custom domain topologies in Kubernetes auto/orchestrated mode; aliases that do not match the Pod hostname retain legacy DNS locality, with the bounded auto fallback described above. They may provide RUSTFS_LOCAL_ENDPOINT_HOST through extraEnv for DNS-free startup. An explicit RUSTFS_VOLUMES, explicit RUSTFS_LOCAL_ENDPOINT_HOST, bounded/dynamic or unrecognized startup mode, or localEndpointHost.autoInject=false, also disables chart injection. A RUSTFS_ADDRESS override alone does not disable it; the effective address and generated topology must agree on the endpoint port. Custom anchor-based configurations must resolve to orchestrated startup mode and must not receive a conflicting mode from an envFrom source. startupWaitTimeoutSeconds is retained for values-file compatibility but is deprecated and ignored. Historical RUSTFS_STARTUP_TOPOLOGY_RETRY_MAX_DELAY values of 0 or 0ms are replaced with the safe default retry cap instead of causing a busy loop or blocking a direct upgrade.

Upgrade the chart and RustFS image together. An older image that does not recognize RUSTFS_LOCAL_ENDPOINT_HOST retains its previous DNS-based startup behavior.


Parameters Overview

ParameterTypeDefault valueDescription
affinity.nodeAffinityobject{}
affinity.podAntiAffinity.enabledbooltrue
affinity.podAntiAffinity.topologyKeystring"kubernetes.io/hostname"
clusterDomainstring"cluster.local"Kubernetes cluster DNS domain used to build in-cluster FQDNs for RUSTFS_VOLUMES (distributed mode) and mTLS server certificate SANs. Override for clusters not using the default cluster.local. Provide the DNS root only, without a svc. prefix or leading/trailing dots.
localEndpointHost.autoInjectbool or nullnullAutomatically inject RUSTFS_LOCAL_ENDPOINT_HOST for chart-generated distributed topologies unless secret.existingSecret is set. Use true for a credentials-only existing Secret or false to preserve legacy DNS locality explicitly.
commonLabelsobject{}Labels to add to all deployed objects.
config.rustfs.addressstring":9000"
config.rustfs.console_addressstring":9001"
config.rustfs.console_enablestring"true"
config.rustfs.domainsstring""Enable virtual host mode.
config.rustfs.log_levelstring"info"
config.rustfs.obs_environmentstring"development"
config.rustfs.obs_log_directorystring"/logs"Log directory inside the RustFS container. Set to "" to disable log PVCs and mounts.
config.rustfs.regionstring"us-east-1"
config.rustfs.volumesstring""Explicit distributed volume topology. When empty, the chart generates the topology and normally injects RUSTFS_LOCAL_ENDPOINT_HOST; custom topologies must configure local endpoint identity explicitly when needed.
config.rustfs.log_rotation.sizeint"100"Default log rotation size mb for rustfs.
config.rustfs.log_rotation.timestring"hour"Default log rotation time for rustfs.
config.rustfs.log_rotation.keep_filesint"30"Default log keep files for rustfs.
config.rustfs.metrics.enabledboolfalseToggle metrics export.
config.rustfs.metrics.endpointstring""Dedicated metrics endpoint.
config.rustfs.scanner.speedstring""Scanner speed preset: fastest, fast, default, slow, slowest.
config.rustfs.scanner.delaystring""Override scanner sleep multiplier with RUSTFS_SCANNER_DELAY (0 through 10000).
config.rustfs.scanner.max_wait_secsstring""Override maximum scanner sleep in seconds with RUSTFS_SCANNER_MAX_WAIT_SECS.
config.rustfs.scanner.cycle_secsstring""Override scanner cycle interval in seconds with RUSTFS_SCANNER_CYCLE.
config.rustfs.scanner.start_delay_secsstring""Override scanner cycle interval in seconds with RUSTFS_SCANNER_START_DELAY_SECS.
config.rustfs.scanner.cycle_max_duration_secsstring""Cap one scanner cycle's runtime in seconds with RUSTFS_SCANNER_CYCLE_MAX_DURATION_SECS (0 disables).
config.rustfs.scanner.cycle_max_objectsstring""Cap objects processed by one scanner cycle with RUSTFS_SCANNER_CYCLE_MAX_OBJECTS (0 disables).
config.rustfs.scanner.cycle_max_directoriesstring""Cap directories entered by one scanner cycle with RUSTFS_SCANNER_CYCLE_MAX_DIRECTORIES (0 disables).
config.rustfs.scanner.bitrot_cycle_secsstring""Override periodic deep bitrot cycle with RUSTFS_SCANNER_BITROT_CYCLE_SECS; false, off, no, or disabled disables it.
config.rustfs.scanner.idle_modestring""Override scanner idle throttling flag (RUSTFS_SCANNER_IDLE_MODE).
config.rustfs.scanner.cache_save_timeout_secsstring""Override scanner cache save timeout in seconds with RUSTFS_SCANNER_CACHE_SAVE_TIMEOUT_SECS (minimum 1).
config.rustfs.scanner.max_concurrent_set_scansstring""Cap concurrent scanner set tasks with RUSTFS_SCANNER_MAX_CONCURRENT_SET_SCANS (0 keeps topology-derived concurrency).
config.rustfs.scanner.max_concurrent_disk_scansstring""Cap concurrent scanner disk bucket walks per set with RUSTFS_SCANNER_MAX_CONCURRENT_DISK_SCANS (0 keeps disk-count-derived concurrency).
config.rustfs.scanner.yield_every_n_objectsstring""Yield to the async runtime every N scanned objects with RUSTFS_SCANNER_YIELD_EVERY_N_OBJECTS (0 disables extra yield).
config.rustfs.scanner.alert_excess_versionsstring""Set version count threshold for scanner alerts with RUSTFS_SCANNER_ALERT_EXCESS_VERSIONS.
config.rustfs.scanner.alert_excess_version_sizestring""Set retained version byte threshold for scanner alerts with RUSTFS_SCANNER_ALERT_EXCESS_VERSION_SIZE.
config.rustfs.scanner.alert_excess_foldersstring""Set direct subfolder threshold for scanner alerts with RUSTFS_SCANNER_ALERT_EXCESS_FOLDERS.
config.rustfs.obs_endpoint.enabledboolfalseWhether to send metrics/logs/traces/profilings to remote endpoint, eg, OLTP.
config.rustfs.obs_endpoint.base_endpointstring""Root OTLP/HTTP endpoint, e.g. http://otel-collector:4318.
config.rustfs.obs_endpoint.use_stdoutboolfalseWhether to output logs to stdout in addition the OLTP.
config.rustfs.obs_endpoint.metrics.enabledboolfalseWhether to send metrics to remote endpoint.
config.rustfs.obs_endpoint.metrics.endpointstring""Remote endpoint url for metrics.
config.rustfs.obs_endpoint.trace.enabledboolfalseWhether to send trace to remote endpoint.
config.rustfs.obs_endpoint.trace.endpointstring""Remote endpoint url for trace.
config.rustfs.obs_endpoint.logs.enabledboolfalseWhether to send logs to remote endpoint.
config.rustfs.obs_endpoint.logs.endpointstring""Remote endpoint url for logs.
config.rustfs.obs_endpoint.profiling.enabledboolfalseWhether to send profiling to remote endpoint.
config.rustfs.obs_endpoint.profiling.endpointstring""Remote endpoint url for profiling.
config.rustfs.kms.enabledboolfalseWhether to enable kms.
config.rustfs.kms.typestringvaultThe kms type that RustFS supported.
config.rustfs.kms.vault.vault_backendstring""The vault backend, vault-kv2 or vault-transit.
config.rustfs.kms.vault.vault_addressstring""The vault address.
config.rustfs.kms.vault.vault_tokenstring""The vault token. Rendered into a dedicated Secret (<fullname>-kms-secret), never into the ConfigMap.
config.rustfs.kms.vault.vault_mount_pathstring"transit"The vault mount path, only works if vault_backend equals vault-transit .
config.rustfs.kms.vault.default_keystring"transit"The master key id for RustFS.
extraEnvlist[]Extra environment variables for the RustFS container. An explicit RUSTFS_LOCAL_ENDPOINT_HOST or RUSTFS_VOLUMES, or a bounded, dynamic, or unrecognized startup mode, disables generated anchor injection. POD_NAME and RUSTFS_ADDRESS remain independent overrides.
extraVolumeslist[]Extra volumes to add to the pod spec. Supported in both standalone (Deployment) and distributed (StatefulSet) modes.
extraVolumeMountslist[]Extra volume mounts to add to the RustFS container. Supported in both standalone (Deployment) and distributed (StatefulSet) modes.
containerSecurityContext.capabilities.drop[0]string"ALL"
containerSecurityContext.readOnlyRootFilesystembooltrue
containerSecurityContext.runAsNonRootbooltrue
priorityClassNamestring""
enableServiceLinksboolfalse
extraManifestslist[]List of additional k8s manifests.
fullnameOverridestring""
image.rustfs.pullPolicystring"IfNotPresent"
image.rustfs.repositorystring"rustfs/rustfs"RustFS docker image repository.
image.rustfs.tagstring""Chart appVersion default if unset.
imagePullSecretslist[]A List of secrets to pull image from private registry.
imageRegistryCredentials.emailstring""The email to pull rustfs image from private registry.
imageRegistryCredentials.enabledboolfalseTo indicate whether pull image from private registry.
imageRegistryCredentials.passwordstring""The password to pull rustfs image from private registry.
imageRegistryCredentials.registrystring""Private registry url to pull rustfs image.
imageRegistryCredentials.usernamestring""The username to pull rustfs image from private registry.
ingress.classNamestring"nginx"Specify the ingress class, traefik or nginx.
ingress.enabledbooltrue
ingress.hosts[0].hoststring"example.rustfs.com"
ingress.hosts[0].paths[0].pathstring"/"
ingress.hosts[0].paths[0].pathTypestring"ImplementationSpecific"
ingress.nginxAnnotations."nginx.ingress.kubernetes.io/affinity"string"cookie"
ingress.nginxAnnotations."nginx.ingress.kubernetes.io/session-cookie-expires"string"3600"
ingress.nginxAnnotations."nginx.ingress.kubernetes.io/session-cookie-hash"string"sha1"
ingress.nginxAnnotations."nginx.ingress.kubernetes.io/session-cookie-max-age"string"3600"
ingress.nginxAnnotations."nginx.ingress.kubernetes.io/session-cookie-name"string"rustfs"
ingress.customAnnotationsdict{}Additional custom annotations, merged with class-specific stickiness annotations.
ingress.traefikAnnotations."traefik.ingress.kubernetes.io/service.sticky.cookie"string"true"
ingress.traefikAnnotations."traefik.ingress.kubernetes.io/service.sticky.cookie.httponly"string"true"
ingress.traefikAnnotations."traefik.ingress.kubernetes.io/service.sticky.cookie.name"string"rustfs"
ingress.traefikAnnotations."traefik.ingress.kubernetes.io/service.sticky.cookie.samesite"string"none"
ingress.traefikAnnotations."traefik.ingress.kubernetes.io/service.sticky.cookie.secure"string"true"
ingress.tls.enabledboolfalseEnable tls and access rustfs via https.
ingress.tls.certManager.enabledstringfalseEnable cert manager support to generate certificate automatically.
ingress.tls.crtstring""The content of certificate file.
ingress.tls.keystring""The content of key file.
livenessProbe.failureThresholdint3
livenessProbe.httpGet.pathstring"/health"
livenessProbe.httpGet.portstring"endpoint"
livenessProbe.initialDelaySecondsint10
livenessProbe.periodSecondsint5
livenessProbe.successThresholdint1
livenessProbe.timeoutSecondsint3
mode.distributed.enabledbooltrueRustFS distributed mode support, namely multiple pod multiple pvc.
mode.standalone.enabledboolfalseRustFS standalone mode support, namely one pod one pvc.
mode.standalone.existingClaim.dataClaimstring""Whether to use existing pvc claim for data storage.
mode.standalone.existingClaim.logsClaimstring""Whether to use existing pvc claim for logs storage.
mtls.enabledboolfalseEnable mtls betweens pods.
mtls.clientCertPathstring/opt/tls/client_cert.pemThe path for client cert.
mtls.clientKeyPathstring/opt/tls/client_key.pemThe path for client key.
mtls.existingIssuerRef.enabledboolfalseEnable to use external/existing certificate issuer.
mtls.existingIssuerRef.namestring""The name of external/existing certificate issuer.
mtls.existingIssuerRef.kindstring""The kind of external/existing certificate iss
uer. ClusterIssuer or Issuer.
mtls.existingIssuerRef.groupstring""The group of external/existing certificate issuer.
nameOverridestring""
nodeSelectorobject{}
pdb.createboolfalseEnable/disable a Pod Disruption Budget creation
pdb.maxUnavailablestring1
pdb.minAvailablestring""
podAnnotationsobject{}
pools.enabledboolfalseEnable multiple server pools (capacity expansion, distributed mode only).
pools.listlist[]One entry per pool; entries may set replicaCount (>= 2) and storageclass, omitted fields inherit top-level values. Append-only.
podLabelsobject{}
podSecurityContext.fsGroupint10001
podSecurityContext.runAsGroupint10001
podSecurityContext.runAsUserint10001
readinessProbe.failureThresholdint3
readinessProbe.httpGet.pathstring"/health/ready"
readinessProbe.httpGet.portstring"endpoint"
readinessProbe.initialDelaySecondsint30
readinessProbe.periodSecondsint5
readinessProbe.successThresholdint1
readinessProbe.timeoutSecondsint3
replicaCountint4Number of cluster nodes. Distributed mode requires >= 2.
drivesPerNodeintnullNumber of data PVCs per pod. Inferred from replicaCount when unset (see Distributed topology above).
resources.limits.cpustring"200m"
resources.limits.memorystring"512Mi"
resources.requests.cpustring"100m"
resources.requests.memorystring"128Mi"
secret.existingSecretstring""Use an existing Secret. Automatic endpoint-anchor injection is disabled because the Secret is opaque; set localEndpointHost.autoInject=true only after confirming it contains credentials rather than runtime topology, address, or startup-mode overrides.
secret.rustfs.access_keystring"rustfsadmin"RustFS Access Key ID
secret.rustfs.secret_keystring"rustfsadmin"RustFS Secret Key ID
service.typestring"ClusterIP"
service.console.nodePortint32001
service.console.portint9001
service.endpoint.nodePortint32000
service.endpoint.portint9000
serviceAccount.annotationsobject{}
serviceAccount.automountbooltrue
serviceAccount.createbooltrue
serviceAccount.namestring""
startupWaitTimeoutSecondsint300Deprecated and ignored; retained for values-file compatibility.
storageclass.dataStorageSizestring"256Mi"The storage size for data PVC.
storageclass.logStorageSizestring"256Mi"The storage size for logs PVC.
storageclass.namestring"local-path"The name for StorageClass.
storageclass.pvcAnnotations.datamap{}Data pvc customized annotations.
storageclass.pvcAnnotations.logsmap{}Logs pvc customized annotations.
tolerationslist[]
topologySpreadConstraints.enabledboolfalseEnable custom topology spread constraints on distributed-mode StatefulSet pods.
topologySpreadConstraints.constraintslist[]Raw spec.template.spec.topologySpreadConstraints entries applied to the distributed StatefulSet when enabled.
gatewayApi.enabledboolfalseTo enable/disable gateway api support.
gatewayApi.gatewayClassstringtraefikGateway class implementation.
gatewayApi.listeners.http.namestringwebGateway API http listener name.
gatewayApi.listeners.http.portint8000Gateway API http listener port.
gatewayApi.listeners.https.namestringwebsecureGateway API https listener name.
gatewayApi.listeners.https.portint8443Gateway API https listener port.
gatewayApi.hostnamestringHostname to access RustFS via gateway api.
gatewayApi.secretNamestringSecret tls to via RustFS using HTTPS.
gatewayApi.existingGateway.namestring""The existing gateway name, instead of creating a new one.
gatewayApi.existingGateway.namespacestring""The namespace of the existing gateway, if not the local namespace.

Scanner values map directly to scanner environment variables. For tuning workflow and /v3/scanner/status interpretation, see Scanner Runtime Controls. For repeatable scanner-pressure validation, see Scanner Benchmark Runbook.


NOTE:

The chart pulls the rustfs image from Docker Hub by default. For private registries, provide either:

  • Existing secrets: Set imagePullSecrets with an array of secret names

    yaml
    imagePullSecrets:
      - name: my-existing-secret
    
  • Auto-generated secret: Enable imageRegistryCredentials.enabled: true and specify credentials plus your image details

    yaml
    imageRegistryCredentials:
      enabled: true
      registry: myregistry.com
      username: myuser
      password: mypass
      email: [email protected]
    

Both approaches support pulling from private registries seamlessly and you can also combine them.

  • The chart default pull rustfs image from dockerhub, if your rustfs image stores in private registry, you can use either existing image Pull secrets with parameter imagePullSecrets or create one setting imageRegistryCredentials.enabled to true,and then specify the imageRegistryCredentials.registry/username/password/email as well as image.rustfs.repository,image.rustfs.tag to pull rustfs image from your private registry.

  • The default storageclass is local-path,if you want to specify your own storageclass, try to set parameter storageclass.name.

  • The default size for data and logs dir is 256Mi which must satisfy the production usage,you should specify storageclass.dataStorageSize and storageclass.logStorageSize to change the size, for example, 1Ti for data and 1Gi for logs.

Server pools (capacity expansion)

In distributed mode the chart can run multiple server pools — independent StatefulSets whose drives together form one cluster, the same expansion model the RustFS server already supports via space-separated RUSTFS_VOLUMES expressions (rc admin pool ls / expand / rebalance / decommission).

With pools.enabled=false (default) the chart behaves exactly as before: one StatefulSet driven by the top-level replicaCount/storageclass.

To expand an existing deployment, enable pools and describe the current layout as pool 0 plus your new capacity:

yaml
pools:
  enabled: true
  list:
    - {}                  # pool 0: inherits top-level values and keeps the
                          # existing StatefulSet/pod/PVC names and data
    - replicaCount: 4     # pool 1: new capacity
      storageclass:
        dataStorageSize: 10Gi

Each entry may set replicaCount (>= 2) and/or a storageclass block; omitted fields inherit the top-level values. Additional pools render as <fullname>-pool<N> StatefulSets; all pools share the headless service, the main service, the configuration and the credentials.

Notes:

  • Pools are append-only. The list index determines the StatefulSet name — never remove or reorder entries. Retire a pool with rc admin decommission before removing it from the list.
  • With chart-generated volumes, each pod receives an explicit local endpoint identity. An unavailable peer no longer blocks a pod from reaching RustFS's own startup and quorum checks.
  • After the cluster converges, run rc admin rebalance start <alias> to spread existing objects across the new pool.
  • Pod anti-affinity in pool mode is scoped per pool and preferred (soft), not required: two pools can share nodes, and each pool's own pods spread across distinct nodes when capacity allows. Preferred affinity keeps additional pools schedulable when the cluster has fewer nodes than total pods. Single-pool deployments (pools.enabled=false) keep the chart's existing required anti-affinity unchanged.
  • The PodDisruptionBudget spans all pools: with the default pdb.maxUnavailable: 1, at most one pod of the whole cluster may be evicted at a time. This is deliberately conservative — quorum safety matters across the union of all pools.

Installation

Requirement

  • Helm V3
  • The RustFS image from the same release as the chart. If image.rustfs.tag is overridden, that image must support RUSTFS_LOCAL_ENDPOINT_HOST.

Due to the traefik and ingress has different session sticky/affinity annotations, and rustfs support both those two controller, you should specify parameter ingress.className to select the right one which suits for you.

Installation with traefik controller

If your ingress class is traefik, running the command:

helm install rustfs -n rustfs --create-namespace ./ --set ingress.className="traefik"

Installation with nginx controller

If your ingress class is nginx, running the command:

helm install rustfs -n rustfs --create-namespace ./ --set ingress.className="nginx"

Installation check and rustfs login

Check the pod status

kubectl -n rustfs get pods -w
NAME       READY   STATUS    RESTARTS        AGE
rustfs-0   1/1     Running   0               2m27s
rustfs-1   1/1     Running   0               2m27s
rustfs-2   1/1     Running   0               2m27s
rustfs-3   1/1     Running   0               2m27s

Check the ingress status

kubectl -n rustfs get ing
NAME     CLASS   HOSTS            ADDRESS         PORTS     AGE
rustfs   nginx   example.rustfs.com   10.43.237.152   80, 443   29m

Access the rustfs cluster via https://example.rustfs.com with the default username and password rustfsadmin.

Replace the example.rustfs.com with your own domain as well as the certificates.

TLS configuration

By default, tls is not enabled. If you want to enable tls(recommendated),you can follow below steps:

  • Step 1: Certification generation

You can request cert and key from CA or use the self-signed cert(not recommendated on prod), and put those two files(eg, tls.crt and tls.key) under some directory on server, for example tls directory.

  • Step 2: Certification specifying

You should use --set-file parameter when running helm install command, for example, running the below command can enable ingress tls and generate tls secret:

helm install rustfs rustfs/rustfs -n rustfs --set tls.enabled=true,--set-file tls.crt=./tls.crt,--set-file tls.key=./tls.key

Gateway API support (alpha)

Due to ingress nginx retirement in March 2026, so RustFS adds support for gateway api. Currently, RustFS only supports traefik as gateway class, more and more gateway class support will be added in the future after those classes are tested. If you want to enable gateway api, specify gatewayApi.enabled to true while specify ingress.enabled to false. After installation, you can find the Gateway and HttpRoute resources,

$ kubectl -n rustfs get gateway
NAME             CLASS     ADDRESS   PROGRAMMED   AGE
rustfs-gateway   traefik             True         169m

$ kubectl -n rustfs get httproute
NAME           HOSTNAMES            AGE
rustfs-route   ["example.rustfs.com"]   172m

Then, via RustFS instance via https://example.rustfs.com or http://example.rustfs.com.

Uninstall

Uninstalling the rustfs installation with command,

helm uninstall rustfs -n rustfs