This is an automated email from the ASF dual-hosted git repository.

github-merge-queue[bot] pushed a commit to branch 
gh-readonly-queue/main/pr-8562-8284b4280c4cd988a4b072900fb7dca7b89cf56b
in repository https://gitbox.apache.org/repos/asf/texera.git

commit af6e0fdd96f44c1d575278b9fd12ed61ce6a8640
Author: Xuan Gu <[email protected]>
AuthorDate: Fri Sep 18 03:54:27 2026 +0000

    fix(deploy): enable CORS on RustFS so browsers can fetch presigned URLs 
(#8562)
    
    ### What changes were proposed in this PR?
    
    Set `RUSTFS_CORS_ALLOWED_ORIGINS=*` on the rustfs service (single-node
    compose, K8s chart via `extraEnv`, dev compose).
    
    The dataset file preview fetches presigned URLs directly from the
    browser, which is cross-origin. MinIO sent CORS headers by default;
    RustFS sends none unless this variable is set (the old reflective
    default was removed as CVE-2026-46685), so the preview shows a loading
    state and does not render the content. Wildcard mode never allows
    credentialed requests, and presigned requests carry no cookies, so this
    restores MinIO's behavior without loosening anything; deployments that
    want an allow-list can override it with their GUI origin.
    
    ### Any related issues, documentation, discussions?
    
    Fixes #8557.
    
    ### How was this PR tested?
    
    Tested on single-node deployment.
    
    ### Was this PR authored or co-authored using generative AI tooling?
    
    Generated-by: Claude Fable 5 (Claude Code)
    
    Co-authored-by: Claude Fable 5 <[email protected]>
---
 bin/k8s/values.yaml                                | 3 +++
 bin/single-node/docker-compose.yml                 | 1 +
 file-service/src/main/resources/docker-compose.yml | 1 +
 3 files changed, 5 insertions(+)

diff --git a/bin/k8s/values.yaml b/bin/k8s/values.yaml
index 8cd3a94d18..4f24269b39 100644
--- a/bin/k8s/values.yaml
+++ b/bin/k8s/values.yaml
@@ -111,6 +111,9 @@ rustfs:
     rustfs:
       access_key: texera_rustfs
       secret_key: password
+  extraEnv:
+    - name: RUSTFS_CORS_ALLOWED_ORIGINS
+      value: "*"
   config:
     rustfs:
       # Must match storage.s3.region: the region is part of the SigV4 scope.
diff --git a/bin/single-node/docker-compose.yml 
b/bin/single-node/docker-compose.yml
index f604db653a..d09cbc09a3 100644
--- a/bin/single-node/docker-compose.yml
+++ b/bin/single-node/docker-compose.yml
@@ -29,6 +29,7 @@ services:
     environment:
       - RUSTFS_ACCESS_KEY=${STORAGE_S3_AUTH_USERNAME}
       - RUSTFS_SECRET_KEY=${STORAGE_S3_AUTH_PASSWORD}
+      - RUSTFS_CORS_ALLOWED_ORIGINS=*
       # Must match STORAGE_S3_REGION: the region is part of the SigV4 scope, 
and
       # LakeFS sends its blockstore region on every request.
       - RUSTFS_REGION=${STORAGE_S3_REGION}
diff --git a/file-service/src/main/resources/docker-compose.yml 
b/file-service/src/main/resources/docker-compose.yml
index 95088150b1..98cef98029 100644
--- a/file-service/src/main/resources/docker-compose.yml
+++ b/file-service/src/main/resources/docker-compose.yml
@@ -27,6 +27,7 @@ services:
     environment:
       - RUSTFS_ACCESS_KEY=texera_rustfs
       - RUSTFS_SECRET_KEY=password
+      - RUSTFS_CORS_ALLOWED_ORIGINS=*
       # Must match the region the AWS SDK signs with: it is part of the SigV4 
scope.
       - RUSTFS_REGION=us-west-2
       - RUSTFS_CONSOLE_ENABLE=true

Reply via email to