This is an automated email from the ASF dual-hosted git repository. github-merge-queue[bot] pushed a commit to branch gh-readonly-queue/release/v1.3/pr-8623-0f3192ea416e151ef73682e9aee33c878f79096f in repository https://gitbox.apache.org/repos/asf/texera.git
commit 3e800323d5be1a4b8fd5079ce8d5cb33fbfe22fe Author: Meng Wang <[email protected]> AuthorDate: Mon Sep 21 20:08:01 2026 +0000 fix(deploy, v1.3): enable CORS on RustFS so browsers can fetch presigned URLs (#8623) ### What changes were proposed in this PR? Backport of #8562 to `release/v1.3`: a clean cherry-pick of its squash commit, no adaptations — five added lines across the single-node compose file, the dev compose file and the Helm chart's `extraEnv`. This branch needs it because #8550 already made RustFS the default object store here. RustFS sends no CORS headers unless `RUSTFS_CORS_ALLOWED_ORIGINS` is set (its reflective default was removed as CVE-2026-46685), while MinIO sent them by default — so without this change a v1.3 deployment renders no dataset file preview: the browser's cross-origin fetch of the presigned URL is blocked and the preview stays in its loading state. Opened manually by the v1.3 release manager: the automated fast path cherry-picked this cleanly and then pushed it straight to `release/v1.3`, where the Merge Queue ruleset rejected the push (`GH013`, [run 35305278774](https://github.com/apache/texera/actions/runs/35305278774)). The Actions-app bypass meant to unblock that path (#8379) was never created — asfyaml rejects an `Integration` bypass actor — and the failing job's notification 403s for want of `pull-requests: write`, so the loss left neither a backport PR nor a comment on #8562. The `release/v1.2` backport did get a PR (#8585, merged) only because it took the other code path. See #8377. Source: af6e0fdd96f44c1d575278b9fd12ed61ce6a8640 ### Any related issues, documentation, discussions? Backport of #8562. Originally linked #8557. ### How was this PR tested? The change is identical to #8562 (configuration only, no application code); the backport tree is verified byte-identical to cherry-picking the squash commit onto `release/v1.3`. Release-branch CI runs the full matrix on this PR, including the integration jobs that provision RustFS. ### Was this PR authored or co-authored using generative AI tooling? Yes. Generated-by: Claude Code (claude-opus-5) Co-authored-by: Xuan Gu <[email protected]> Co-authored-by: Claude Fable 5 <[email protected]> --- bin/k8s/values.yaml | 3 +++ bin/single-node/docker-compose.yml | 1 + file-service/src/main/resources/docker-compose.yml | 1 + 3 files changed, 5 insertions(+) diff --git a/bin/k8s/values.yaml b/bin/k8s/values.yaml index 11b102b728..f88d5acd14 100644 --- a/bin/k8s/values.yaml +++ b/bin/k8s/values.yaml @@ -111,6 +111,9 @@ rustfs: rustfs: access_key: texera_rustfs secret_key: password + extraEnv: + - name: RUSTFS_CORS_ALLOWED_ORIGINS + value: "*" config: rustfs: # Must match storage.s3.region: the region is part of the SigV4 scope. diff --git a/bin/single-node/docker-compose.yml b/bin/single-node/docker-compose.yml index f604db653a..d09cbc09a3 100644 --- a/bin/single-node/docker-compose.yml +++ b/bin/single-node/docker-compose.yml @@ -29,6 +29,7 @@ services: environment: - RUSTFS_ACCESS_KEY=${STORAGE_S3_AUTH_USERNAME} - RUSTFS_SECRET_KEY=${STORAGE_S3_AUTH_PASSWORD} + - RUSTFS_CORS_ALLOWED_ORIGINS=* # Must match STORAGE_S3_REGION: the region is part of the SigV4 scope, and # LakeFS sends its blockstore region on every request. - RUSTFS_REGION=${STORAGE_S3_REGION} diff --git a/file-service/src/main/resources/docker-compose.yml b/file-service/src/main/resources/docker-compose.yml index 95088150b1..98cef98029 100644 --- a/file-service/src/main/resources/docker-compose.yml +++ b/file-service/src/main/resources/docker-compose.yml @@ -27,6 +27,7 @@ services: environment: - RUSTFS_ACCESS_KEY=texera_rustfs - RUSTFS_SECRET_KEY=password + - RUSTFS_CORS_ALLOWED_ORIGINS=* # Must match the region the AWS SDK signs with: it is part of the SigV4 scope. - RUSTFS_REGION=us-west-2 - RUSTFS_CONSOLE_ENABLE=true
