Good evening I am trying to enable the personal ac...
# all-things-deployment
w
Good evening I am trying to enable the personal access tokens inside GKE in GCP, but I always get the same error “Token based authentication is currently disabled. Contact your DataHub administrator to enable this feature.” I have in my values.yaml file the following configuration but I always get the same error.
Copy code
global:        
  datahub:
    metadata_service_authentication:
      enabled: false
      systemClientId: "__datahub_system"
      systemClientSecret:
        secretRef: "datahub-auth-secrets"
        secretKey: "token_service_signing_key"
      tokenService:
        signingKey:
          secretRef: "datahub-auth-secrets"
          secretKey: "token_service_signing_key"
        salt:
          secretRef: "datahub-auth-secrets"
          secretKey: "token_service_salt"
        # Set to false if you'd like to provide your own auth secrets
      provisionSecrets: 
        enabled: true
        autoGenerate: true
        annotations: {}
b
set it to:
Copy code
metadata_service_authentication:
      enabled: true
to enable tokens
thanks bear 2
plus1 1
w
Good morning I was doing the tests changing the yaml but it generates errors in the installation of datahub with our values.yaml file.
Copy code
Error: INSTALLATION FAILED: rendered manifests contain a resource that already exists. Unable to continue with install: Secret "datahub-auth-secrets" in namespace "default" exists and cannot be imported into the current release: invalid ownership metadata; label validation error: missing key "<http://app.kubernetes.io/managed-by|app.kubernetes.io/managed-by>": must be set to "Helm"; annotation validation error: missing key "<http://meta.helm.sh/release-name|meta.helm.sh/release-name>": must be set to "datahub"; annotation validation error: missing key "<http://meta.helm.sh/release-namespace|meta.helm.sh/release-namespace>": must be set to "default"
I am enabling and adding the new secret datahub-auth-secrets but the error persists, do you know what could be the error?
b
im uncertain how you're updating your helm chart - it appears that you're not upgrading the release and instead possibly uninstalling the old one and installing a new one under a different name? if so, then somehow your auth-secrets is kept undeleted (not sure why) and the new release is unable to use it cos it sees that it is using the secret name but not meant for it.
plus1 1