fix(api): MinIO health check use dynamic scheme and verify (Closes #13159 and #13158) (#13197)

## Summary

Fixes MinIO SSL/TLS support in two places: the MinIO **client**
connection and the **health check** used by the Admin/Service Health
dashboard. Both now respect the `secure` and `verify` settings from the
MinIO configuration.

Closes #13158
Closes #13159

---

## Problem

**#13158 – MinIO client:** The client in `rag/utils/minio_conn.py` was
hardcoded with `secure=False`, so RAGFlow could not connect to MinIO
over HTTPS even when `secure: true` was set in config. There was also no
way to disable certificate verification for self-signed certs.

**#13159 – MinIO health check:** In `api/utils/health_utils.py`, the
MinIO liveness check always used `http://` for the health URL. When
MinIO was configured with SSL, the health check failed and the dashboard
showed "timeout" even though MinIO was reachable over HTTPS.

---

## Solution

### MinIO client (`rag/utils/minio_conn.py`)

- Read `MINIO.secure` (default `false`) and pass it into the `Minio()`
constructor so HTTPS is used when configured.
- Add `_build_minio_http_client()` that reads `MINIO.verify` (default
`true`). When `verify` is false, return an `urllib3.PoolManager` with
`cert_reqs=ssl.CERT_NONE` and pass it as `http_client` to `Minio()` so
self-signed certificates are accepted.
- Support string values for `secure` and `verify` (e.g. `"true"`,
`"false"`).

### MinIO health check (`api/utils/health_utils.py`)

- Add `_minio_scheme_and_verify()` to derive URL scheme (http/https) and
the `verify` flag from `MINIO.secure` and `MINIO.verify`.
- Update `check_minio_alive()` to use the correct scheme, pass `verify`
into `requests.get(..., verify=verify)`, and use `timeout=10`.

### Config template (`docker/service_conf.yaml.template`)

- Add commented optional MinIO keys `secure` and `verify` (and env vars
`MINIO_SECURE`, `MINIO_VERIFY`) so deployers know they can enable HTTPS
and optional cert verification.

### Tests

- **`test/unit_test/utils/test_health_utils_minio.py`** – Tests for
`_minio_scheme_and_verify()` and `check_minio_alive()` (scheme, verify,
status codes, timeout, errors).
- **`test/unit_test/utils/test_minio_conn_ssl.py`** – Tests for
`_build_minio_http_client()` (verify true/false/missing, string values,
`CERT_NONE` when verify is false).

---

## Testing

- Unit tests added/updated as above; run with the project's test runner.
- Manually: configure MinIO with HTTPS and `secure: true` (and
optionally `verify: false` for self-signed); confirm client operations
work and the Service Health dashboard shows MinIO as alive instead of
timeout.
This commit is contained in:
PandaMan
2026-02-25 09:47:12 +08:00
committed by GitHub
parent c292d617ca
commit f4cbdc3a3b
5 changed files with 267 additions and 8 deletions

View File

@@ -233,14 +233,40 @@ def get_mysql_status():
}
def _minio_scheme_and_verify():
"""
Determine URL scheme (http/https) and SSL verify flag for MinIO health check.
Uses MINIO.secure for scheme and MINIO.verify for certificate verification
(e.g. self-signed certs when verify is False).
"""
secure = settings.MINIO.get("secure", False)
if isinstance(secure, str):
secure = secure.lower() in ("true", "1", "yes")
scheme = "https" if secure else "http"
verify = settings.MINIO.get("verify", True)
if isinstance(verify, str):
verify = verify.lower() not in ("false", "0", "no")
elif isinstance(verify, bool):
pass
else:
verify = bool(verify)
return scheme, verify
def check_minio_alive():
"""
Check MinIO service liveness via /minio/health/live.
Uses http or https and optional certificate verification based on
MINIO.secure and MINIO.verify configuration.
"""
start_time = timer()
try:
response = requests.get(f'http://{settings.MINIO["host"]}/minio/health/live')
scheme, verify = _minio_scheme_and_verify()
url = f"{scheme}://{settings.MINIO['host']}/minio/health/live"
response = requests.get(url, timeout=10, verify=verify)
if response.status_code == 200:
return {"status": "alive", "message": f"Confirm elapsed: {(timer() - start_time) * 1000.0:.1f} ms."}
else:
return {"status": "timeout", "message": f"Confirm elapsed: {(timer() - start_time) * 1000.0:.1f} ms."}
return {"status": "timeout", "message": f"Confirm elapsed: {(timer() - start_time) * 1000.0:.1f} ms."}
except Exception as e:
return {
"status": "timeout",