From 7e78519499ee3cfed94f9c8e4a35b4116e5c7e82 Mon Sep 17 00:00:00 2001 From: Admin Bot Date: Mon, 7 Sep 2026 13:47:14 -0700 Subject: [PATCH 1/2] ci: unified workflow - single job, DOCKER_HOST, build+push on all events --- .gitea/workflows/ci.yaml | 39 +++++++++++++-------------------------- 1 file changed, 13 insertions(+), 26 deletions(-) diff --git a/.gitea/workflows/ci.yaml b/.gitea/workflows/ci.yaml index f8b8689..cba679f 100644 --- a/.gitea/workflows/ci.yaml +++ b/.gitea/workflows/ci.yaml @@ -5,32 +5,16 @@ on: branches: [main] pull_request: branches: [main] + workflow_dispatch: env: REGISTRY: forgejo.riotpiao.com IMAGE: forgejo.riotpiao.com/rock/api-gateway + DOCKER_HOST: tcp://localhost:2375 jobs: - test: - name: Test - runs-on: golang - steps: - - name: Install Node.js for actions runtime - run: apt-get update && apt-get install -y nodejs - - - name: Checkout code - uses: actions/checkout@v4 - - - name: Go vet - run: go vet ./... - - - name: Go test - run: go test ./... - - build-push: - name: Build & Push Image - needs: test - if: github.event_name == 'push' && github.ref == 'refs/heads/main' + ci: + name: CI runs-on: golang steps: - name: Install Node.js and Docker @@ -41,11 +25,15 @@ jobs: - name: Checkout code uses: actions/checkout@v4 + - name: Go vet + run: go vet ./... + + - name: Go test + run: go test ./... + - name: Get short SHA id: sha - run: | - SHORT_SHA=$(git rev-parse --short HEAD) - echo "short_sha=${SHORT_SHA}" >> $GITHUB_OUTPUT + run: echo "short_sha=$(git rev-parse --short HEAD)" >> $GITHUB_OUTPUT - name: Registry login run: | @@ -60,14 +48,13 @@ jobs: docker build --no-cache \ -t "${IMAGE}:${{ steps.sha.outputs.short_sha }}" \ -t "${IMAGE}:latest" \ - -f Dockerfile \ - . + -f Dockerfile . - name: Push Docker image run: | docker push "${IMAGE}:${{ steps.sha.outputs.short_sha }}" docker push "${IMAGE}:latest" - echo "✓ Image pushed: ${IMAGE}:${{ steps.sha.outputs.short_sha }}" + echo "✓ Pushed: ${IMAGE}:${{ steps.sha.outputs.short_sha }}" - name: Prune unused images run: docker image prune -a --force 2>&1 | tail -3 || true From c87463c850e20e465f06c4f3afa839d01f8165b9 Mon Sep 17 00:00:00 2001 From: Admin Bot Date: Tue, 8 Sep 2026 09:58:36 -0700 Subject: [PATCH 2/2] fix(s3): correct MinIO service port and allow egress MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit MinIO ClusterIP service listens on port 80 (targetPort 9000). Config had port 9000 which caused 30s timeout then 502 — gateway connected to service port 9000 which doesn't exist on the ClusterIP. Changes: - configmap.yaml: S3 upstream :9000 → :80 - gateway-config-secret.enc.yaml: same - network-policy.yaml: add port 80 egress to storage namespace Verified: S3 adapter now reaches MinIO (403 AccessDenied = auth issue, not connectivity). --- k8s/configmap.yaml | 2 +- k8s/gateway-config-secret.enc.yaml | 2 +- k8s/network-policy.yaml | 4 ++++ 3 files changed, 6 insertions(+), 2 deletions(-) diff --git a/k8s/configmap.yaml b/k8s/configmap.yaml index 0714348..14b9617 100644 --- a/k8s/configmap.yaml +++ b/k8s/configmap.yaml @@ -113,7 +113,7 @@ data: - serviceName: s3 upstream: - url: http://minio.storage.svc.cluster.local:9000 + url: http://minio.storage.svc.cluster.local:80 timeoutSeconds: 30 auth: required: false diff --git a/k8s/gateway-config-secret.enc.yaml b/k8s/gateway-config-secret.enc.yaml index 96f657f..fa55e3a 100644 --- a/k8s/gateway-config-secret.enc.yaml +++ b/k8s/gateway-config-secret.enc.yaml @@ -91,7 +91,7 @@ stringData: upstreamPath: /memory/skills - serviceName: s3 upstream: - url: http://minio.storage.svc.cluster.local:9000 + url: http://minio.storage.svc.cluster.local:80 timeoutSeconds: 30 auth: required: false diff --git a/k8s/network-policy.yaml b/k8s/network-policy.yaml index e0323aa..44364db 100644 --- a/k8s/network-policy.yaml +++ b/k8s/network-policy.yaml @@ -123,10 +123,14 @@ spec: - protocol: TCP port: 8080 # Allow to MinIO (S3-compatible storage) + # Service `minio` listens on port 80 (targetPort 9000). + # Headless `minio-cluster-hl` is 9000. Allow both. - to: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: storage ports: + - protocol: TCP + port: 80 - protocol: TCP port: 9000