Author SHA1 Message Date
rock 5dd76f3b49 Merge pull request 'fix(s3): correct MinIO service port and allow egress' (#14) from fix/s3-adapter-port into main
CI / CI (push) Successful in 3m16s
2026-09-08 17:03:52 +00:00
Admin Bot c87463c850 fix(s3): correct MinIO service port and allow egress
CI / CI (pull_request) Successful in 3m16s
MinIO ClusterIP service listens on port 80 (targetPort 9000).
Config had port 9000 which caused 30s timeout then 502 — gateway
connected to service port 9000 which doesn't exist on the ClusterIP.

Changes:
- configmap.yaml: S3 upstream :9000 → :80
- gateway-config-secret.enc.yaml: same
- network-policy.yaml: add port 80 egress to storage namespace

Verified: S3 adapter now reaches MinIO (403 AccessDenied = auth issue,
not connectivity).
2026-09-08 09:58:36 -07:00
rockandAdmin Bot 1cd8e711dd ci: unified workflow - single job, DOCKER_HOST, build+push on all events (#4)
CI / CI (push) Successful in 3m23s
- Single job (no split test/build-push)
- DOCKER_HOST=tcp://localhost:2375 for dind
- Build + push on PRs too (verify before merge)
- workflow_dispatch for manual trigger

---------

Co-authored-by: Admin Bot <[email protected]>
Reviewed-on: rock/homelab-frontend#4
2026-09-07 21:01:02 +00:00
Admin Bot 7e78519499 ci: unified workflow - single job, DOCKER_HOST, build+push on all events
CI / CI (pull_request) Successful in 4m0s
2026-09-07 13:47:14 -07:00
4 changed files with 19 additions and 28 deletions
+13 -26
View File
@@ -5,32 +5,16 @@ on:
branches: [main] branches: [main]
pull_request: pull_request:
branches: [main] branches: [main]
workflow_dispatch:
env: env:
REGISTRY: forgejo.riotpiao.com REGISTRY: forgejo.riotpiao.com
IMAGE: forgejo.riotpiao.com/rock/api-gateway IMAGE: forgejo.riotpiao.com/rock/api-gateway
DOCKER_HOST: tcp://localhost:2375
jobs: jobs:
test: ci:
name: Test name: CI
runs-on: golang
steps:
- name: Install Node.js for actions runtime
run: apt-get update && apt-get install -y nodejs
- name: Checkout code
uses: actions/checkout@v4
- name: Go vet
run: go vet ./...
- name: Go test
run: go test ./...
build-push:
name: Build & Push Image
needs: test
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
runs-on: golang runs-on: golang
steps: steps:
- name: Install Node.js and Docker - name: Install Node.js and Docker
@@ -41,11 +25,15 @@ jobs:
- name: Checkout code - name: Checkout code
uses: actions/checkout@v4 uses: actions/checkout@v4
- name: Go vet
run: go vet ./...
- name: Go test
run: go test ./...
- name: Get short SHA - name: Get short SHA
id: sha id: sha
run: | run: echo "short_sha=$(git rev-parse --short HEAD)" >> $GITHUB_OUTPUT
SHORT_SHA=$(git rev-parse --short HEAD)
echo "short_sha=${SHORT_SHA}" >> $GITHUB_OUTPUT
- name: Registry login - name: Registry login
run: | run: |
@@ -60,14 +48,13 @@ jobs:
docker build --no-cache \ docker build --no-cache \
-t "${IMAGE}:${{ steps.sha.outputs.short_sha }}" \ -t "${IMAGE}:${{ steps.sha.outputs.short_sha }}" \
-t "${IMAGE}:latest" \ -t "${IMAGE}:latest" \
-f Dockerfile \ -f Dockerfile .
.
- name: Push Docker image - name: Push Docker image
run: | run: |
docker push "${IMAGE}:${{ steps.sha.outputs.short_sha }}" docker push "${IMAGE}:${{ steps.sha.outputs.short_sha }}"
docker push "${IMAGE}:latest" docker push "${IMAGE}:latest"
echo "✓ Image pushed: ${IMAGE}:${{ steps.sha.outputs.short_sha }}" echo "✓ Pushed: ${IMAGE}:${{ steps.sha.outputs.short_sha }}"
- name: Prune unused images - name: Prune unused images
run: docker image prune -a --force 2>&1 | tail -3 || true run: docker image prune -a --force 2>&1 | tail -3 || true
+1 -1
View File
@@ -113,7 +113,7 @@ data:
- serviceName: s3 - serviceName: s3
upstream: upstream:
url: http://minio.storage.svc.cluster.local:9000 url: http://minio.storage.svc.cluster.local:80
timeoutSeconds: 30 timeoutSeconds: 30
auth: auth:
required: false required: false
+1 -1
View File
@@ -91,7 +91,7 @@ stringData:
upstreamPath: /memory/skills upstreamPath: /memory/skills
- serviceName: s3 - serviceName: s3
upstream: upstream:
url: http://minio.storage.svc.cluster.local:9000 url: http://minio.storage.svc.cluster.local:80
timeoutSeconds: 30 timeoutSeconds: 30
auth: auth:
required: false required: false
+4
View File
@@ -123,10 +123,14 @@ spec:
- protocol: TCP - protocol: TCP
port: 8080 port: 8080
# Allow to MinIO (S3-compatible storage) # Allow to MinIO (S3-compatible storage)
# Service `minio` listens on port 80 (targetPort 9000).
# Headless `minio-cluster-hl` is 9000. Allow both.
- to: - to:
- namespaceSelector: - namespaceSelector:
matchLabels: matchLabels:
kubernetes.io/metadata.name: storage kubernetes.io/metadata.name: storage
ports: ports:
- protocol: TCP
port: 80
- protocol: TCP - protocol: TCP
port: 9000 port: 9000