CI runner (Forgejo DinD) runs jobs as Docker containers — no in-cluster SA token available. Industry standard: dedicated SA with minimal RBAC, long-lived token as KUBECONFIG_B64 secret in Forgejo. SA: ci-tekton-trigger (namespace: api) Permissions: create/get/watch/delete PipelineRuns, get TaskRuns, get pod logs Token: kubernetes.io/service-account-token secret
Tekton Integration Tests
Curl-based integration tests for the API gateway, orchestrated by Tekton.
How It Works
CI pushes image:sha → creates PipelineRun → Tekton spins up gateway sidecar
→ runs curl tests → reports pass/fail → CI promotes to :latest if pass
The Task runs the gateway image as a sidecar (same pod, localhost),
then executes scripts/integration-test.sh which tests every adapter
via X-Service + X-Resource header routing.
Files
| File | Purpose |
|---|---|
task-integration-test.yaml |
Task: sidecar gateway + curl test step |
pipeline-integration-test.yaml |
Pipeline: wraps the Task |
scripts/integration-test.sh |
Test script (mounted as ConfigMap) |
kustomization.yaml |
Generates ConfigMap from script |
Manual Run
kubectl apply -k k8s/tekton/
kubectl create -f - <<'EOF'
apiVersion: tekton.dev/v1
kind: PipelineRun
metadata:
name: integration-test-manual
namespace: api
spec:
pipelineRef:
name: integration-test-pipeline
params:
- name: image
value: forgejo.riotpiao.com/rock/api-gateway:latest
EOF
# Watch
kubectl logs -f -n api pipelinerun/integration-test-manual -c step-run-tests
Updating Tests
Edit scripts/integration-test.sh, then:
kubectl apply -k k8s/tekton/ # recreates ConfigMap
Tekton Infrastructure
Tekton Pipelines is installed in ~/workplace/homelab via ArgoCD
(k8s/argocd/apps/06-ci-cd.yaml → vendored k8s/infra/tekton/release.yaml).