CI needs kubectl access to create Tekton PipelineRuns for integration
testing. The API server runs on control-plane nodes in 192.168.1.0/24
which was blocked by the existing except rule.
Allow port 6443 to 192.168.1.0/24 (control-plane subnet only).
- Runner egress: allow 192.168.1.160/32:443. forgejo.riotpiao.com resolves to
the ingress LB, inside the 192.168.1.0/24 block the NetworkPolicy denies, so
docker push hung until timeout.
- dind CA: also mount homelab-ca at /etc/docker/certs.d/forgejo.riotpiao.com/,
the path dockerd actually reads for per-registry trust.
- Pull secret: dockerconfigjson for the api namespace; /v2/ answers 401.
- AppProject: allow the Forgejo repo as a source for api-gw.