fix: allow CI runner egress to K8s API server #48

Merged
rock merged 1 commits from feat/ci-k8s-api-egress into main 2026-09-13 13:54:32 +00:00
Member

CI runner needs kubectl access to create Tekton PipelineRuns for integration testing.

Root Cause

The runner egress NetworkPolicy blocks 192.168.1.0/24 (LAN). The K8s API server runs on control-plane nodes in that subnet (192.168.1.166:6443). kubectl from inside the DinD container times out.

Fix

Allow TCP port 6443 to 192.168.1.0/24 — scoped to control-plane API server only.

Required By

homelab-frontend PR #25 (Tekton integration testing) — CI creates PipelineRuns via kubectl.

CI runner needs kubectl access to create Tekton PipelineRuns for integration testing. ## Root Cause The runner egress NetworkPolicy blocks `192.168.1.0/24` (LAN). The K8s API server runs on control-plane nodes in that subnet (`192.168.1.166:6443`). kubectl from inside the DinD container times out. ## Fix Allow TCP port 6443 to `192.168.1.0/24` — scoped to control-plane API server only. ## Required By homelab-frontend PR #25 (Tekton integration testing) — CI creates PipelineRuns via kubectl.
poimen added 1 commit 2026-09-13 13:51:55 +00:00
CI needs kubectl access to create Tekton PipelineRuns for integration
testing. The API server runs on control-plane nodes in 192.168.1.0/24
which was blocked by the existing except rule.

Allow port 6443 to 192.168.1.0/24 (control-plane subnet only).
rock merged commit 4b5ecfcd49 into main 2026-09-13 13:54:32 +00:00
rock deleted branch feat/ci-k8s-api-egress 2026-09-13 13:54:37 +00:00
Sign in to join this conversation.