feat: let the runner build and the cluster pull from the Forgejo registry
- Runner egress: allow 192.168.1.160/32:443. forgejo.riotpiao.com resolves to the ingress LB, inside the 192.168.1.0/24 block the NetworkPolicy denies, so docker push hung until timeout. - dind CA: also mount homelab-ca at /etc/docker/certs.d/forgejo.riotpiao.com/, the path dockerd actually reads for per-registry trust. - Pull secret: dockerconfigjson for the api namespace; /v2/ answers 401. - AppProject: allow the Forgejo repo as a source for api-gw.
This commit is contained in:
@@ -91,6 +91,13 @@ spec:
|
||||
- name: homelab-ca
|
||||
mountPath: /etc/ssl/certs/homelab-ca.pem
|
||||
subPath: ca.crt
|
||||
# dockerd resolves per-registry CAs from /etc/docker/certs.d/<host>/
|
||||
# before falling back to the system pool. Mounting it here is what
|
||||
# makes `docker push forgejo.riotpiao.com/...` trust the homelab CA
|
||||
# rather than failing x509: signed by unknown authority.
|
||||
- name: homelab-ca
|
||||
mountPath: /etc/docker/certs.d/forgejo.riotpiao.com/ca.crt
|
||||
subPath: ca.crt
|
||||
resources:
|
||||
{{- toYaml .Values.dind.resources | nindent 12 }}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user