feat: let the runner build and the cluster pull from the Forgejo registry
- Runner egress: allow 192.168.1.160/32:443. forgejo.riotpiao.com resolves to the ingress LB, inside the 192.168.1.0/24 block the NetworkPolicy denies, so docker push hung until timeout. - dind CA: also mount homelab-ca at /etc/docker/certs.d/forgejo.riotpiao.com/, the path dockerd actually reads for per-registry trust. - Pull secret: dockerconfigjson for the api namespace; /v2/ answers 401. - AppProject: allow the Forgejo repo as a source for api-gw.
This commit is contained in:
@@ -29,3 +29,13 @@ spec:
|
||||
except:
|
||||
- 192.168.1.0/24
|
||||
- 10.244.0.0/16
|
||||
# Single LAN exception: the ingress-nginx LoadBalancer, which is how
|
||||
# forgejo.riotpiao.com resolves. Image pushes go to that name so the tag
|
||||
# matches what containerd pulls on the nodes; without this the whole /24 is
|
||||
# denied above and `docker push` hangs until it times out.
|
||||
- to:
|
||||
- ipBlock:
|
||||
cidr: {{ .Values.egress.ingressLoadBalancerIP }}/32
|
||||
ports:
|
||||
- protocol: TCP
|
||||
port: 443
|
||||
|
||||
Reference in New Issue
Block a user