feat: let the runner build and the cluster pull from the Forgejo registry
- Runner egress: allow 192.168.1.160/32:443. forgejo.riotpiao.com resolves to the ingress LB, inside the 192.168.1.0/24 block the NetworkPolicy denies, so docker push hung until timeout. - dind CA: also mount homelab-ca at /etc/docker/certs.d/forgejo.riotpiao.com/, the path dockerd actually reads for per-registry trust. - Pull secret: dockerconfigjson for the api namespace; /v2/ answers 401. - AppProject: allow the Forgejo repo as a source for api-gw.
This commit is contained in:
@@ -47,3 +47,10 @@ tolerations:
|
||||
# attach there.
|
||||
nodeSelector:
|
||||
topology.kubernetes.io/zone: az-a
|
||||
|
||||
# Egress exceptions. The NetworkPolicy denies the whole LAN /24 by default;
|
||||
# this is the one address punched back through, because forgejo.riotpiao.com
|
||||
# (the image registry) resolves to the ingress-nginx LoadBalancer.
|
||||
# Must match the Cilium LB pool allocation — pool is 192.168.1.160/28.
|
||||
egress:
|
||||
ingressLoadBalancerIP: 192.168.1.160
|
||||
|
||||
Reference in New Issue
Block a user