fix(forgejo-runner): cicd ns PSS privileged (dind needs it) + mount homelab-ca as ConfigMap not Secret — runner RS created 0 pods under baseline PSS, then FailedMount because homelab-ca is a ConfigMap trust bundle, not a Secret

This commit is contained in:
Story Crater Bot
2026-08-18 15:08:04 -07:00
parent 6401652aa8
commit b863b6974e
2 changed files with 11 additions and 7 deletions
+7 -5
View File
@@ -3,8 +3,10 @@ kind: Namespace
metadata:
name: cicd
labels:
# Baseline allows most workloads while blocking clearly dangerous configurations
# Redis needs some relaxed settings but doesn't need full privileged access
pod-security.kubernetes.io/enforce: baseline
pod-security.kubernetes.io/audit: baseline
pod-security.kubernetes.io/warn: baseline
# privileged: the forgejo-runner's dind (docker-in-docker) sidecar requires
# securityContext.privileged=true, which baseline/restricted PSS reject
# (the ReplicaSet silently creates 0 pods). gitea, redis and CNPG here are
# already privileged-tolerant.
pod-security.kubernetes.io/enforce: privileged
pod-security.kubernetes.io/audit: privileged
pod-security.kubernetes.io/warn: privileged