rock
1a8e87131b
ci: fix runner labels + CoreDNS rewrite + cleanup
...
- Runners use public images (code.forgejo.org/forgejo/runner:6)
- Labels pull from Docker Hub: golang:1.26, node:22, rust:1-bookworm
- Add CoreDNS api.riotpiao.com rewrite
- Fix runner re-registration to keep labels in sync
- Add unified CI pattern docs to CLAUDE.example.md
- Remove dead .forgejo/ workflow dir (Forgejo uses .gitea/)
2026-09-07 13:01:56 -07:00
Story Crater Bot
d6fcf1016e
refactor(forgejo-runner): template PVC names off Release.Name for multi-instance reuse
2026-08-21 16:30:41 -07:00
Story Crater Bot
c46e69fd43
fix(forgejo-runner): allow job containers to mount /docker-certs/client so docker login/build/push work
2026-08-21 16:22:19 -07:00
Story Crater Bot
720181c900
feat: let the runner build and the cluster pull from the Forgejo registry
...
- Runner egress: allow 192.168.1.160/32:443. forgejo.riotpiao.com resolves to
the ingress LB, inside the 192.168.1.0/24 block the NetworkPolicy denies, so
docker push hung until timeout.
- dind CA: also mount homelab-ca at /etc/docker/certs.d/forgejo.riotpiao.com/,
the path dockerd actually reads for per-registry trust.
- Pull secret: dockerconfigjson for the api namespace; /v2/ answers 401.
- AppProject: allow the Forgejo repo as a source for api-gw.
2026-08-19 21:48:01 -07:00
Story Crater Bot
b863b6974e
fix(forgejo-runner): cicd ns PSS privileged (dind needs it) + mount homelab-ca as ConfigMap not Secret — runner RS created 0 pods under baseline PSS, then FailedMount because homelab-ca is a ConfigMap trust bundle, not a Secret
2026-08-18 15:08:04 -07:00
Story Crater Bot
41f5b05395
refactor(k8s): consolidate to infra/+apps/ single-source tree, dedicated per-app CNPG (authentik-db/temporal-db), wire monitoring-config, forgejo→cicd ns, drop orphan/stale (data-schemas, ollama, story-crater, sqs/argocd, key-rotation)
2026-08-18 15:08:03 -07:00