2.3 KiB
2.3 KiB
CI/CD Setup — Using Homelab SOPS-Managed REGISTRY_PAT
🔐 Secret Management
The REGISTRY_PAT token is now encrypted and managed via SOPS/ksops in the homelab repository.
Location: ~/workplace/homelab/k8s/argocd/secrets/forgejo-registry-pat.enc.yaml
Status: ✅ Deployed to K8s cluster (forgejo namespace)
Setup (5 minutes)
Step 1: Add Secret to Repository Actions (Web UI)
Go to: https://git.riotpiao.com/rock/poimen-memory/settings/secrets
Add secret:
- Name:
REGISTRY_PAT - Value:
bdf6a1d2317c28a332447083c61bb463d24defb7
(This value is also encrypted in homelab — see forgejo-registry-pat.enc.yaml)
Step 2: Trigger Build
cd ~/workplace/Poimen/memory
git commit --allow-empty -m "Trigger CI with REGISTRY_PAT"
git push origin main
Step 3: Monitor
# Watch workflow
https://git.riotpiao.com/rock/poimen-memory/actions
# Watch deployment
kubectl get pods -n poimen -l app.kubernetes.io/name=poimen-memory -w
How It Works
Git Push
↓
Forgejo Actions CI
↓
Uses REGISTRY_PAT secret
↓
docker login → build → push to forgejo.riotpiao.com
↓
ArgoCD watches and deploys
For All Poimen Repos
Same process:
- Add
REGISTRY_PATsecret to each repo's Actions settings - Copy
.forgejo/workflows/build.yamlfrom poimen-memory - Push and CI runs automatically
The PAT is centrally managed in homelab (encrypted with SOPS), so if it needs rotation:
- Update only once in homelab
- Re-encrypt with SOPS
- All repos using the same token automatically work
Homelab Integration
Encrypted in: ~/workplace/homelab/k8s/argocd/secrets/forgejo-registry-pat.enc.yaml
Managed by: ksops in k8s/argocd/secrets/secret-generator.yaml
Deployed as: K8s Secret forgejo-registry-pat in forgejo namespace
Accessible in cluster:
kubectl get secret -n forgejo forgejo-registry-pat
kubectl get secret -n forgejo forgejo-registry-pat -o jsonpath='{.data.REGISTRY_PAT}' | base64 -d
Security
- ✅ Token encrypted with SOPS (age encryption)
- ✅ Never committed in plaintext
- ✅ Centrally managed (single source of truth)
- ✅ Can be rotated in one place (homelab)
- ✅ Audit trail in git commits
- ✅ Requires age private key to decrypt (access controlled)