diff --git a/secretstores/demo-go-app-image-pull-secret.yaml b/secretstores/demo-go-app-image-pull-secret.yaml new file mode 100644 index 0000000..867e58b --- /dev/null +++ b/secretstores/demo-go-app-image-pull-secret.yaml @@ -0,0 +1,35 @@ +# imagePullSecret for demo-go-app's own Deployment — separate from +# harbor-robot-dockerconfig (which lives in the jenkins namespace, for +# the build pod's docker push). This one lands in the demo-go-app +# namespace itself, since imagePullSecrets must be in the same namespace +# as the pod referencing them. Same underlying robot account/Vault path +# (harbor/jenkins-robot already has push+pull scope), just synced to a +# second namespace and keyed to the same Contour ingress hostname used +# for the image reference in values/demo-go-app/demo-go-app/values.yaml. +apiVersion: external-secrets.io/v1 +kind: ExternalSecret +metadata: + name: demo-go-app-image-pull-secret + namespace: demo-go-app +spec: + refreshInterval: 1h + secretStoreRef: + name: vault-backend + kind: ClusterSecretStore + target: + name: demo-go-app-image-pull-secret + creationPolicy: Owner + template: + type: kubernetes.io/dockerconfigjson + data: + .dockerconfigjson: | + {"auths":{"harbor.192.168.1.7.nip.io":{"username":"{{ .username }}","password":"{{ .password }}","auth":"{{ printf "%s:%s" .username .password | b64enc }}"}}} + data: + - secretKey: username + remoteRef: + key: harbor/jenkins-robot + property: username + - secretKey: password + remoteRef: + key: harbor/jenkins-robot + property: password diff --git a/secretstores/harbor-robot-dockerconfig.yaml b/secretstores/harbor-robot-dockerconfig.yaml index 8929209..b91ec98 100644 --- a/secretstores/harbor-robot-dockerconfig.yaml +++ b/secretstores/harbor-robot-dockerconfig.yaml @@ -27,8 +27,14 @@ spec: template: type: kubernetes.io/dockerconfigjson data: + # Keyed by exact registry hostname — docker matches credentials + # against the host portion of the image reference. Was + # harbor-core.harbor.svc.cluster.local; switched to the Contour + # ingress hostname alongside buildDocker.groovy and dind-pod.yaml + # so push/pull share one consistent, resolvable-from-anywhere + # reference. .dockerconfigjson: | - {"auths":{"harbor-core.harbor.svc.cluster.local":{"username":"{{ .username }}","password":"{{ .password }}","auth":"{{ printf "%s:%s" .username .password | b64enc }}"}}} + {"auths":{"harbor.192.168.1.7.nip.io":{"username":"{{ .username }}","password":"{{ .password }}","auth":"{{ printf "%s:%s" .username .password | b64enc }}"}}} data: - secretKey: username remoteRef: