Add demo-go-app-image-pull-secret; rekey harbor-robot-dockerconfig
Both needed for the registry hostname switch to harbor.192.168.1.7.nip.io (devops-lib#3ffa2d8): - harbor-robot-dockerconfig's auths key was hardcoded to harbor-core.harbor.svc.cluster.local — docker matches stored credentials by exact registry hostname, so this had to move with the image reference or push would go back to unauthorized. - New demo-go-app-image-pull-secret, in the demo-go-app namespace (imagePullSecrets must be same-namespace as the pod), for the Deployment's own pull — separate from harbor-robot-dockerconfig, which only ever lived in the jenkins namespace for the build pod's push. Same underlying robot account/Vault path.
This commit is contained in:
@@ -0,0 +1,35 @@
|
|||||||
|
# imagePullSecret for demo-go-app's own Deployment — separate from
|
||||||
|
# harbor-robot-dockerconfig (which lives in the jenkins namespace, for
|
||||||
|
# the build pod's docker push). This one lands in the demo-go-app
|
||||||
|
# namespace itself, since imagePullSecrets must be in the same namespace
|
||||||
|
# as the pod referencing them. Same underlying robot account/Vault path
|
||||||
|
# (harbor/jenkins-robot already has push+pull scope), just synced to a
|
||||||
|
# second namespace and keyed to the same Contour ingress hostname used
|
||||||
|
# for the image reference in values/demo-go-app/demo-go-app/values.yaml.
|
||||||
|
apiVersion: external-secrets.io/v1
|
||||||
|
kind: ExternalSecret
|
||||||
|
metadata:
|
||||||
|
name: demo-go-app-image-pull-secret
|
||||||
|
namespace: demo-go-app
|
||||||
|
spec:
|
||||||
|
refreshInterval: 1h
|
||||||
|
secretStoreRef:
|
||||||
|
name: vault-backend
|
||||||
|
kind: ClusterSecretStore
|
||||||
|
target:
|
||||||
|
name: demo-go-app-image-pull-secret
|
||||||
|
creationPolicy: Owner
|
||||||
|
template:
|
||||||
|
type: kubernetes.io/dockerconfigjson
|
||||||
|
data:
|
||||||
|
.dockerconfigjson: |
|
||||||
|
{"auths":{"harbor.192.168.1.7.nip.io":{"username":"{{ .username }}","password":"{{ .password }}","auth":"{{ printf "%s:%s" .username .password | b64enc }}"}}}
|
||||||
|
data:
|
||||||
|
- secretKey: username
|
||||||
|
remoteRef:
|
||||||
|
key: harbor/jenkins-robot
|
||||||
|
property: username
|
||||||
|
- secretKey: password
|
||||||
|
remoteRef:
|
||||||
|
key: harbor/jenkins-robot
|
||||||
|
property: password
|
||||||
@@ -27,8 +27,14 @@ spec:
|
|||||||
template:
|
template:
|
||||||
type: kubernetes.io/dockerconfigjson
|
type: kubernetes.io/dockerconfigjson
|
||||||
data:
|
data:
|
||||||
|
# Keyed by exact registry hostname — docker matches credentials
|
||||||
|
# against the host portion of the image reference. Was
|
||||||
|
# harbor-core.harbor.svc.cluster.local; switched to the Contour
|
||||||
|
# ingress hostname alongside buildDocker.groovy and dind-pod.yaml
|
||||||
|
# so push/pull share one consistent, resolvable-from-anywhere
|
||||||
|
# reference.
|
||||||
.dockerconfigjson: |
|
.dockerconfigjson: |
|
||||||
{"auths":{"harbor-core.harbor.svc.cluster.local":{"username":"{{ .username }}","password":"{{ .password }}","auth":"{{ printf "%s:%s" .username .password | b64enc }}"}}}
|
{"auths":{"harbor.192.168.1.7.nip.io":{"username":"{{ .username }}","password":"{{ .password }}","auth":"{{ printf "%s:%s" .username .password | b64enc }}"}}}
|
||||||
data:
|
data:
|
||||||
- secretKey: username
|
- secretKey: username
|
||||||
remoteRef:
|
remoteRef:
|
||||||
|
|||||||
Reference in New Issue
Block a user