diff --git a/helm-overrides/gke-toolshed-prd-usc1/gitea/custom-values.yaml b/helm-overrides/gke-toolshed-prd-usc1/gitea/custom-values.yaml index 500e280..9136a31 100644 --- a/helm-overrides/gke-toolshed-prd-usc1/gitea/custom-values.yaml +++ b/helm-overrides/gke-toolshed-prd-usc1/gitea/custom-values.yaml @@ -50,10 +50,26 @@ gitea: DISABLE_REGISTRATION: true security: # The homelab allowed "*" because every host was on a private LAN. - # Here "*" would also allow webhooks to the node metadata server, - # so this is narrowed to private ranges — which still covers every + # Here "*" would also allow webhooks to the node metadata server, so + # this stays narrowed to private ranges — which covers every # in-cluster Service (Jenkins included) reached over cluster DNS. - ALLOWED_HOST_LIST: private + # + # The one public entry is toolshed's own dashboard host, and it is a + # STOPGAP. toolshed builds each app's webhook target from the + # hostname the dashboard was browsed on (internal/api/apps.go's + # queueRepo), with no override, so an app registered through the + # public URL gets a public webhook target and Gitea refuses to call + # it: "webhook can only call allowed HTTP servers". + # + # The cost is real but bounded: this permits exactly one hostname, + # which happens to be our own load balancer, so the callback + # hairpins out and back in rather than staying pod-to-pod. It does + # not re-expose the metadata server, which is why "*" was rejected. + # + # The proper fix is a configurable webhook base URL in toolshed + # pointing at toolshed-api.toolshed.svc.cluster.local:8080, after + # which this entry should be removed. + ALLOWED_HOST_LIST: private,toolshed.35.238.248.203.nip.io admin: username: gitadmin # Created by hand with kubectl at bootstrap, because Vault and ESO