From 73ddfd853429d333f81a2ef8461926da36238768 Mon Sep 17 00:00:00 2001 From: Mukul Sharma Date: Sun, 13 Sep 2026 09:25:39 +0530 Subject: [PATCH] Let Gitea call toolshed's webhook endpoint Gitea refused every push notification with "webhook can only call allowed HTTP servers": toolshed builds an app's webhook target from the hostname the dashboard was browsed on, so an app registered through the public URL gets a public target, and this cluster's allowlist only permitted private ranges. Adding that one hostname rather than reverting to the homelab's "*". The difference matters: "*" would also permit the node metadata server, which is why it was narrowed in the first place. This permits exactly one host, our own load balancer. It is a stopgap and labelled as one in the file. The callback now hairpins out to the load balancer and back in, which is precisely what the cluster-DNS rule exists to avoid. The real fix is a configurable webhook base URL in toolshed pointing at toolshed-api.toolshed.svc.cluster.local:8080; this entry should be removed when that lands. Verified in the render: the value reaches Gitea's inline config, and Recreate, standard-rwo, sqlite and disabled registration are untouched. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01LEsTefWWifp4ikvhHF5s6N --- .../gitea/custom-values.yaml | 22 ++++++++++++++++--- 1 file changed, 19 insertions(+), 3 deletions(-) diff --git a/helm-overrides/gke-toolshed-prd-usc1/gitea/custom-values.yaml b/helm-overrides/gke-toolshed-prd-usc1/gitea/custom-values.yaml index 500e280..9136a31 100644 --- a/helm-overrides/gke-toolshed-prd-usc1/gitea/custom-values.yaml +++ b/helm-overrides/gke-toolshed-prd-usc1/gitea/custom-values.yaml @@ -50,10 +50,26 @@ gitea: DISABLE_REGISTRATION: true security: # The homelab allowed "*" because every host was on a private LAN. - # Here "*" would also allow webhooks to the node metadata server, - # so this is narrowed to private ranges — which still covers every + # Here "*" would also allow webhooks to the node metadata server, so + # this stays narrowed to private ranges — which covers every # in-cluster Service (Jenkins included) reached over cluster DNS. - ALLOWED_HOST_LIST: private + # + # The one public entry is toolshed's own dashboard host, and it is a + # STOPGAP. toolshed builds each app's webhook target from the + # hostname the dashboard was browsed on (internal/api/apps.go's + # queueRepo), with no override, so an app registered through the + # public URL gets a public webhook target and Gitea refuses to call + # it: "webhook can only call allowed HTTP servers". + # + # The cost is real but bounded: this permits exactly one hostname, + # which happens to be our own load balancer, so the callback + # hairpins out and back in rather than staying pod-to-pod. It does + # not re-expose the metadata server, which is why "*" was rejected. + # + # The proper fix is a configurable webhook base URL in toolshed + # pointing at toolshed-api.toolshed.svc.cluster.local:8080, after + # which this entry should be removed. + ALLOWED_HOST_LIST: private,toolshed.35.238.248.203.nip.io admin: username: gitadmin # Created by hand with kubectl at bootstrap, because Vault and ESO