Let Gitea call toolshed's webhook endpoint

Gitea refused every push notification with "webhook can only call allowed
HTTP servers": toolshed builds an app's webhook target from the hostname
the dashboard was browsed on, so an app registered through the public URL
gets a public target, and this cluster's allowlist only permitted private
ranges.

Adding that one hostname rather than reverting to the homelab's "*". The
difference matters: "*" would also permit the node metadata server, which
is why it was narrowed in the first place. This permits exactly one host,
our own load balancer.

It is a stopgap and labelled as one in the file. The callback now hairpins
out to the load balancer and back in, which is precisely what the
cluster-DNS rule exists to avoid. The real fix is a configurable webhook
base URL in toolshed pointing at
toolshed-api.toolshed.svc.cluster.local:8080; this entry should be removed
when that lands.

Verified in the render: the value reaches Gitea's inline config, and
Recreate, standard-rwo, sqlite and disabled registration are untouched.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LEsTefWWifp4ikvhHF5s6N
This commit is contained in:
Mukul Sharma
2026-09-13 09:25:39 +05:30
co-authored by Claude Opus 5
parent 41dd021d06
commit 73ddfd8534
@@ -50,10 +50,26 @@ gitea:
DISABLE_REGISTRATION: true DISABLE_REGISTRATION: true
security: security:
# The homelab allowed "*" because every host was on a private LAN. # The homelab allowed "*" because every host was on a private LAN.
# Here "*" would also allow webhooks to the node metadata server, # Here "*" would also allow webhooks to the node metadata server, so
# so this is narrowed to private ranges — which still covers every # this stays narrowed to private ranges — which covers every
# in-cluster Service (Jenkins included) reached over cluster DNS. # in-cluster Service (Jenkins included) reached over cluster DNS.
ALLOWED_HOST_LIST: private #
# The one public entry is toolshed's own dashboard host, and it is a
# STOPGAP. toolshed builds each app's webhook target from the
# hostname the dashboard was browsed on (internal/api/apps.go's
# queueRepo), with no override, so an app registered through the
# public URL gets a public webhook target and Gitea refuses to call
# it: "webhook can only call allowed HTTP servers".
#
# The cost is real but bounded: this permits exactly one hostname,
# which happens to be our own load balancer, so the callback
# hairpins out and back in rather than staying pod-to-pod. It does
# not re-expose the metadata server, which is why "*" was rejected.
#
# The proper fix is a configurable webhook base URL in toolshed
# pointing at toolshed-api.toolshed.svc.cluster.local:8080, after
# which this entry should be removed.
ALLOWED_HOST_LIST: private,toolshed.35.238.248.203.nip.io
admin: admin:
username: gitadmin username: gitadmin
# Created by hand with kubectl at bootstrap, because Vault and ESO # Created by hand with kubectl at bootstrap, because Vault and ESO