Let Gitea call toolshed's webhook endpoint
Gitea refused every push notification with "webhook can only call allowed HTTP servers": toolshed builds an app's webhook target from the hostname the dashboard was browsed on, so an app registered through the public URL gets a public target, and this cluster's allowlist only permitted private ranges. Adding that one hostname rather than reverting to the homelab's "*". The difference matters: "*" would also permit the node metadata server, which is why it was narrowed in the first place. This permits exactly one host, our own load balancer. It is a stopgap and labelled as one in the file. The callback now hairpins out to the load balancer and back in, which is precisely what the cluster-DNS rule exists to avoid. The real fix is a configurable webhook base URL in toolshed pointing at toolshed-api.toolshed.svc.cluster.local:8080; this entry should be removed when that lands. Verified in the render: the value reaches Gitea's inline config, and Recreate, standard-rwo, sqlite and disabled registration are untouched. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LEsTefWWifp4ikvhHF5s6N
This commit is contained in:
co-authored by
Claude Opus 5
parent
41dd021d06
commit
73ddfd8534
@@ -50,10 +50,26 @@ gitea:
|
|||||||
DISABLE_REGISTRATION: true
|
DISABLE_REGISTRATION: true
|
||||||
security:
|
security:
|
||||||
# The homelab allowed "*" because every host was on a private LAN.
|
# The homelab allowed "*" because every host was on a private LAN.
|
||||||
# Here "*" would also allow webhooks to the node metadata server,
|
# Here "*" would also allow webhooks to the node metadata server, so
|
||||||
# so this is narrowed to private ranges — which still covers every
|
# this stays narrowed to private ranges — which covers every
|
||||||
# in-cluster Service (Jenkins included) reached over cluster DNS.
|
# in-cluster Service (Jenkins included) reached over cluster DNS.
|
||||||
ALLOWED_HOST_LIST: private
|
#
|
||||||
|
# The one public entry is toolshed's own dashboard host, and it is a
|
||||||
|
# STOPGAP. toolshed builds each app's webhook target from the
|
||||||
|
# hostname the dashboard was browsed on (internal/api/apps.go's
|
||||||
|
# queueRepo), with no override, so an app registered through the
|
||||||
|
# public URL gets a public webhook target and Gitea refuses to call
|
||||||
|
# it: "webhook can only call allowed HTTP servers".
|
||||||
|
#
|
||||||
|
# The cost is real but bounded: this permits exactly one hostname,
|
||||||
|
# which happens to be our own load balancer, so the callback
|
||||||
|
# hairpins out and back in rather than staying pod-to-pod. It does
|
||||||
|
# not re-expose the metadata server, which is why "*" was rejected.
|
||||||
|
#
|
||||||
|
# The proper fix is a configurable webhook base URL in toolshed
|
||||||
|
# pointing at toolshed-api.toolshed.svc.cluster.local:8080, after
|
||||||
|
# which this entry should be removed.
|
||||||
|
ALLOWED_HOST_LIST: private,toolshed.35.238.248.203.nip.io
|
||||||
admin:
|
admin:
|
||||||
username: gitadmin
|
username: gitadmin
|
||||||
# Created by hand with kubectl at bootstrap, because Vault and ESO
|
# Created by hand with kubectl at bootstrap, because Vault and ESO
|
||||||
|
|||||||
Reference in New Issue
Block a user