gitea: # GKE counterpart of helm-overrides/k8s-admin-prd-ase1/gitea — same # SQLite/no-cache shape, with what differs on GKE called out inline. # # Installed once by hand with `helm install gitea` (release "gitea", # namespace "gitea"), then adopted by ArgoCD via the nameOverride in # devops-infra-argo-config-gcp's values file. Gitea has to exist before # ArgoCD can read anything, since both config repos live inside it. # Recreate for a different reason than the homelab's LevelDB lock: on # three nodes with a ReadWriteOnce persistent disk, the chart's default # RollingUpdate (maxUnavailable: 0) starts the new pod first, and if it # lands on another node it waits forever on Multi-Attach. strategy: type: Recreate persistence: size: 10Gi # GKE's default class (pd-balanced), in place of the homelab's # local-path. Counts against the project's 250GB SSD quota. storageClass: standard-rwo postgresql: enabled: false postgresql-ha: enabled: false valkey: enabled: false valkey-cluster: enabled: false resources: requests: cpu: 100m memory: 300Mi limits: memory: 500Mi gitea: config: database: DB_TYPE: sqlite3 actions: ENABLED: true server: ROOT_URL: https://gitea.infra.deployshed.com/ service: # The homelab sat on a LAN; this Gitea is on a public IP. Open # registration would let anyone on the internet create an account. DISABLE_REGISTRATION: true security: # The homelab allowed "*" because every host was on a private LAN. # Here "*" would also allow webhooks to the node metadata server, so # this stays narrowed to private ranges — which covers every # in-cluster Service (Jenkins included) reached over cluster DNS. # # The one public entry is toolshed's own dashboard host, and it is a # STOPGAP. toolshed builds each app's webhook target from the # hostname the dashboard was browsed on (internal/api/apps.go's # queueRepo), with no override, so an app registered through the # public URL gets a public webhook target and Gitea refuses to call # it: "webhook can only call allowed HTTP servers". # # The cost is real but bounded: this permits exactly one hostname, # which happens to be our own load balancer, so the callback # hairpins out and back in rather than staying pod-to-pod. It does # not re-expose the metadata server, which is why "*" was rejected. # # The proper fix is a configurable webhook base URL in toolshed # pointing at toolshed-api.toolshed.svc.cluster.local:8080, after # which this entry should be removed. ALLOWED_HOST_LIST: private,console.deployshed.com admin: username: gitadmin # Created by hand with kubectl at bootstrap, because Vault and ESO # are not running yet. Same Secret name as the homelab so the # ExternalSecret (secretstores/gitea-admin-credentials.yaml) can take # it over unchanged once Vault is up. existingSecret: gitea-admin-credentials email: "admin@local.lab" # Contour does not exist yet at bootstrap — the Ingress just sits unused # until ArgoCD installs it. # # One host. The nip.io name was served alongside this one while the # deployment moved onto its own domain, and came out once everything # referencing it had been repointed: ROOT_URL above, the webhook allow-list # above that, and any git remote anyone had configured. ingress: enabled: true className: contour annotations: # Issues the certificate named in tls below. This could only ever cover # the real domain: Let's Encrypt cannot issue for nip.io, so while both # names were served, asking for one certificate spanning them returned # nothing for either. cert-manager.io/cluster-issuer: letsencrypt-prod hosts: - host: gitea.infra.deployshed.com paths: - path: / pathType: Prefix tls: - secretName: gitea-tls hosts: - gitea.infra.deployshed.com