Harbor, Gitea, Argo CD, Jenkins, Vault, Grafana and vmui now answer on their deployshed.com names alone. Each was already serving both while the move was proved out; this removes the nip.io half. The dual-hostname workarounds go with it. Jenkins' secondaryingress existed only because its chart's primary ingress takes one hostName and a certificate could not span both names — the real domain moves onto the primary with jenkins-tls, which it already holds. Argo CD gets extraTls rather than ingress.tls, because the boolean hardcodes secretName argocd-server-tls and would request a second certificate for a name that already has a valid one in argocd-deployshed-tls. Harbor also changes in two ways beyond the hostname: - externalURL moves to https://harbor.infra.deployshed.com. Harbor hands this to docker clients in its own API responses and builds the push commands shown in its UI from it, so a stale value is what makes a correctly-configured registry still advertise the old address. - updateStrategy is now Recreate. Its jobservice and registry volumes are standard-rwo (ReadWriteOnce), and a RollingUpdate starts the new pod before the old one releases the disk, so the replacement hangs forever on Multi-Attach. The cluster was sitting in exactly that state, old pods serving while new ones stayed in ContainerCreating. The chart's own comment on this value recommends Recreate when RWM is unavailable. The cost is a brief outage during upgrades, which beats a rollout that cannot complete. The private registry CA is not removed yet. Apps deployed before this move recorded nip.io image references that only change when each is rebuilt, so the old hostname stays served by a standalone Ingress until then. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LEsTefWWifp4ikvhHF5s6N
107 lines
4.1 KiB
YAML
107 lines
4.1 KiB
YAML
gitea:
|
|
# GKE counterpart of helm-overrides/k8s-admin-prd-ase1/gitea — same
|
|
# SQLite/no-cache shape, with what differs on GKE called out inline.
|
|
#
|
|
# Installed once by hand with `helm install gitea` (release "gitea",
|
|
# namespace "gitea"), then adopted by ArgoCD via the nameOverride in
|
|
# devops-infra-argo-config-gcp's values file. Gitea has to exist before
|
|
# ArgoCD can read anything, since both config repos live inside it.
|
|
|
|
# Recreate for a different reason than the homelab's LevelDB lock: on
|
|
# three nodes with a ReadWriteOnce persistent disk, the chart's default
|
|
# RollingUpdate (maxUnavailable: 0) starts the new pod first, and if it
|
|
# lands on another node it waits forever on Multi-Attach.
|
|
strategy:
|
|
type: Recreate
|
|
|
|
persistence:
|
|
size: 10Gi
|
|
# GKE's default class (pd-balanced), in place of the homelab's
|
|
# local-path. Counts against the project's 250GB SSD quota.
|
|
storageClass: standard-rwo
|
|
|
|
postgresql:
|
|
enabled: false
|
|
postgresql-ha:
|
|
enabled: false
|
|
valkey:
|
|
enabled: false
|
|
valkey-cluster:
|
|
enabled: false
|
|
|
|
resources:
|
|
requests:
|
|
cpu: 100m
|
|
memory: 300Mi
|
|
limits:
|
|
memory: 500Mi
|
|
|
|
gitea:
|
|
config:
|
|
database:
|
|
DB_TYPE: sqlite3
|
|
actions:
|
|
ENABLED: true
|
|
server:
|
|
ROOT_URL: https://gitea.infra.deployshed.com/
|
|
service:
|
|
# The homelab sat on a LAN; this Gitea is on a public IP. Open
|
|
# registration would let anyone on the internet create an account.
|
|
DISABLE_REGISTRATION: true
|
|
security:
|
|
# The homelab allowed "*" because every host was on a private LAN.
|
|
# Here "*" would also allow webhooks to the node metadata server, so
|
|
# this stays narrowed to private ranges — which covers every
|
|
# in-cluster Service (Jenkins included) reached over cluster DNS.
|
|
#
|
|
# The one public entry is toolshed's own dashboard host, and it is a
|
|
# STOPGAP. toolshed builds each app's webhook target from the
|
|
# hostname the dashboard was browsed on (internal/api/apps.go's
|
|
# queueRepo), with no override, so an app registered through the
|
|
# public URL gets a public webhook target and Gitea refuses to call
|
|
# it: "webhook can only call allowed HTTP servers".
|
|
#
|
|
# The cost is real but bounded: this permits exactly one hostname,
|
|
# which happens to be our own load balancer, so the callback
|
|
# hairpins out and back in rather than staying pod-to-pod. It does
|
|
# not re-expose the metadata server, which is why "*" was rejected.
|
|
#
|
|
# The proper fix is a configurable webhook base URL in toolshed
|
|
# pointing at toolshed-api.toolshed.svc.cluster.local:8080, after
|
|
# which this entry should be removed.
|
|
ALLOWED_HOST_LIST: private,console.deployshed.com
|
|
admin:
|
|
username: gitadmin
|
|
# Created by hand with kubectl at bootstrap, because Vault and ESO
|
|
# are not running yet. Same Secret name as the homelab so the
|
|
# ExternalSecret (secretstores/gitea-admin-credentials.yaml) can take
|
|
# it over unchanged once Vault is up.
|
|
existingSecret: gitea-admin-credentials
|
|
email: "admin@local.lab"
|
|
|
|
# Contour does not exist yet at bootstrap — the Ingress just sits unused
|
|
# until ArgoCD installs it.
|
|
#
|
|
# One host. The nip.io name was served alongside this one while the
|
|
# deployment moved onto its own domain, and came out once everything
|
|
# referencing it had been repointed: ROOT_URL above, the webhook allow-list
|
|
# above that, and any git remote anyone had configured.
|
|
ingress:
|
|
enabled: true
|
|
className: contour
|
|
annotations:
|
|
# Issues the certificate named in tls below. This could only ever cover
|
|
# the real domain: Let's Encrypt cannot issue for nip.io, so while both
|
|
# names were served, asking for one certificate spanning them returned
|
|
# nothing for either.
|
|
cert-manager.io/cluster-issuer: letsencrypt-prod
|
|
hosts:
|
|
- host: gitea.infra.deployshed.com
|
|
paths:
|
|
- path: /
|
|
pathType: Prefix
|
|
tls:
|
|
- secretName: gitea-tls
|
|
hosts:
|
|
- gitea.infra.deployshed.com
|