Files
devops-infra-helm-charts-gcp/helm-overrides/gke-toolshed-prd-usc1/gitea/custom-values.yaml
T
Mukul SharmaandClaude Opus 5 73ddfd8534 Let Gitea call toolshed's webhook endpoint
Gitea refused every push notification with "webhook can only call allowed
HTTP servers": toolshed builds an app's webhook target from the hostname
the dashboard was browsed on, so an app registered through the public URL
gets a public target, and this cluster's allowlist only permitted private
ranges.

Adding that one hostname rather than reverting to the homelab's "*". The
difference matters: "*" would also permit the node metadata server, which
is why it was narrowed in the first place. This permits exactly one host,
our own load balancer.

It is a stopgap and labelled as one in the file. The callback now hairpins
out to the load balancer and back in, which is precisely what the
cluster-DNS rule exists to avoid. The real fix is a configurable webhook
base URL in toolshed pointing at
toolshed-api.toolshed.svc.cluster.local:8080; this entry should be removed
when that lands.

Verified in the render: the value reaches Gitea's inline config, and
Recreate, standard-rwo, sqlite and disabled registration are untouched.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LEsTefWWifp4ikvhHF5s6N
2026-09-13 09:25:39 +05:30

92 lines
3.5 KiB
YAML

gitea:
# GKE counterpart of helm-overrides/k8s-admin-prd-ase1/gitea — same
# SQLite/no-cache shape, with what differs on GKE called out inline.
#
# Installed once by hand with `helm install gitea` (release "gitea",
# namespace "gitea"), then adopted by ArgoCD via the nameOverride in
# devops-infra-argo-config-gcp's values file. Gitea has to exist before
# ArgoCD can read anything, since both config repos live inside it.
# Recreate for a different reason than the homelab's LevelDB lock: on
# three nodes with a ReadWriteOnce persistent disk, the chart's default
# RollingUpdate (maxUnavailable: 0) starts the new pod first, and if it
# lands on another node it waits forever on Multi-Attach.
strategy:
type: Recreate
persistence:
size: 10Gi
# GKE's default class (pd-balanced), in place of the homelab's
# local-path. Counts against the project's 250GB SSD quota.
storageClass: standard-rwo
postgresql:
enabled: false
postgresql-ha:
enabled: false
valkey:
enabled: false
valkey-cluster:
enabled: false
resources:
requests:
cpu: 100m
memory: 300Mi
limits:
memory: 500Mi
gitea:
config:
database:
DB_TYPE: sqlite3
actions:
ENABLED: true
server:
ROOT_URL: http://gitea.35.238.248.203.nip.io/
service:
# The homelab sat on a LAN; this Gitea is on a public IP. Open
# registration would let anyone on the internet create an account.
DISABLE_REGISTRATION: true
security:
# The homelab allowed "*" because every host was on a private LAN.
# Here "*" would also allow webhooks to the node metadata server, so
# this stays narrowed to private ranges — which covers every
# in-cluster Service (Jenkins included) reached over cluster DNS.
#
# The one public entry is toolshed's own dashboard host, and it is a
# STOPGAP. toolshed builds each app's webhook target from the
# hostname the dashboard was browsed on (internal/api/apps.go's
# queueRepo), with no override, so an app registered through the
# public URL gets a public webhook target and Gitea refuses to call
# it: "webhook can only call allowed HTTP servers".
#
# The cost is real but bounded: this permits exactly one hostname,
# which happens to be our own load balancer, so the callback
# hairpins out and back in rather than staying pod-to-pod. It does
# not re-expose the metadata server, which is why "*" was rejected.
#
# The proper fix is a configurable webhook base URL in toolshed
# pointing at toolshed-api.toolshed.svc.cluster.local:8080, after
# which this entry should be removed.
ALLOWED_HOST_LIST: private,toolshed.35.238.248.203.nip.io
admin:
username: gitadmin
# Created by hand with kubectl at bootstrap, because Vault and ESO
# are not running yet. Same Secret name as the homelab so the
# ExternalSecret (secretstores/gitea-admin-credentials.yaml) can take
# it over unchanged once Vault is up.
existingSecret: gitea-admin-credentials
email: "admin@local.lab"
# Contour does not exist yet at bootstrap — the Ingress just sits unused
# until ArgoCD installs it. One host only: no Tailscale on GKE.
ingress:
enabled: true
className: contour
hosts:
- host: gitea.35.238.248.203.nip.io
paths:
- path: /
pathType: Prefix