Gitea refused every push notification with "webhook can only call allowed HTTP servers": toolshed builds an app's webhook target from the hostname the dashboard was browsed on, so an app registered through the public URL gets a public target, and this cluster's allowlist only permitted private ranges. Adding that one hostname rather than reverting to the homelab's "*". The difference matters: "*" would also permit the node metadata server, which is why it was narrowed in the first place. This permits exactly one host, our own load balancer. It is a stopgap and labelled as one in the file. The callback now hairpins out to the load balancer and back in, which is precisely what the cluster-DNS rule exists to avoid. The real fix is a configurable webhook base URL in toolshed pointing at toolshed-api.toolshed.svc.cluster.local:8080; this entry should be removed when that lands. Verified in the render: the value reaches Gitea's inline config, and Recreate, standard-rwo, sqlite and disabled registration are untouched. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LEsTefWWifp4ikvhHF5s6N
92 lines
3.5 KiB
YAML
92 lines
3.5 KiB
YAML
gitea:
|
|
# GKE counterpart of helm-overrides/k8s-admin-prd-ase1/gitea — same
|
|
# SQLite/no-cache shape, with what differs on GKE called out inline.
|
|
#
|
|
# Installed once by hand with `helm install gitea` (release "gitea",
|
|
# namespace "gitea"), then adopted by ArgoCD via the nameOverride in
|
|
# devops-infra-argo-config-gcp's values file. Gitea has to exist before
|
|
# ArgoCD can read anything, since both config repos live inside it.
|
|
|
|
# Recreate for a different reason than the homelab's LevelDB lock: on
|
|
# three nodes with a ReadWriteOnce persistent disk, the chart's default
|
|
# RollingUpdate (maxUnavailable: 0) starts the new pod first, and if it
|
|
# lands on another node it waits forever on Multi-Attach.
|
|
strategy:
|
|
type: Recreate
|
|
|
|
persistence:
|
|
size: 10Gi
|
|
# GKE's default class (pd-balanced), in place of the homelab's
|
|
# local-path. Counts against the project's 250GB SSD quota.
|
|
storageClass: standard-rwo
|
|
|
|
postgresql:
|
|
enabled: false
|
|
postgresql-ha:
|
|
enabled: false
|
|
valkey:
|
|
enabled: false
|
|
valkey-cluster:
|
|
enabled: false
|
|
|
|
resources:
|
|
requests:
|
|
cpu: 100m
|
|
memory: 300Mi
|
|
limits:
|
|
memory: 500Mi
|
|
|
|
gitea:
|
|
config:
|
|
database:
|
|
DB_TYPE: sqlite3
|
|
actions:
|
|
ENABLED: true
|
|
server:
|
|
ROOT_URL: http://gitea.35.238.248.203.nip.io/
|
|
service:
|
|
# The homelab sat on a LAN; this Gitea is on a public IP. Open
|
|
# registration would let anyone on the internet create an account.
|
|
DISABLE_REGISTRATION: true
|
|
security:
|
|
# The homelab allowed "*" because every host was on a private LAN.
|
|
# Here "*" would also allow webhooks to the node metadata server, so
|
|
# this stays narrowed to private ranges — which covers every
|
|
# in-cluster Service (Jenkins included) reached over cluster DNS.
|
|
#
|
|
# The one public entry is toolshed's own dashboard host, and it is a
|
|
# STOPGAP. toolshed builds each app's webhook target from the
|
|
# hostname the dashboard was browsed on (internal/api/apps.go's
|
|
# queueRepo), with no override, so an app registered through the
|
|
# public URL gets a public webhook target and Gitea refuses to call
|
|
# it: "webhook can only call allowed HTTP servers".
|
|
#
|
|
# The cost is real but bounded: this permits exactly one hostname,
|
|
# which happens to be our own load balancer, so the callback
|
|
# hairpins out and back in rather than staying pod-to-pod. It does
|
|
# not re-expose the metadata server, which is why "*" was rejected.
|
|
#
|
|
# The proper fix is a configurable webhook base URL in toolshed
|
|
# pointing at toolshed-api.toolshed.svc.cluster.local:8080, after
|
|
# which this entry should be removed.
|
|
ALLOWED_HOST_LIST: private,toolshed.35.238.248.203.nip.io
|
|
admin:
|
|
username: gitadmin
|
|
# Created by hand with kubectl at bootstrap, because Vault and ESO
|
|
# are not running yet. Same Secret name as the homelab so the
|
|
# ExternalSecret (secretstores/gitea-admin-credentials.yaml) can take
|
|
# it over unchanged once Vault is up.
|
|
existingSecret: gitea-admin-credentials
|
|
email: "admin@local.lab"
|
|
|
|
# Contour does not exist yet at bootstrap — the Ingress just sits unused
|
|
# until ArgoCD installs it. One host only: no Tailscale on GKE.
|
|
ingress:
|
|
enabled: true
|
|
className: contour
|
|
hosts:
|
|
- host: gitea.35.238.248.203.nip.io
|
|
paths:
|
|
- path: /
|
|
pathType: Prefix
|