Make the registry hostname configurable and drop the CA mount
buildDocker.groovy hardcoded harbor.35.238.248.203.nip.io as the push target, so the registry could not move without editing this shared library and every consumer moving in the same commit. It now reads config.harbor_registry, whose default lives in homelabPipeline.groovy beside harbor_project and every other key. The stage errors rather than defaulting when the value is missing. Carrying a second copy of the literal would leave two defaults free to disagree, and an unset value would otherwise build an image named "null/<project>/<repo>" — which docker accepts as a hostname and then fails to resolve, pointing nowhere near the cause. The dind pod no longer mounts the registry CA. That mount existed because the registry was a nip.io name, which no public CA will issue for, so cert-manager signed Harbor from a private CA; the node pool was told to trust it for pulls, but a push comes from dockerd inside the build pod, which has its own trust store. harbor.infra.deployshed.com carries a Let's Encrypt certificate that both already trust, so the mount, its volume and the whole arrangement go away rather than being repointed. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LEsTefWWifp4ikvhHF5s6N
This commit is contained in:
co-authored by
Claude Opus 5
parent
a9119d7b8e
commit
6d743cbe48
@@ -13,14 +13,14 @@
|
||||
# a dockerBuildVersion whose tag isn't in devops-base-images/images.txt
|
||||
# yet needs that added and re-mirrored first, unlike pulling straight
|
||||
# from Docker Hub where any tag "just worked".
|
||||
FROM harbor.35.238.248.203.nip.io/base-images/golang:${version}-alpine AS build
|
||||
FROM harbor.infra.deployshed.com/base-images/golang:${version}-alpine AS build
|
||||
WORKDIR /src
|
||||
COPY go.mod go.sum* ./
|
||||
RUN go mod download 2>/dev/null || true
|
||||
COPY . .
|
||||
RUN CGO_ENABLED=0 go build -o /app .
|
||||
|
||||
FROM harbor.35.238.248.203.nip.io/base-images/alpine:3.20
|
||||
FROM harbor.infra.deployshed.com/base-images/alpine:3.20
|
||||
COPY --from=build /app /app
|
||||
EXPOSE 8080
|
||||
ENTRYPOINT ["/app"]
|
||||
|
||||
@@ -8,14 +8,14 @@
|
||||
# to Maven Central for plugins/dependencies during the build regardless
|
||||
# of base image — this only removes the Docker Hub dependency for the
|
||||
# base image layer, not package-registry traffic during the build.
|
||||
FROM harbor.35.238.248.203.nip.io/base-images/maven:3-eclipse-temurin-${version}-alpine AS build
|
||||
FROM harbor.infra.deployshed.com/base-images/maven:3-eclipse-temurin-${version}-alpine AS build
|
||||
WORKDIR /src
|
||||
COPY pom.xml .
|
||||
RUN mvn -B dependency:go-offline
|
||||
COPY . .
|
||||
RUN mvn -B package -DskipTests
|
||||
|
||||
FROM harbor.35.238.248.203.nip.io/base-images/eclipse-temurin:${version}-jre-alpine
|
||||
FROM harbor.infra.deployshed.com/base-images/eclipse-temurin:${version}-jre-alpine
|
||||
WORKDIR /app
|
||||
COPY --from=build /src/target/*.jar app.jar
|
||||
EXPOSE 8080
|
||||
|
||||
@@ -5,14 +5,14 @@
|
||||
# Assumes a standard `npm run build` + `npm start` repo. Switched from
|
||||
# node:*-slim (Debian) to node:*-alpine for both stages — smaller, still
|
||||
# keeps a shell for kubectl exec debugging (not distroless).
|
||||
FROM harbor.35.238.248.203.nip.io/base-images/node:${version}-alpine AS build
|
||||
FROM harbor.infra.deployshed.com/base-images/node:${version}-alpine AS build
|
||||
WORKDIR /app
|
||||
COPY package*.json ./
|
||||
RUN npm ci
|
||||
COPY . .
|
||||
RUN npm run build --if-present
|
||||
|
||||
FROM harbor.35.238.248.203.nip.io/base-images/node:${version}-alpine
|
||||
FROM harbor.infra.deployshed.com/base-images/node:${version}-alpine
|
||||
WORKDIR /app
|
||||
COPY --from=build /app .
|
||||
ENV NODE_ENV=production
|
||||
|
||||
@@ -36,7 +36,7 @@
|
||||
# very comment did so), new edits to this header should avoid typing
|
||||
# the character at all — write "dollar sign" in words instead of using
|
||||
# the glyph.
|
||||
FROM harbor.35.238.248.203.nip.io/base-images/php:${version}-cli-alpine
|
||||
FROM harbor.infra.deployshed.com/base-images/php:${version}-cli-alpine
|
||||
WORKDIR /var/www/html
|
||||
RUN apk add --no-cache --virtual .build-deps \$PHPIZE_DEPS \
|
||||
&& docker-php-ext-install pdo pdo_mysql \
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# extensions that only ship glibc wheels may need musl-dev/gcc added
|
||||
# here to build from source on Alpine — fine for this repo's pure-Python
|
||||
# deps, worth knowing if a future repo's requirements.txt needs more.
|
||||
FROM harbor.35.238.248.203.nip.io/base-images/python:${version}-alpine
|
||||
FROM harbor.infra.deployshed.com/base-images/python:${version}-alpine
|
||||
WORKDIR /app
|
||||
COPY requirements.txt .
|
||||
RUN pip install --no-cache-dir -r requirements.txt
|
||||
|
||||
@@ -15,34 +15,33 @@ spec:
|
||||
image: docker:27-dind
|
||||
securityContext:
|
||||
privileged: true
|
||||
# No --insecure-registry, unlike the homelab: Harbor here serves a real
|
||||
# certificate, issued by cert-manager from the private CA that the node
|
||||
# pool was told to trust when it was created.
|
||||
# No --insecure-registry and no mounted CA: Harbor is reached at
|
||||
# harbor.infra.deployshed.com, which carries a publicly trusted Let's
|
||||
# Encrypt certificate, so dockerd's own trust store already accepts it
|
||||
# with nothing configured.
|
||||
#
|
||||
# That node trust covers image PULLS, which containerd performs on the
|
||||
# node. This push is a different client — dockerd, inside this pod,
|
||||
# with its own trust store and no knowledge of what the node trusts —
|
||||
# so it needs the CA mounted itself. dockerd looks it up at
|
||||
# /etc/docker/certs.d/<registry host>/ca.crt, and the directory name
|
||||
# must be the registry hostname exactly; anything else is silently
|
||||
# ignored, and the push then fails TLS verification while a pull of the
|
||||
# very same image works.
|
||||
# This previously mounted the private registry CA here, because the
|
||||
# registry was a nip.io name that no public CA can issue for (nip.io is
|
||||
# not on the public suffix list, and every *.nip.io certificate shares
|
||||
# one rate limit), so cert-manager signed it from a private CA instead.
|
||||
# A pull was fine — the node pool was told to trust that CA and
|
||||
# containerd performs pulls — but a push is a different client with its
|
||||
# own trust store, which is why dockerd needed the CA at
|
||||
# /etc/docker/certs.d/<registry host>/ca.crt. Moving to a real domain
|
||||
# removes the whole arrangement rather than repointing it.
|
||||
#
|
||||
# The registry hostname (rather than harbor-core.harbor.svc.cluster.local)
|
||||
# carries over unchanged from the homelab, for a reason that still
|
||||
# holds: cluster DNS resolves from this pod but not from the node's
|
||||
# containerd doing the real Deployment pull, and Docker matches both
|
||||
# stored credentials and trust by exact hostname — so push and pull
|
||||
# have to name the registry identically.
|
||||
# The registry is still named by its ingress hostname rather than
|
||||
# harbor-core.harbor.svc.cluster.local, for a reason that still holds:
|
||||
# cluster DNS resolves from this pod but not from the node's containerd
|
||||
# doing the real Deployment pull, and Docker matches both stored
|
||||
# credentials and trust by exact hostname — so push and pull have to
|
||||
# name the registry identically.
|
||||
env:
|
||||
- name: DOCKER_TLS_CERTDIR
|
||||
value: ""
|
||||
volumeMounts:
|
||||
- name: docker-graph-storage
|
||||
mountPath: /var/lib/docker
|
||||
- name: registry-ca
|
||||
mountPath: /etc/docker/certs.d/harbor.35.238.248.203.nip.io
|
||||
readOnly: true
|
||||
- name: docker-cli
|
||||
# Custom image, built and pushed by hand from devops-base-images-gcp
|
||||
# (build-tools.Dockerfile there) — bakes in git/yq/bash/python3 with
|
||||
@@ -55,7 +54,7 @@ spec:
|
||||
#
|
||||
# Versioned tag, never :latest — rebuilding the tools image must not
|
||||
# roll out until this pin is bumped deliberately.
|
||||
image: harbor.35.238.248.203.nip.io/base-images/build-tools:1
|
||||
image: harbor.infra.deployshed.com/base-images/build-tools:1
|
||||
command: ["cat"]
|
||||
tty: true
|
||||
env:
|
||||
@@ -92,13 +91,6 @@ spec:
|
||||
volumes:
|
||||
- name: docker-graph-storage
|
||||
emptyDir: {}
|
||||
- name: registry-ca
|
||||
configMap:
|
||||
# Published by devops-infra-argo-config-gcp (extra-manifests). The
|
||||
# CA's public certificate only — its private key never leaves
|
||||
# Terraform state and cert-manager, which is why this is a ConfigMap
|
||||
# rather than a Secret.
|
||||
name: registry-ca
|
||||
- name: docker-config
|
||||
secret:
|
||||
secretName: harbor-robot-dockerconfig
|
||||
|
||||
Reference in New Issue
Block a user