The homelab pushes to a project called "homelab"; this cluster's is
apps-registry. Harbor rejects a push to a missing project with
"unauthorized: project homelab not found" — the word unauthorized sends
you looking at the robot account, when the credentials were never the
problem.
Only the harbor_project default changes. The com/homelab and org/homelab
paths in this repo are the library's own package and resource paths and
have nothing to do with the registry; renaming those would break the
library.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LEsTefWWifp4ikvhHF5s6N
The GCP counterpart of devops-lib. Registered in Jenkins under the same
name, so consuming repos need no change: the two-line Jenkinsfile is
identical on both clusters, and which library it resolves to is a property
of the Jenkins running it.
Substantive changes, all consequences of GKE being a real cloud:
- Harbor speaks TLS here, so dind no longer passes --insecure-registry.
It mounts the private CA at
/etc/docker/certs.d/harbor.35.238.248.203.nip.io/ca.crt instead, from the
registry-ca ConfigMap. This is not redundant with the node pool's trust:
that covers pulls, performed by containerd on the node, while the push
comes from dockerd in the build pod with its own trust store. Without it,
pushes fail TLS verification while pulls of the same image succeed —
which reads like a broken registry rather than a missing trust anchor.
- The registry hostname changes in the push target and all five fallback
Dockerfiles. It still must be spelled identically everywhere, because
Docker matches credentials and trust by exact hostname.
- helm_repo_url moves to cluster DNS. That clone runs in a build pod, so
sending it out through the ingress and back would make the pipeline
depend on Contour for pod-to-pod traffic. syncArgoApp already addressed
ArgoCD this way and needed no change.
- build-tools.Dockerfile is removed: devops-base-images-gcp owns it now,
next to the mirrored base images, and the pod references the result by
tag at base-images/build-tools:1. The base-images project is public, so
the pod can pull it before it has any credentials.
Verified: no homelab addresses remain; the pod template parses with the CA
mount, the new image and no insecure-registry flag; and every fallback
template's base image, with the default version buildDocker would pick, is
present in the mirror manifest — an unmirrored tag now fails the build
rather than silently falling back to Docker Hub.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LEsTefWWifp4ikvhHF5s6N
Build #5 got through checkout, loadConfig, and the pre_build hook,
then hit two real bugs at the actual docker build step:
1. `docker build` failed with "mkdir /root/.docker/buildx: read-only
file system" — dind-pod.yaml mounts the Harbor push-auth secret
read-only at /root/.docker, but modern docker defaults to
BuildKit/buildx, which wants to write its own state there. Forces
the classic builder via DOCKER_BUILDKIT=0 instead.
2. The subsequent error-handling itself then threw a
NullPointerException — every stage file (including untouched
legacy ones from the real devops-lib) reads env.FAILURE when
setting currentBuild.result, but nothing in this repo ever defined
it, so it was null. Defined once in homelabPipeline.groovy rather
than touching 40+ individual occurrences across every stage file.
Renames src/com/meesho -> src/com/homelab, resources/com/meesho ->
resources/com/homelab, resources/org/meesho -> resources/org/homelab
(via git mv, preserving history), and sweeps every remaining
occurrence of "meesho" (any casing) out of package declarations,
imports, libraryResource() paths, and comments across the whole repo.
Also drops the per-user allowlist in vars/eksCICD.groovy, which
hardcoded real former-colleagues' emails and doesn't apply to a
single-person homelab — that branch is now permanently skipped rather
than deleted outright, to avoid hand-editing the escape-sequence-heavy
echo blocks it guards (eksCICD.groovy itself is unused legacy code,
not called by homelabPipeline.groovy).
Does not touch the ~114 files that were already missing from the
working tree but still tracked in the prior commit — that's unrelated
pre-existing state, left as-is.