fix(argocd): let the image-updater trust the lab CA — the last blocker to rollouts (#36)
Co-authored-by: Gabriel Radureau <[email protected]> Co-committed-by: Gabriel Radureau <[email protected]>
This commit was merged in pull request #36.
This commit is contained in:
@@ -0,0 +1,12 @@
|
|||||||
|
-----BEGIN CERTIFICATE-----
|
||||||
|
MIIBwDCCAWagAwIBAgIRAJzOnXbHdqAB0QnEjNw21xgwCgYIKoZIzj0EAwIwPjEZ
|
||||||
|
MBcGA1UEChMQQXJjb2RhbmdlIExhYiBDQTEhMB8GA1UEAxMYQXJjb2RhbmdlIExh
|
||||||
|
YiBDQSBSb290IENBMB4XDTI1MTIyOTA5Mjk0NVoXDTM1MTIyNzA5Mjk0NVowPjEZ
|
||||||
|
MBcGA1UEChMQQXJjb2RhbmdlIExhYiBDQTEhMB8GA1UEAxMYQXJjb2RhbmdlIExh
|
||||||
|
YiBDQSBSb290IENBMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAERTF3M6MtqK4m
|
||||||
|
q4e38e1KzHP7TRrf/DwEwxyafyp9iONE6na0+dgPvXPurG0kmom9PIYA2aE2eCzz
|
||||||
|
hFkQ2DO1TqNFMEMwDgYDVR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQIMAYBAf8CAQEw
|
||||||
|
HQYDVR0OBBYEFJCxc6tumAlVAaUjoKExPcNZsVoYMAoGCCqGSM49BAMCA0gAMEUC
|
||||||
|
IGtrew3FOPh16x3XevWCO8suH7laCn8kTV2ZZpAK0UkhAiEA/bA7HiDqEaXHSc35
|
||||||
|
b7fZX1fuKI6SdEWN9hj5EwP45Z8=
|
||||||
|
-----END CERTIFICATE-----
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
{{- /*
|
||||||
|
The lab's root CA, as a ConfigMap the image-updater pod can mount.
|
||||||
|
|
||||||
|
Nodes trust it through the OS store (/usr/local/share/ca-certificates), which
|
||||||
|
is why kubelet pulls images fine — but a container carries its own trust store,
|
||||||
|
so argocd-image-updater failed every registry query with
|
||||||
|
"x509: certificate signed by unknown authority" and updated nothing.
|
||||||
|
|
||||||
|
A root CA certificate is public material (no private key here), so it lives in
|
||||||
|
git next to the chart that consumes it.
|
||||||
|
*/ -}}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: homelab-ca
|
||||||
|
namespace: argocd
|
||||||
|
data:
|
||||||
|
arcodange-root.crt: |
|
||||||
|
{{ .Files.Get "files/arcodange-root.crt" | indent 4 }}
|
||||||
@@ -57,3 +57,18 @@ argocd_image_updater_chart_values:
|
|||||||
serverAddress: "https://argocd.arcodange.lab/"
|
serverAddress: "https://argocd.arcodange.lab/"
|
||||||
insecure: true
|
insecure: true
|
||||||
plaintext: true
|
plaintext: true
|
||||||
|
# The lab CA, so the updater can talk to the Gitea registry over TLS.
|
||||||
|
# Go reads every file in /etc/ssl/certs on top of the bundle, so dropping our
|
||||||
|
# root in there (subPath — the image's own certs stay untouched) is enough.
|
||||||
|
# Without it every query died on "certificate signed by unknown authority"
|
||||||
|
# and no image was ever rolled out. The registry itself allows anonymous
|
||||||
|
# pulls, so no credentials are needed — trust was the only missing piece.
|
||||||
|
volumes:
|
||||||
|
- name: homelab-ca
|
||||||
|
configMap:
|
||||||
|
name: homelab-ca
|
||||||
|
volumeMounts:
|
||||||
|
- name: homelab-ca
|
||||||
|
mountPath: /etc/ssl/certs/arcodange-root.crt
|
||||||
|
subPath: arcodange-root.crt
|
||||||
|
readOnly: true
|
||||||
|
|||||||
Reference in New Issue
Block a user