fix(argocd): let the image-updater trust the lab CA — the last blocker to rollouts

With the ImageUpdater CR in place (#34) the updater finally sees all six
annotated applications, and every single registry query dies on
"x509: certificate signed by unknown authority": nodes trust the lab root
through the OS store, but the container carries its own.

Mount the root CA (public material, no key) into /etc/ssl/certs via subPath —
Go reads every file in that directory on top of the bundle, so the image's own
certs stay untouched. The registry allows anonymous pulls, so trust was the
only missing piece; no credentials needed.

Co-Authored-By: Claude Fable 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_013ws8L74dVZmp97Wu36fm8j
This commit is contained in:
2026-07-20 09:10:59 +02:00
co-authored by Claude Fable 5
parent d3261bc8c4
commit 4d67f699a1
3 changed files with 46 additions and 0 deletions
+12
View File
@@ -0,0 +1,12 @@
-----BEGIN CERTIFICATE-----
MIIBwDCCAWagAwIBAgIRAJzOnXbHdqAB0QnEjNw21xgwCgYIKoZIzj0EAwIwPjEZ
MBcGA1UEChMQQXJjb2RhbmdlIExhYiBDQTEhMB8GA1UEAxMYQXJjb2RhbmdlIExh
YiBDQSBSb290IENBMB4XDTI1MTIyOTA5Mjk0NVoXDTM1MTIyNzA5Mjk0NVowPjEZ
MBcGA1UEChMQQXJjb2RhbmdlIExhYiBDQTEhMB8GA1UEAxMYQXJjb2RhbmdlIExh
YiBDQSBSb290IENBMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAERTF3M6MtqK4m
q4e38e1KzHP7TRrf/DwEwxyafyp9iONE6na0+dgPvXPurG0kmom9PIYA2aE2eCzz
hFkQ2DO1TqNFMEMwDgYDVR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQIMAYBAf8CAQEw
HQYDVR0OBBYEFJCxc6tumAlVAaUjoKExPcNZsVoYMAoGCCqGSM49BAMCA0gAMEUC
IGtrew3FOPh16x3XevWCO8suH7laCn8kTV2ZZpAK0UkhAiEA/bA7HiDqEaXHSc35
b7fZX1fuKI6SdEWN9hj5EwP45Z8=
-----END CERTIFICATE-----
+19
View File
@@ -0,0 +1,19 @@
{{- /*
The lab's root CA, as a ConfigMap the image-updater pod can mount.
Nodes trust it through the OS store (/usr/local/share/ca-certificates), which
is why kubelet pulls images fine — but a container carries its own trust store,
so argocd-image-updater failed every registry query with
"x509: certificate signed by unknown authority" and updated nothing.
A root CA certificate is public material (no private key here), so it lives in
git next to the chart that consumes it.
*/ -}}
apiVersion: v1
kind: ConfigMap
metadata:
name: homelab-ca
namespace: argocd
data:
arcodange-root.crt: |
{{ .Files.Get "files/arcodange-root.crt" | indent 4 }}
+15
View File
@@ -57,3 +57,18 @@ argocd_image_updater_chart_values:
serverAddress: "https://argocd.arcodange.lab/" serverAddress: "https://argocd.arcodange.lab/"
insecure: true insecure: true
plaintext: true plaintext: true
# The lab CA, so the updater can talk to the Gitea registry over TLS.
# Go reads every file in /etc/ssl/certs on top of the bundle, so dropping our
# root in there (subPath — the image's own certs stay untouched) is enough.
# Without it every query died on "certificate signed by unknown authority"
# and no image was ever rolled out. The registry itself allows anonymous
# pulls, so no credentials are needed — trust was the only missing piece.
volumes:
- name: homelab-ca
configMap:
name: homelab-ca
volumeMounts:
- name: homelab-ca
mountPath: /etc/ssl/certs/arcodange-root.crt
subPath: arcodange-root.crt
readOnly: true