fix(argocd): let the image-updater trust the lab CA — the last blocker to rollouts #36

Merged
arcodange merged 1 commits from arcodange/updater-ca into main 2026-07-20 09:11:26 +02:00
1 Commits
Author SHA1 Message Date
arcodangeandClaude Fable 5 4d67f699a1 fix(argocd): let the image-updater trust the lab CA — the last blocker to rollouts
With the ImageUpdater CR in place (#34) the updater finally sees all six
annotated applications, and every single registry query dies on
"x509: certificate signed by unknown authority": nodes trust the lab root
through the OS store, but the container carries its own.

Mount the root CA (public material, no key) into /etc/ssl/certs via subPath —
Go reads every file in that directory on top of the bundle, so the image's own
certs stay untouched. The registry allows anonymous pulls, so trust was the
only missing piece; no credentials needed.

Co-Authored-By: Claude Fable 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_013ws8L74dVZmp97Wu36fm8j
2026-07-20 09:10:59 +02:00