With the ImageUpdater CR in place (#34) the updater finally sees all six annotated applications, and every single registry query dies on "x509: certificate signed by unknown authority": nodes trust the lab root through the OS store, but the container carries its own. Mount the root CA (public material, no key) into /etc/ssl/certs via subPath — Go reads every file in that directory on top of the bundle, so the image's own certs stay untouched. The registry allows anonymous pulls, so trust was the only missing piece; no credentials needed. Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_013ws8L74dVZmp97Wu36fm8j
13 lines
668 B
Plaintext
13 lines
668 B
Plaintext
-----BEGIN CERTIFICATE-----
|
|
MIIBwDCCAWagAwIBAgIRAJzOnXbHdqAB0QnEjNw21xgwCgYIKoZIzj0EAwIwPjEZ
|
|
MBcGA1UEChMQQXJjb2RhbmdlIExhYiBDQTEhMB8GA1UEAxMYQXJjb2RhbmdlIExh
|
|
YiBDQSBSb290IENBMB4XDTI1MTIyOTA5Mjk0NVoXDTM1MTIyNzA5Mjk0NVowPjEZ
|
|
MBcGA1UEChMQQXJjb2RhbmdlIExhYiBDQTEhMB8GA1UEAxMYQXJjb2RhbmdlIExh
|
|
YiBDQSBSb290IENBMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAERTF3M6MtqK4m
|
|
q4e38e1KzHP7TRrf/DwEwxyafyp9iONE6na0+dgPvXPurG0kmom9PIYA2aE2eCzz
|
|
hFkQ2DO1TqNFMEMwDgYDVR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQIMAYBAf8CAQEw
|
|
HQYDVR0OBBYEFJCxc6tumAlVAaUjoKExPcNZsVoYMAoGCCqGSM49BAMCA0gAMEUC
|
|
IGtrew3FOPh16x3XevWCO8suH7laCn8kTV2ZZpAK0UkhAiEA/bA7HiDqEaXHSc35
|
|
b7fZX1fuKI6SdEWN9hj5EwP45Z8=
|
|
-----END CERTIFICATE-----
|