ghp: use direct ghcr.io image + set GHP_ADMINS (#359)

## Why
The `ghp` app is deployed but its pods are stuck 0/1 Ready (and were ImagePullBackOff), for three separate reasons this PR fixes:

- **ImagePullBackOff:** kubelet anonymous pulls fail on the artifactapi ghcr pull-through because ghcr.io's per-scope token auth is not proxied. The direct public image pulls anonymously, so switch to it.
- **Pods never Ready:** ghp serves its metrics endpoint over **HTTPS** (TLS is configured globally), but the liveness/readiness probes used the default HTTP scheme, so the kubelet probe got an HTTPS-server error and the pods never went Ready.
- **Scrape failure:** the VMServiceScrape hits that same HTTPS endpoint and needs a matching scheme/TLS config, or VM scraping of ghp fails.
- The `GHP_ADMINS` value was still a placeholder.

## How
- `deployment.yaml`: image -> `ghcr.io/goodtune/ghp:0.20.0`; liveness + readiness probe `scheme: HTTP` -> `HTTPS` (kubelet does not verify the probe cert).
- `migrate-job.yaml`: image -> `ghcr.io/goodtune/ghp:0.20.0` (shared image).
- `vmservicescrape.yaml`: endpoint `scheme: https` + `tlsConfig.insecureSkipVerify: true` (internal-CA cert; pod-IP target not in SANs).
- `configmap.yaml`: `GHP_ADMINS` -> `neoloc`.

Validated: `kustomize build apps/overlays/au-syd1/ghp` renders clean, kubeconform + pre-commit pass. Not applied.

## Follow-up (not fixed here)
The artifactapi ghcr pull-through does not proxy ghcr.io's per-scope token auth for anonymous kubelet pulls — worth closing that gap so estate images can go back through artifactapi.

Reviewed-on: #359
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #359.
This commit is contained in:
2026-08-13 22:08:05 +10:00
committed by BenVincent
parent fa1f3e7756
commit 0130d538f5
4 changed files with 10 additions and 5 deletions
+1 -1
View File
@@ -19,4 +19,4 @@ data:
GHP_TLS_CERT_FILE: /etc/ghp/tls/tls.crt
GHP_TLS_KEY_FILE: /etc/ghp/tls/tls.key
# PLACEHOLDER: set to Ben's GitHub username before ghp will admit an admin.
GHP_ADMINS: "REPLACE_ME_ben_github_username"
GHP_ADMINS: "neoloc"
+3 -3
View File
@@ -34,7 +34,7 @@ spec:
type: RuntimeDefault
containers:
- name: ghp
image: artifactapi.k8s.syd1.au.unkin.net/ghcr/goodtune/ghp:0.20.0
image: ghcr.io/goodtune/ghp:0.20.0
imagePullPolicy: IfNotPresent
# Drop the image's default --migrate so replicas never race migrations;
# schema is applied by the wave-1 migrate hook Job instead.
@@ -102,7 +102,7 @@ spec:
httpGet:
path: /metrics
port: metrics
scheme: HTTP
scheme: HTTPS
initialDelaySeconds: 30
periodSeconds: 30
successThreshold: 1
@@ -112,7 +112,7 @@ spec:
httpGet:
path: /metrics
port: metrics
scheme: HTTP
scheme: HTTPS
initialDelaySeconds: 10
periodSeconds: 5
successThreshold: 1
+1 -1
View File
@@ -37,7 +37,7 @@ spec:
type: RuntimeDefault
containers:
- name: migrate
image: artifactapi.k8s.syd1.au.unkin.net/ghcr/goodtune/ghp:0.20.0
image: ghcr.io/goodtune/ghp:0.20.0
imagePullPolicy: IfNotPresent
command: ["/ghp", "migrate"]
env:
+5
View File
@@ -16,3 +16,8 @@ spec:
endpoints:
- port: metrics
path: /metrics
scheme: https
# ghp serves metrics over TLS with an internal-CA cert; skip verification
# since the scrape targets a pod IP the cert SANs do not cover.
tlsConfig:
insecureSkipVerify: true