Per the forge design: drop git-over-ssh (HTTPS clones only, estate norm) and
serve the new instance on both the canonical git.unkin.net and a
git.k8s.syd1.au.unkin.net admin/backup route (same dual-name pattern as
identity). Only the k8s admin name goes live now (external-dns); the
git.unkin.net DNS flip stays the gated final cutover step.
- values: DISABLE_SSH + START_SSH_SERVER false; DOMAIN/ROOT_URL/SSH_DOMAIN ->
git.unkin.net; drop the SSH LoadBalancer service
- overlay: $patch-delete the chart's leftover gitea-ssh Service
- gateway/httproute: listeners + routes for git.unkin.net and
git.k8s.syd1.au.unkin.net; cert CN git.unkin.net (both as SANs); external-dns
publishes only git.k8s.syd1.au.unkin.net -> 198.18.200.4
- bind-internal: prepared (commented) git-dns-internal DNSRecord as the gated
apex cutover step
- docs: SSH removed, dual hostnames, git.unkin.net flip as the final step
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
Stand up the forge on k8s to replace the Puppet VM. Deployed HA-shaped to match
what the VM already runs (multi-replica on shared storage + external DB/cache):
official Gitea chart 12.6.0 (app 1.26.2) at 2 replicas on RWX CephFS, CNPG
Postgres with S3 backup, standalone Valkey for cache/session/queue, Authentik
OIDC, Actions disabled and the container registry moved to artifactapi. Serves a
temporary git2.k8s.syd1.au.unkin.net host; cutover is staged (see the doc).
- add apps/base/gitea (namespace, CNPG cluster+backup+pooler, Valkey, VaultAuth,
VaultStaticSecrets, Gateway, HTTPRoute)
- add apps/overlays/au-syd1/gitea (chart 12.6.0 via helm-through-kustomize + values,
drop the chart test Pod)
- register gitea in the platform ApplicationSet and AppProject
- add docs/gitea-migration.md staged cutover plan
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv