Per the forge design: drop git-over-ssh (HTTPS clones only, estate norm) and
serve the new instance on both the canonical git.unkin.net and a
git.k8s.syd1.au.unkin.net admin/backup route (same dual-name pattern as
identity). Only the k8s admin name goes live now (external-dns); the
git.unkin.net DNS flip stays the gated final cutover step.
- values: DISABLE_SSH + START_SSH_SERVER false; DOMAIN/ROOT_URL/SSH_DOMAIN ->
git.unkin.net; drop the SSH LoadBalancer service
- overlay: $patch-delete the chart's leftover gitea-ssh Service
- gateway/httproute: listeners + routes for git.unkin.net and
git.k8s.syd1.au.unkin.net; cert CN git.unkin.net (both as SANs); external-dns
publishes only git.k8s.syd1.au.unkin.net -> 198.18.200.4
- bind-internal: prepared (commented) git-dns-internal DNSRecord as the gated
apex cutover step
- docs: SSH removed, dual hostnames, git.unkin.net flip as the final step
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
identity.unkin.net is now the canonical Authentik host. Gitea reaches it for
OIDC discovery/JWKS over TLS served by the internal unkin.net CA, which the
rootless image doesn't trust.
- Flip the authentik login source autoDiscoverUrl to identity.unkin.net.
- Mount the reflected vault-ca-cert and add it to Gitea's Go trust pool via
SSL_CERT_DIR (additive; public roots stay intact).
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
Signed-off-by: Ben Vincent <ben@unkin.net>
The chart leaves the http Service targetPort null (defaults to the port name,
which kustomize drops), failing strict kubeconform. Pin it to 3000 via a
kustomize patch.
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
Stand up the forge on k8s to replace the Puppet VM. Deployed HA-shaped to match
what the VM already runs (multi-replica on shared storage + external DB/cache):
official Gitea chart 12.6.0 (app 1.26.2) at 2 replicas on RWX CephFS, CNPG
Postgres with S3 backup, standalone Valkey for cache/session/queue, Authentik
OIDC, Actions disabled and the container registry moved to artifactapi. Serves a
temporary git2.k8s.syd1.au.unkin.net host; cutover is staged (see the doc).
- add apps/base/gitea (namespace, CNPG cluster+backup+pooler, Valkey, VaultAuth,
VaultStaticSecrets, Gateway, HTTPRoute)
- add apps/overlays/au-syd1/gitea (chart 12.6.0 via helm-through-kustomize + values,
drop the chart test Pod)
- register gitea in the platform ApplicationSet and AppProject
- add docs/gitea-migration.md staged cutover plan
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv