Add k8s Gitea deployment (migration target for git.unkin.net) #309

Merged
benvin merged 4 commits from benvin/gitea into main 2026-07-31 20:03:44 +10:00

4 Commits

Author SHA1 Message Date
unkinben 34c2994cd3 Disable SSH; serve git.unkin.net + git.k8s.syd1 admin route
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
Per the forge design: drop git-over-ssh (HTTPS clones only, estate norm) and
serve the new instance on both the canonical git.unkin.net and a
git.k8s.syd1.au.unkin.net admin/backup route (same dual-name pattern as
identity). Only the k8s admin name goes live now (external-dns); the
git.unkin.net DNS flip stays the gated final cutover step.

- values: DISABLE_SSH + START_SSH_SERVER false; DOMAIN/ROOT_URL/SSH_DOMAIN ->
  git.unkin.net; drop the SSH LoadBalancer service
- overlay: $patch-delete the chart's leftover gitea-ssh Service
- gateway/httproute: listeners + routes for git.unkin.net and
  git.k8s.syd1.au.unkin.net; cert CN git.unkin.net (both as SANs); external-dns
  publishes only git.k8s.syd1.au.unkin.net -> 198.18.200.4
- bind-internal: prepared (commented) git-dns-internal DNSRecord as the gated
  apex cutover step
- docs: SSH removed, dual hostnames, git.unkin.net flip as the final step

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
2026-07-31 20:01:46 +10:00
unkinben 1ea0dc920c Point Gitea OIDC at canonical identity.unkin.net and trust the internal CA
identity.unkin.net is now the canonical Authentik host. Gitea reaches it for
OIDC discovery/JWKS over TLS served by the internal unkin.net CA, which the
rootless image doesn't trust.

- Flip the authentik login source autoDiscoverUrl to identity.unkin.net.
- Mount the reflected vault-ca-cert and add it to Gitea's Go trust pool via
  SSL_CERT_DIR (additive; public roots stay intact).

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
Signed-off-by: Ben Vincent <ben@unkin.net>
2026-07-31 20:01:46 +10:00
unkinben 2c43e57ed2 Fix gitea-http Service targetPort (chart renders null)
The chart leaves the http Service targetPort null (defaults to the port name,
which kustomize drops), failing strict kubeconform. Pin it to 3000 via a
kustomize patch.

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
2026-07-31 20:01:46 +10:00
unkinben e8d46d08f2 Add k8s Gitea deployment (HA-shaped, migration target for git.unkin.net)
Stand up the forge on k8s to replace the Puppet VM. Deployed HA-shaped to match
what the VM already runs (multi-replica on shared storage + external DB/cache):
official Gitea chart 12.6.0 (app 1.26.2) at 2 replicas on RWX CephFS, CNPG
Postgres with S3 backup, standalone Valkey for cache/session/queue, Authentik
OIDC, Actions disabled and the container registry moved to artifactapi. Serves a
temporary git2.k8s.syd1.au.unkin.net host; cutover is staged (see the doc).

- add apps/base/gitea (namespace, CNPG cluster+backup+pooler, Valkey, VaultAuth,
  VaultStaticSecrets, Gateway, HTTPRoute)
- add apps/overlays/au-syd1/gitea (chart 12.6.0 via helm-through-kustomize + values,
  drop the chart test Pod)
- register gitea in the platform ApplicationSet and AppProject
- add docs/gitea-migration.md staged cutover plan

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
2026-07-31 20:01:46 +10:00