ghp serves metrics over HTTPS (TLS configured globally), but the
liveness/readiness probes used the default HTTP scheme, so the kubelet
probe hit an HTTPS-server error and pods never went Ready. Set
scheme: HTTPS on both probes (kubelet does not verify the probe cert).
The VMServiceScrape targets that same HTTPS endpoint, so set scheme:
https with tlsConfig.insecureSkipVerify (internal-CA cert, pod-IP target
not in the cert SANs); otherwise VM scraping of ghp fails.
- deployment.yaml: liveness+readiness probes scheme HTTP -> HTTPS
- vmservicescrape.yaml: scheme https + tlsConfig.insecureSkipVerify
Kubelet pulls hit ImagePullBackOff on the artifactapi ghcr pull-through
because ghcr.io's per-scope token auth is not proxied for anonymous
pulls. Switch the serve Deployment and migrate Job to the direct public
image (pulls anonymously) and set the admin to neoloc.
- deployment.yaml: image -> ghcr.io/goodtune/ghp:0.20.0
- migrate-job.yaml: image -> ghcr.io/goodtune/ghp:0.20.0
- configmap.yaml: GHP_ADMINS -> neoloc