5341253573357ab04791592707f2bfacb025c9d5
Go builds on CI and laptops each rebuild the same packages from scratch. A GOCACHEPROG backend needs an S3 bucket plus credentials before anything can point at it, so provision those first. The bucket lives in the woodpecker namespace because CI is the primary consumer and reads the Secret there. - add Bucket and ObjectStoreUser for the shared Go build cache - use default (replicated) placement rather than the ec target, since a build cache is millions of small objects - purge and drop the bucket and user on delete; the cache is disposable Nothing consumes the bucket yet. Reviewed-on: #489 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
argocd-apps docs
Operational notes for the manifests in this repo.
| Doc | What it covers |
|---|---|
| cnpg-backups.md | How CNPG Postgres backups (WAL archiving + nightly base backups) to Ceph RGW are configured. |
| cnpg-restore.md | Restoring a CNPG cluster: full recovery, point-in-time recovery, cutover, and gotchas. |
| authentik-rancher-sso.md | Manual runtime step to point Rancher's OIDC auth at the canonical identity.unkin.net issuer and trust the internal CA. |
| gitea-migration.md | Staged cutover of the git.unkin.net forge from the Puppet VM to the gitea namespace. |
| ca-rotation.md | Rolling the internal unkin.net PKI CA (vault-ca-cert): what Reloader restarts automatically vs. manual/CNPG restarts. |
Description
Languages
Shell
91.1%
Makefile
8.9%