693f541840
go-cache-plugin serve binds 127.0.0.1 only, so a Service cannot reach it directly and CI/developer builds have no way to use the S3-backed cache. - Run go-cache-plugin serve against the gocache RGW bucket, path-style, with an explicit region to skip the GetBucketLocation probe - Add an nginx sidecar stream-proxying 9090 to the loopback plugin port - Restrict the listener to the workstation and pod CIDRs: GOCACHEPROG is unauthenticated and a poisoned entry runs in every consuming build - Stage the cache on an emptyDir; loss costs a repopulate from S3
37 lines
1.1 KiB
YAML
37 lines
1.1 KiB
YAML
---
|
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
kind: Kustomization
|
|
|
|
resources:
|
|
- namespace.yaml
|
|
- cnpg_cluster.yaml
|
|
- cnpg_backup.yaml
|
|
- cnpg_pooler.yaml
|
|
- gocache_bucket.yaml
|
|
- configmap_gocache-nginx.yaml
|
|
- deployment_gocache.yaml
|
|
- service_gocache.yaml
|
|
- serviceaccount_arrproxy_ci.yaml
|
|
- serviceaccount_autobackup_operator_ci.yaml
|
|
- serviceaccount_ghp.yaml
|
|
- serviceaccount_golib_ci.yaml
|
|
- serviceaccount_kea_operator_ci.yaml
|
|
- serviceaccount_mediamark_ci.yaml
|
|
- serviceaccount_plugin_docker_buildx.yaml
|
|
- serviceaccount_jellyfin_ha_src.yaml
|
|
- serviceaccount_jellyfin_plugin_sso.yaml
|
|
- serviceaccount_repospawner_ci.yaml
|
|
- serviceaccount_terraform_artifactapi.yaml
|
|
- serviceaccount_terraform_authentik.yaml
|
|
- serviceaccount_terraform_enc.yaml
|
|
- serviceaccount_terraform_git.yaml
|
|
- serviceaccount_terraform_infra.yaml
|
|
- serviceaccount_terraform_prowlarr.yaml
|
|
- serviceaccount_terraform_rancher.yaml
|
|
- serviceaccount_terraform_radarr.yaml
|
|
- serviceaccount_terraform_sonarr.yaml
|
|
- serviceaccount_terraform_vault.yaml
|
|
- serviceaccount_vimpack_ci.yaml
|
|
- vaultauth.yaml
|
|
- vaultstaticsecret.yaml
|