Fetch templates over HTTP instead of shelling out to git
The runtime image is distroless and has no git binary, so every sync failed and bootapi silently served the stale embedded templates. - fetch the branch tarball (<repo>/archive/<branch>.tar.gz) and extract it into an in-memory FS; no checkout, no writable volume - digest the extracted tree, not the archive bytes, so a recompressed identical archive is not a change - skip entries that would escape the tree - log the source commit from Gitea's immutable Link header
This commit is contained in:
+3
-4
@@ -44,10 +44,9 @@ Create `apps/base/bootapi/` following the argocd-apps `AGENTS.md` pattern:
|
||||
as `BOOTAPI_NETBOX_TOKEN_FILE` / `BOOTAPI_PROVISION_TOKEN_FILE` /
|
||||
`BOOTAPI_ROOT_PASSWORD_HASH_FILE` (mount the Secret). Least-privilege
|
||||
securityContext (`runAsNonRoot`, `drop: [all]`). Baseline resources: requests
|
||||
`512Mi`/`1`, limits `2Gi`/`2` cpu. The pod needs `git` on PATH for template
|
||||
sync (the distroless image includes only the static binary — either add a git
|
||||
layer, use an initContainer that seeds the checkout, or fall back to a
|
||||
ConfigMap; simplest is a small alpine+git base for this service).
|
||||
`512Mi`/`1`, limits `2Gi`/`2` cpu. No `git` binary and no writable volume
|
||||
are needed: template sync is an HTTP fetch of the repo's branch tarball, held
|
||||
in memory.
|
||||
6. **Service + exposure**: see the Gateway section below.
|
||||
7. Register in `argocd/applicationsets/platform.yaml` (`apps/overlays/*/bootapi`)
|
||||
and the platform AppProject destinations.
|
||||
|
||||
@@ -8,7 +8,8 @@ bootapi ships an embedded default set and lets you override or extend it.
|
||||
`templates/ipxe/*.ipxe.tmpl` and `templates/catalog/*.yaml`, compiled into the
|
||||
binary (`templates/embed.go`). These are the always-available startup fallback.
|
||||
- **Template git repo** (preferred in prod): `BOOTAPI_TEMPLATE_GIT_URL`. bootapi
|
||||
clones it at startup and re-pulls every `BOOTAPI_TEMPLATE_GIT_INTERVAL`
|
||||
fetches the branch tarball (`<repo>/archive/<branch>.tar.gz`) over HTTP at
|
||||
startup and re-fetches every `BOOTAPI_TEMPLATE_GIT_INTERVAL`
|
||||
(default 3m, like argocd), atomically swapping the loaded set on change. A
|
||||
parse failure keeps the **last-good** set and is only logged + counted
|
||||
(`bootapi_template_sync_failures_total`), so a bad push can't take bootapi
|
||||
|
||||
Reference in New Issue
Block a user