diff --git a/.woodpecker/docker.yaml b/.woodpecker/docker.yaml index 9662029..0eb4efb 100644 --- a/.woodpecker/docker.yaml +++ b/.woodpecker/docker.yaml @@ -24,44 +24,25 @@ steps: memory: 6Gi cpu: 4 - # Stage the internal (Vault) CA into the shared workspace so the buildkit push - # below can verify artifactapi's TLS cert. almalinux9-base already trusts the - # unkin CA (it is the image the RPM release pipelines use to reach artifactapi - # over HTTPS), so its consolidated trust bundle contains the chain we need. - - name: ca-trust - image: git.unkin.net/unkin/almalinux9-base:20260606 - commands: - - cp /etc/pki/tls/certs/ca-bundle.crt "$${CI_WORKSPACE}/artifactapi-ca.crt" - depends_on: [publish] - backend_options: - kubernetes: - serviceAccountName: default - resources: - requests: - memory: 256Mi - cpu: 250m - limits: - memory: 512Mi - cpu: 1 - # Build the runtime image and push it to the artifactapi local docker registry. - # buildkit_config points buildkit at the staged CA so the TLS handshake with - # artifactapi (Vault-signed cert) verifies; buildx copies the referenced CA - # into the buildkitd container under /etc/buildkit/certs when it creates the - # builder. CI_WORKSPACE is runtime-only so the path is the fixed workspace path. + # The plugin image bakes artifactapi's internal (Vault) CA at + # /etc/docker/certs.d//ca.crt; buildkit_config points the buildx + # docker-container builder at that in-image CA. buildkitd runs in its own + # container and performs the push, so it needs the CA via --config even though + # the plugin image already trusts it — buildx copies the referenced file in. - name: docker - image: woodpeckerci/plugin-docker-buildx + image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/plugin-docker-buildx:latest settings: registry: artifactapi.k8s.syd1.au.unkin.net repo: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha dockerfile: Dockerfile.runtime buildkit_config: | [registry."artifactapi.k8s.syd1.au.unkin.net"] - ca = ["/woodpecker/src/git.unkin.net/unkin/jellyfin-ha/artifactapi-ca.crt"] + ca = ["/etc/docker/certs.d/artifactapi.k8s.syd1.au.unkin.net/ca.crt"] tags: - ${CI_COMMIT_TAG} - latest - depends_on: [ca-trust] + depends_on: [publish] backend_options: kubernetes: serviceAccountName: default