Merge pull request 'ci: trust artifactapi internal CA when pushing docker-internal' (#5) from benvin/jellyfin-buildkit-ca into main
ci/woodpecker/tag/docker Pipeline failed

Reviewed-on: #5
This commit was merged in pull request #5.
This commit is contained in:
2026-08-15 16:42:06 +10:00
+28 -1
View File
@@ -24,17 +24,44 @@ steps:
memory: 6Gi
cpu: 4
# Stage the internal (Vault) CA into the shared workspace so the buildkit push
# below can verify artifactapi's TLS cert. almalinux9-base already trusts the
# unkin CA (it is the image the RPM release pipelines use to reach artifactapi
# over HTTPS), so its consolidated trust bundle contains the chain we need.
- name: ca-trust
image: git.unkin.net/unkin/almalinux9-base:20260606
commands:
- cp /etc/pki/tls/certs/ca-bundle.crt "$${CI_WORKSPACE}/artifactapi-ca.crt"
depends_on: [publish]
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 256Mi
cpu: 250m
limits:
memory: 512Mi
cpu: 1
# Build the runtime image and push it to the artifactapi local docker registry.
# buildkit_config points buildkit at the staged CA so the TLS handshake with
# artifactapi (Vault-signed cert) verifies; buildx copies the referenced CA
# into the buildkitd container under /etc/buildkit/certs when it creates the
# builder. CI_WORKSPACE is runtime-only so the path is the fixed workspace path.
- name: docker
image: woodpeckerci/plugin-docker-buildx
settings:
registry: artifactapi.k8s.syd1.au.unkin.net
repo: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha
dockerfile: Dockerfile.runtime
buildkit_config: |
[registry."artifactapi.k8s.syd1.au.unkin.net"]
ca = ["/woodpecker/src/git.unkin.net/unkin/jellyfin-ha/artifactapi-ca.crt"]
tags:
- ${CI_COMMIT_TAG}
- latest
depends_on: [publish]
depends_on: [ca-trust]
backend_options:
kubernetes:
serviceAccountName: default