Add CA-baked plugin-docker-buildx image + buildah CI
Bake the internal Vault-PKI CA into a rebuild of woodpeckerci/plugin-docker-buildx so k8s buildx jobs can push to artifactapi's docker-internal registry over TLS. - Dockerfile: copy unkin-ca.crt into /etc/docker/certs.d/<registry>/ca.crt and the system trust store - unkin-ca.crt: vault-ca-cert bundle (root + intermediate) - .woodpecker/build.yaml: PR gate, buildah build-only - .woodpecker/release.yaml: on v* tag, buildah build + credless push to docker-internal with --tls-verify=false (bootstrap)
This commit is contained in:
@@ -0,0 +1,20 @@
|
||||
when:
|
||||
- event: pull_request
|
||||
|
||||
steps:
|
||||
# PR gate: build the CA-baked plugin image only, no push. buildah runs
|
||||
# unprivileged in-cluster, so use the vfs storage driver + chroot isolation.
|
||||
- name: build
|
||||
image: quay.io/buildah/stable
|
||||
commands:
|
||||
- buildah build --isolation chroot --storage-driver vfs -t plugin-docker-buildx:${CI_COMMIT_SHA} .
|
||||
backend_options:
|
||||
kubernetes:
|
||||
serviceAccountName: plugin-docker-buildx
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
@@ -0,0 +1,32 @@
|
||||
when:
|
||||
- event: tag
|
||||
ref: refs/tags/v*
|
||||
|
||||
steps:
|
||||
# Build the CA-baked plugin image and push it to artifactapi's docker-internal
|
||||
# registry. buildah runs unprivileged in-cluster (vfs + chroot isolation).
|
||||
#
|
||||
# Push is credential-less: the in-cluster runner already has push access to the
|
||||
# artifactapi docker-internal registry (same pattern as autobackup-operator /
|
||||
# jellyfin-ha). --tls-verify=false is a deliberate bootstrap: THIS image is what
|
||||
# teaches k8s buildx to trust artifactapi's internal CA, so its own push cannot
|
||||
# yet rely on that trust.
|
||||
- name: release
|
||||
image: quay.io/buildah/stable
|
||||
environment:
|
||||
IMG: artifactapi.k8s.syd1.au.unkin.net/docker-internal/plugin-docker-buildx
|
||||
commands:
|
||||
- buildah build --isolation chroot --storage-driver vfs -t $${IMG}:${CI_COMMIT_TAG} .
|
||||
- buildah tag --storage-driver vfs $${IMG}:${CI_COMMIT_TAG} $${IMG}:latest
|
||||
- buildah push --storage-driver vfs --tls-verify=false $${IMG}:${CI_COMMIT_TAG}
|
||||
- buildah push --storage-driver vfs --tls-verify=false $${IMG}:latest
|
||||
backend_options:
|
||||
kubernetes:
|
||||
serviceAccountName: plugin-docker-buildx
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
Reference in New Issue
Block a user