Add CA-baked plugin-docker-buildx image + buildah CI

Bake the internal Vault-PKI CA into a rebuild of
woodpeckerci/plugin-docker-buildx so k8s buildx jobs can push to
artifactapi's docker-internal registry over TLS.

- Dockerfile: copy unkin-ca.crt into /etc/docker/certs.d/<registry>/ca.crt
  and the system trust store
- unkin-ca.crt: vault-ca-cert bundle (root + intermediate)
- .woodpecker/build.yaml: PR gate, buildah build-only
- .woodpecker/release.yaml: on v* tag, buildah build + credless push to
  docker-internal with --tls-verify=false (bootstrap)
This commit is contained in:
2026-08-15 15:22:11 +10:00
parent 080084c4fd
commit b13a8cec78
5 changed files with 128 additions and 1 deletions
+20
View File
@@ -0,0 +1,20 @@
when:
- event: pull_request
steps:
# PR gate: build the CA-baked plugin image only, no push. buildah runs
# unprivileged in-cluster, so use the vfs storage driver + chroot isolation.
- name: build
image: quay.io/buildah/stable
commands:
- buildah build --isolation chroot --storage-driver vfs -t plugin-docker-buildx:${CI_COMMIT_SHA} .
backend_options:
kubernetes:
serviceAccountName: plugin-docker-buildx
resources:
requests:
memory: 512Mi
cpu: 1
limits:
memory: 2Gi
cpu: 2
+32
View File
@@ -0,0 +1,32 @@
when:
- event: tag
ref: refs/tags/v*
steps:
# Build the CA-baked plugin image and push it to artifactapi's docker-internal
# registry. buildah runs unprivileged in-cluster (vfs + chroot isolation).
#
# Push is credential-less: the in-cluster runner already has push access to the
# artifactapi docker-internal registry (same pattern as autobackup-operator /
# jellyfin-ha). --tls-verify=false is a deliberate bootstrap: THIS image is what
# teaches k8s buildx to trust artifactapi's internal CA, so its own push cannot
# yet rely on that trust.
- name: release
image: quay.io/buildah/stable
environment:
IMG: artifactapi.k8s.syd1.au.unkin.net/docker-internal/plugin-docker-buildx
commands:
- buildah build --isolation chroot --storage-driver vfs -t $${IMG}:${CI_COMMIT_TAG} .
- buildah tag --storage-driver vfs $${IMG}:${CI_COMMIT_TAG} $${IMG}:latest
- buildah push --storage-driver vfs --tls-verify=false $${IMG}:${CI_COMMIT_TAG}
- buildah push --storage-driver vfs --tls-verify=false $${IMG}:latest
backend_options:
kubernetes:
serviceAccountName: plugin-docker-buildx
resources:
requests:
memory: 512Mi
cpu: 1
limits:
memory: 2Gi
cpu: 2