1 Commits

Author SHA1 Message Date
unkin-agent bc6d2b218d feat(github): allowlist jellyfin-plugin-sso release assets
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
jellyfin-ha bakes the SSO auth plugin at image build time, but the CI
build network cannot reach github directly. Route it through the
artifactapi github proxy by allowlisting the SSO plugin release asset.
2026-08-26 23:32:07 +10:00
9 changed files with 4 additions and 82 deletions
+1 -3
View File
@@ -1,12 +1,10 @@
when:
- event: push
branch: main
- event: manual
branch: main
steps:
- name: apply
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/opentofu:0.1.0
image: git.unkin.net/unkin/almalinux9-opentofu:20260606
environment:
VAULT_AUTH_METHOD: kubernetes
VAULT_VERSION: "1.20.0"
+1 -1
View File
@@ -3,7 +3,7 @@ when:
steps:
- name: plan
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/opentofu:0.1.0
image: git.unkin.net/unkin/almalinux9-opentofu:20260606
environment:
VAULT_AUTH_METHOD: kubernetes
VAULT_VERSION: "1.20.0"
+1 -1
View File
@@ -3,7 +3,7 @@ when:
steps:
- name: pre-commit
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/opentofu:0.1.0
image: git.unkin.net/unkin/almalinux9-opentofu:20260606
commands:
- uvx pre-commit run --all-files
backend_options:
@@ -1,2 +0,0 @@
---
description: "Jellyfin plugin zips built in-house (JPRM release archives published on tag)"
-2
View File
@@ -1,2 +0,0 @@
---
description: "Neovim plugin release archives (<plugin>-<version>.zip) installed by arti-pack"
-6
View File
@@ -1,6 +0,0 @@
base_url: https://git.unkin.net
description: Internal Gitea unkin tag source archives
immutable_ttl: 0
mutable_ttl: 7200
patterns:
- "^unkin/[^/]+/archive/refs/tags/[^/]+\\.zip$"
+1 -51
View File
@@ -3,71 +3,25 @@ description: GitHub releases and files
immutable_ttl: 0
mutable_ttl: 7200
mutable_patterns:
# Branch archives of tagless Neovim plugins; a branch ref moves, so these
# revalidate on mutable_ttl instead of caching immutably.
- "^HampusHauffman/block\\.nvim/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-buffer/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-nvim-lsp/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-nvim-lsp-signature-help/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-nvim-lua/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-path/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-vsnip/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/vim-vsnip/archive/refs/heads/master\\.(zip|tar\\.gz)$"
- "^junegunn/gv\\.vim/archive/refs/heads/master\\.(zip|tar\\.gz)$"
- "^jvirtanen/vim-hcl/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^Mofiqul/dracula\\.nvim/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^numToStr/FTerm\\.nvim/archive/refs/heads/master\\.(zip|tar\\.gz)$"
- "^qvalentin/helm-ls\\.nvim/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^rafamadriz/friendly-snippets/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- ".*/archive/refs/heads/.*.tar.gz$"
- "stalwartlabs/webadmin/releases/latest/download/webadmin.zip$"
# iplocate IP databases (Git-LFS; the /raw/ path redirects to the LFS media host).
- "iplocate/ip-address-databases/raw/.*/ip-to-asn/.*"
- "iplocate/ip-address-databases/raw/.*/ip-to-country/.*"
patterns:
# Branch archives of Neovim plugins that publish no tags. patterns is a
# strict allowlist checked before mutable_patterns, so each repo must be
# listed in both. Anchored per repo: matching is a substring search, so an
# unanchored entry would also admit evil/<owner>/<repo>/....
- "^HampusHauffman/block\\.nvim/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-buffer/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-nvim-lsp/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-nvim-lsp-signature-help/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-nvim-lua/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-path/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-vsnip/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/vim-vsnip/archive/refs/heads/master\\.(zip|tar\\.gz)$"
- "^junegunn/gv\\.vim/archive/refs/heads/master\\.(zip|tar\\.gz)$"
- "^jvirtanen/vim-hcl/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^Mofiqul/dracula\\.nvim/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^numToStr/FTerm\\.nvim/archive/refs/heads/master\\.(zip|tar\\.gz)$"
- "^qvalentin/helm-ls\\.nvim/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^rafamadriz/friendly-snippets/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- ".*/archive/refs/tags/.*.tar.gz$"
- ".*/archive/refs/tags/.*\\.zip$"
- "9p4/jellyfin-plugin-sso/.*/sso-authentication_.*.zip$"
- "ahmetb/kubectl-tree/.*/kubectl-tree_.*_checksums.txt$"
- "ahmetb/kubectl-tree/.*/kubectl-tree_.*_linux_amd64.tar.gz$"
- "ahmetb/kubectx/.*/kubectx_.*_linux_x86_64.tar.gz$"
- "ahmetb/kubectx/.*/kubens_.*_linux_x86_64.tar.gz$"
- "apple/foundationdb/.*/libfdb_c.x86_64.so$"
- "argoproj/argo-cd/.*/argocd-linux-amd64$"
- "argoproj/argo-cd/.*/cli_checksums.txt$"
- "astral-sh/ruff/.*/ruff-x86_64-unknown-linux-gnu.tar.gz$"
- "astral-sh/uv/.*/uv-x86_64-unknown-linux-gnu.tar.gz$"
- "camptocamp/prometheus-puppetdb-exporter/.*/prometheus-puppetdb-exporter-.*.linux-amd64.tar.gz$"
- "cert-manager/cmctl/.*/checksums.txt$"
- "cert-manager/cmctl/.*/cmctl_linux_amd64$"
- "cloudnative-pg/cloudnative-pg/.*/cnpg-.*-checksums.txt$"
- "cloudnative-pg/cloudnative-pg/.*/kubectl-cnpg_.*_linux_x86_64.tar.gz$"
- "coder/code-server/.*/code-server-.*-amd64.rpm$"
- "containernetworking/plugins/.*/cni-plugins-linux-amd64-.*.tgz"
- "dandavison/delta/.*/delta-.*-x86_64-unknown-linux-musl.tar.gz$"
- "ducaale/xh/.*/xh-.*-x86_64-unknown-linux-musl.tar.gz$"
- "elsesiy/kubectl-view-secret/.*/kubectl-view-secret_.*_checksums.txt$"
- "elsesiy/kubectl-view-secret/.*/kubectl-view-secret_.*_linux_amd64.tar.gz$"
- "etcd-io/etcd/.*/etcd-.*-linux-amd64.tar.gz$"
- "envoyproxy/envoy/.*/envoy-.*-linux-x86_64$"
- "envoyproxy/envoy/.*/checksums.txt.asc$"
- "getsops/sops/.*/sops-v.*\\.linux\\.amd64$"
- "grafana/jsonnet-language-server/.*/jsonnet-language-server_.*_linux_amd64$"
- "gruntwork-io/boilerplate/.*/boilerplate_linux_amd64$"
@@ -80,10 +34,6 @@ patterns:
- "iplocate/ip-address-databases/raw/.*/ip-to-asn/.*"
- "iplocate/ip-address-databases/raw/.*/ip-to-country/.*"
- "jesseduffield/lazydocker/.*/lazydocker_.*_Linux_x86_64.tar.gz$"
- "JohnnyMorganz/StyLua/.*/stylua-linux-x86_64\\.zip$"
- "JohnnyMorganz/StyLua/.*/stylua-linux-x86_64-musl\\.zip$"
- "k8up-io/k8up/.*/checksums.txt$"
- "k8up-io/k8up/.*/k8up_.*_linux_amd64.tar.gz$"
- "kubecolor/kubecolor/.*/kubecolor_.*_linux_amd64.tar.gz$"
- "kubernetes-sigs/gateway-api/.*/standard-install.yaml$"
- "kubernetes-sigs/kustomize/.*/kustomize_.*_linux_amd64.tar.gz$"
-10
View File
@@ -2,18 +2,8 @@ base_url: https://raw.githubusercontent.com
description: GitHub User Content
immutable_ttl: 0
mutable_ttl: 7200
mutable_patterns:
# victoria-metrics-k8s-stack dashboard sources; branch refs move, so these
# revalidate on mutable_ttl instead of caching immutably.
- "^dotdc/grafana-dashboards-kubernetes/master/dashboards/k8s-[a-z-]+\\.json$"
- "^monitoring-mixins/website/master/assets/etcd/dashboards/etcd\\.json$"
- "^prometheus-operator/kube-prometheus/main/manifests/grafana-dashboardDefinitions\\.yaml$"
patterns:
- "argoproj/argo-cd/.*.yaml$"
- "datreeio/CRDs-catalog/main/.*.json$"
- "kubernetes/kubernetes/.*.json$"
- "yannh/kubernetes-json-schema/master/.*.json$"
# victoria-metrics-k8s-stack dashboard sources (also in mutable_patterns).
- "^dotdc/grafana-dashboards-kubernetes/master/dashboards/k8s-[a-z-]+\\.json$"
- "^monitoring-mixins/website/master/assets/etcd/dashboards/etcd\\.json$"
- "^prometheus-operator/kube-prometheus/main/manifests/grafana-dashboardDefinitions\\.yaml$"
-6
View File
@@ -1,6 +0,0 @@
base_url: https://repo.jellyfin.org
description: Jellyfin official plugin repository
immutable_ttl: 0
mutable_ttl: 7200
patterns:
- "files/plugin/ldap-authentication/ldap-authentication_.*.zip$"