ci: move authentik_url ClusterIP override into woodpecker only
Keep local/default terragrunt runs pointed at the real public URL; set the goauthentik#954 ClusterIP workaround via TF_VAR_authentik_url in the CI environment blocks instead of as a terragrunt input.
This commit is contained in:
@@ -8,6 +8,8 @@ steps:
|
||||
environment:
|
||||
VAULT_AUTH_METHOD: kubernetes
|
||||
VAULT_VERSION: "1.20.0"
|
||||
# ClusterIP + sessionAffinity pins CI to one replica (goauthentik#954).
|
||||
TF_VAR_authentik_url: http://authentik-server.authentik.svc.cluster.local
|
||||
commands:
|
||||
- curl -fsSL -o /tmp/vault.zip "https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/hashicorp-releases/vault/$${VAULT_VERSION}/vault_$${VAULT_VERSION}_linux_amd64.zip" && python3 -m zipfile -e /tmp/vault.zip /tmp/ && install -m0755 /tmp/vault /usr/local/bin/vault && rm -f /tmp/vault.zip /tmp/vault /tmp/LICENSE.txt
|
||||
- make plan
|
||||
|
||||
@@ -7,6 +7,8 @@ steps:
|
||||
environment:
|
||||
VAULT_AUTH_METHOD: kubernetes
|
||||
VAULT_VERSION: "1.20.0"
|
||||
# ClusterIP + sessionAffinity pins CI to one replica (goauthentik#954).
|
||||
TF_VAR_authentik_url: http://authentik-server.authentik.svc.cluster.local
|
||||
commands:
|
||||
- curl -fsSL -o /tmp/vault.zip "https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/hashicorp-releases/vault/$${VAULT_VERSION}/vault_$${VAULT_VERSION}_linux_amd64.zip" && python3 -m zipfile -e /tmp/vault.zip /tmp/ && install -m0755 /tmp/vault /usr/local/bin/vault && rm -f /tmp/vault.zip /tmp/vault /tmp/LICENSE.txt
|
||||
- make plan
|
||||
|
||||
Reference in New Issue
Block a user