Reusable repo template for homelab services on git.aridgwayweb.com. Bakes in (all verified live on armistace/wedding-photos): - Hard commit guard: shared pre-commit hook (git config core.hooksPath ~/dev/git-hooks) + master branch protection (push whitelist [armistace], merge whitelist [hermes, armistace]). - Gitea Actions CI (.gitea/workflows/build_push.yml): test + build-deploy, persistent remote buildkit cache, registry push, idempotent deploy that preserves hand-provisioned Secrets, cluster injection from repo secrets/vars via scripts/reconcile-cluster-inject.sh. - Persistent buildkit cache (ci/buildkit/): single-replica Longhorn backing. - scripts/reconcile-cluster-inject.sh: reconcile live Secret/ConfigMap from Gitea secrets/vars without clobbering hand-provisioned values. - RUNBOOK.md: handoff-complete ops doc. Placeholders (<APP> <OWNER> <NS> <KEY_*>) are filled per-service on repo creation.
27 lines
997 B
YAML
27 lines
997 B
YAML
# NetworkPolicy: only the Gitea action runners may reach the buildkit daemon.
|
|
# Closes the reviewer's High: buildkit listens on plaintext tcp:1234 with no
|
|
# auth — without this policy ANY cluster pod could submit arbitrary build
|
|
# requests (lateral-movement / resource-abuse surface). Restricting ingress to
|
|
# the gitea-runner namespace (where the runners live) removes that exposure.
|
|
# Homelab note: full TLS+auth on the buildkit socket is deferred (documented) —
|
|
# the runner and daemon are on the private cluster network; the policy closes the
|
|
# pod-to-pod surface that TLS alone wouldn't.
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: buildkit-allow-runner-only
|
|
namespace: gitea-runner
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
app: buildkit
|
|
policyTypes: ["Ingress"]
|
|
ingress:
|
|
- from:
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: gitea-runner
|
|
ports:
|
|
- protocol: TCP
|
|
port: 1234
|