nxtgauge-gitops/apps/forgejo/runner-registry-cert.yaml
Ashwin Kumar Sivakumar c633dd4ea2 Sync forgejo runner-deployment.yaml with live cluster state, drop exposed password
This file had drifted badly from the actual running DaemonSet - the
live cluster already moved off the standalone registry.nxtgauge.com
mirror (now decommissioned, confirmed dead: internal DNS routes it to
Traefik with no matching ingress) onto ci.nxtgauge.com's built-in
registry. That migration was done directly against the cluster and
never reflected back to git, leaving a stale REGISTRY_PASSWORD literal
("Ashwin@2026") in this file that doesn't exist in the live DaemonSet
at all. Replaces the file with the actual live spec and adds the two
ConfigMaps (docker-daemon-config, registry-cert) it depends on, which
were also missing from the repo. Not applying this to the cluster -
the differences are purely cosmetic (mount ordering, stale
annotations) and would trigger a pointless restart of healthy runners.
2026-07-02 19:17:07 +05:30

28 lines
1.4 KiB
YAML

apiVersion: v1
kind: ConfigMap
metadata:
name: registry-cert
namespace: forgejo
data:
registry.crt: |
-----BEGIN CERTIFICATE-----
MIIDXjCCAkagAwIBAgIRAKmaH9FY6+MJkPAoIP/iQkkwDQYJKoZIhvcNAQELBQAw
HzEdMBsGA1UEAxMUVFJBRUZJSyBERUZBVUxUIENFUlQwHhcNMjYwNjE3MTYxMTI2
WhcNMjcwNjE3MTYxMTI2WjAfMR0wGwYDVQQDExRUUkFFRklLIERFRkFVTFQgQ0VS
VDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALOQ4CM5+Vxm/0S3ijLl
nCdrhLO5/YHW4cby7llpn2Sac2fJP4jVnLLrFWITAfvqa5o2oDeHJH9nhpGZI/fg
NQvQu9RZIeq4d8xKoJ4d8qSJ2IVt2JJ+J0cjfg6Wm69DnFGpZGy4Vz4DgEWQ1u20
gnRfFBPBZmo45/pz9UafNtjoOx++C8VeHJRt8RCd0Zx26wePXQbN07+T1tj3MOc+
t92IBn0tQ9g20hiGMgrhi50dPv7HEupbKKy7ZCkBVN/XNHFrvorsCudirFlJZTGw
k2chsTOm2jiIf7xob+Ma1kHncH/NWm9QVieeBUTgrH/Fa2xAHhJ+DuFR0iXW8APj
FnMCAwEAAaOBlDCBkTAOBgNVHQ8BAf8EBAMCA7gwEwYDVR0lBAwwCgYIKwYBBQUH
AwEwDAYDVR0TAQH/BAIwADBcBgNVHREEVTBTglFmZmE0MmE0ZGJhZGJiMTY3ZjUz
YTBiNjA3ZWIyOTQ5OS5iN2QyYWM4ZDlhODRmZDU1MjU5OTc1Y2I0NDM3MWZhZS50
cmFlZmlrLmRlZmF1bHQwDQYJKoZIhvcNAQELBQADggEBAF1RgfSra5RE1zyRLAai
d8tBbzBMAYQVrLKjlYATsnv+d6RQ9ZocdwgLG2OI+roFx1BuLLl/C5aL09UFqCvr
Ab2exdlLMi4IGoVvgUkEtWYwwnbbsL0hR0keR7UE5snc2tT3SlAYLHenzY3kPFhf
Tx0IiS1hdLAQk0TpfRKDYJ7+IV5Mj+aeiG9uK+0je5VcvRSFnrGnackYT7f5yX96
fQ9vwhi7HvWwUlj/8wU/Se//92N7KkddlasyBF77Gdhnoa9qzYyUD1DJHCyfmkaI
RV9jAOWn4RFwpXB7TqNAKnkGWzYBaF5OQc7K/pHgYb+RtC1uNKd1rK3Lyoh56vAy
Y1g=
-----END CERTIFICATE-----