fix(runner): point GITEA_INSTANCE_URL at GKE Gitea public URL
Gitea moved to GKE. The old in-cluster URL http://gitea.git.svc.cluster.local:3000 now has 0 pods behind it. The runner daemon gets connection refused on every poll. Switch both ExternalSecrets to https://git.neuralplatform.ai. The public URL does not require CF Access tokens — the runner can connect without them. CF_ACCESS_CLIENT_ID/SECRET remain for git operations inside CI job containers (via BASH_ENV init script).
This commit is contained in:
@@ -14,7 +14,7 @@ metadata:
|
||||
name: gitea-runner-secret
|
||||
namespace: ci
|
||||
annotations:
|
||||
force-sync: "2026-05-04-cf-access"
|
||||
force-sync: "2026-05-05-gke-gitea-url"
|
||||
spec:
|
||||
refreshInterval: 1h
|
||||
secretStoreRef:
|
||||
@@ -25,7 +25,7 @@ spec:
|
||||
creationPolicy: Owner
|
||||
template:
|
||||
data:
|
||||
GITEA_INSTANCE_URL: "http://gitea.git.svc.cluster.local:3000"
|
||||
GITEA_INSTANCE_URL: "https://git.neuralplatform.ai"
|
||||
GITEA_RUNNER_REGISTRATION_TOKEN: "{{ .runner_token }}"
|
||||
CF_ACCESS_CLIENT_ID: "{{ .cf_access_client_id }}"
|
||||
CF_ACCESS_CLIENT_SECRET: "{{ .cf_access_client_secret }}"
|
||||
@@ -50,7 +50,7 @@ metadata:
|
||||
name: neuron-technologies-runner-secret
|
||||
namespace: ci
|
||||
annotations:
|
||||
force-sync: "2026-05-04-cf-access"
|
||||
force-sync: "2026-05-05-gke-gitea-url"
|
||||
spec:
|
||||
refreshInterval: 1h
|
||||
secretStoreRef:
|
||||
@@ -61,7 +61,7 @@ spec:
|
||||
creationPolicy: Owner
|
||||
template:
|
||||
data:
|
||||
GITEA_INSTANCE_URL: "http://gitea.git.svc.cluster.local:3000"
|
||||
GITEA_INSTANCE_URL: "https://git.neuralplatform.ai"
|
||||
GITEA_RUNNER_REGISTRATION_TOKEN: "{{ .runner_token }}"
|
||||
CF_ACCESS_CLIENT_ID: "{{ .cf_access_client_id }}"
|
||||
CF_ACCESS_CLIENT_SECRET: "{{ .cf_access_client_secret }}"
|
||||
|
||||
Reference in New Issue
Block a user