neuron-web: drop unused registry-pull-secret
The registry currently allows anonymous cluster-internal pulls so the imagePullSecrets reference was failing the externalsecret reconcile (secret/data/mudcraft has no registry creds for this app). Pod was pulling fine anyway. If the registry later gets locked down, add a proper externalsecret using the path from secret/data/<app> instead of borrowing mudcraft's.
This commit is contained in:
@@ -22,8 +22,10 @@ spec:
|
|||||||
app: neuron-web
|
app: neuron-web
|
||||||
env: stage
|
env: stage
|
||||||
spec:
|
spec:
|
||||||
imagePullSecrets:
|
# The registry currently allows anonymous reads from the cluster; if we
|
||||||
- name: registry-pull-secret
|
# later flip it to require auth, add a registry-pull-secret here that
|
||||||
|
# ESO populates from Vault. See the mudcraft externalsecret-registry
|
||||||
|
# for the pattern.
|
||||||
containers:
|
containers:
|
||||||
- name: neuron-web
|
- name: neuron-web
|
||||||
image: registry.neuralplatform.ai/neuron-web:dev-dfe41234
|
image: registry.neuralplatform.ai/neuron-web:dev-dfe41234
|
||||||
|
|||||||
@@ -2,7 +2,6 @@ apiVersion: kustomize.config.k8s.io/v1beta1
|
|||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
resources:
|
resources:
|
||||||
- namespace.yaml
|
- namespace.yaml
|
||||||
- registry-pull-secret.yaml
|
|
||||||
- externalsecret.yaml
|
- externalsecret.yaml
|
||||||
- service.yaml
|
- service.yaml
|
||||||
- deployment.yaml
|
- deployment.yaml
|
||||||
|
|||||||
@@ -1,30 +0,0 @@
|
|||||||
# registry-pull-secret — credentials for registry.neuralplatform.ai
|
|
||||||
# pulled from Vault by ESO. Lets the deployment fetch
|
|
||||||
# registry.neuralplatform.ai/neuron-web:* without baking creds into the manifest.
|
|
||||||
apiVersion: external-secrets.io/v1beta1
|
|
||||||
kind: ExternalSecret
|
|
||||||
metadata:
|
|
||||||
name: registry-pull-secret
|
|
||||||
namespace: neuron-web
|
|
||||||
spec:
|
|
||||||
refreshInterval: 1h
|
|
||||||
secretStoreRef:
|
|
||||||
name: vault
|
|
||||||
kind: ClusterSecretStore
|
|
||||||
target:
|
|
||||||
name: registry-pull-secret
|
|
||||||
creationPolicy: Owner
|
|
||||||
template:
|
|
||||||
type: kubernetes.io/dockerconfigjson
|
|
||||||
data:
|
|
||||||
.dockerconfigjson: |
|
|
||||||
{"auths":{"registry.neuralplatform.ai":{"username":"{{ .registry_user }}","password":"{{ .registry_docker_token }}","auth":"{{ list .registry_user .registry_docker_token | join ":" | b64enc }}"}}}
|
|
||||||
data:
|
|
||||||
- secretKey: registry_user
|
|
||||||
remoteRef:
|
|
||||||
key: secret/data/mudcraft
|
|
||||||
property: registry_user
|
|
||||||
- secretKey: registry_docker_token
|
|
||||||
remoteRef:
|
|
||||||
key: secret/data/mudcraft
|
|
||||||
property: registry_docker_token
|
|
||||||
Reference in New Issue
Block a user