neuron-web: drop unused registry-pull-secret

The registry currently allows anonymous cluster-internal pulls so the
imagePullSecrets reference was failing the externalsecret reconcile
(secret/data/mudcraft has no registry creds for this app). Pod was
pulling fine anyway. If the registry later gets locked down, add a
proper externalsecret using the path from secret/data/<app> instead of
borrowing mudcraft's.
This commit is contained in:
Will Anderson
2026-05-03 10:49:24 -05:00
parent 2f5fdd163e
commit 73004fa287
3 changed files with 4 additions and 33 deletions
@@ -22,8 +22,10 @@ spec:
app: neuron-web
env: stage
spec:
imagePullSecrets:
- name: registry-pull-secret
# The registry currently allows anonymous reads from the cluster; if we
# later flip it to require auth, add a registry-pull-secret here that
# ESO populates from Vault. See the mudcraft externalsecret-registry
# for the pattern.
containers:
- name: neuron-web
image: registry.neuralplatform.ai/neuron-web:dev-dfe41234
@@ -2,7 +2,6 @@ apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- namespace.yaml
- registry-pull-secret.yaml
- externalsecret.yaml
- service.yaml
- deployment.yaml
@@ -1,30 +0,0 @@
# registry-pull-secret — credentials for registry.neuralplatform.ai
# pulled from Vault by ESO. Lets the deployment fetch
# registry.neuralplatform.ai/neuron-web:* without baking creds into the manifest.
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: registry-pull-secret
namespace: neuron-web
spec:
refreshInterval: 1h
secretStoreRef:
name: vault
kind: ClusterSecretStore
target:
name: registry-pull-secret
creationPolicy: Owner
template:
type: kubernetes.io/dockerconfigjson
data:
.dockerconfigjson: |
{"auths":{"registry.neuralplatform.ai":{"username":"{{ .registry_user }}","password":"{{ .registry_docker_token }}","auth":"{{ list .registry_user .registry_docker_token | join ":" | b64enc }}"}}}
data:
- secretKey: registry_user
remoteRef:
key: secret/data/mudcraft
property: registry_user
- secretKey: registry_docker_token
remoteRef:
key: secret/data/mudcraft
property: registry_docker_token