infra: wire GKE cluster endpoint and fix gitea SA account_id

- Replace GKE_CLUSTER_ENDPOINT placeholder with real endpoint (34.63.89.52)
  in all three Argo CD Application manifests
- Fix gitea GCP SA account_id from 'gitea' (5 chars, too short) to 'gitea-gke'
  to satisfy GCP's 6-30 char constraint
- Update serviceaccount.yaml annotation to match new SA email (gitea-gke@...)
This commit is contained in:
Will Anderson
2026-05-04 21:56:06 -05:00
parent 4ef5e99f31
commit b572f5720b
5 changed files with 5 additions and 5 deletions
+1 -1
View File
@@ -7,4 +7,4 @@ metadata:
# Workload Identity — allows the Cloud SQL Auth Proxy sidecar to authenticate
# to Cloud SQL as the gitea GCP SA without a JSON key file.
# The GCP SA binding is in servers/gcp/gke.tf (gitea_workload_identity).
iam.gke.io/gcp-service-account: gitea@neuron-785695.iam.gserviceaccount.com
iam.gke.io/gcp-service-account: gitea-gke@neuron-785695.iam.gserviceaccount.com