c31edc8b83
Replaces the GCE VM runner with a k8s Deployment in the ci namespace on neuron-platform GKE. Uses Docker-in-Docker for build isolation since Autopilot doesn't expose the node socket. Runner token pulled from Secret Manager via ESO + Workload Identity. - servers/gcp/k8s/gitea-runner/: namespace, serviceaccount, external-secrets, deployment manifests (ci namespace, dind sidecar, idempotent registration) - servers/gcp/k8s/argocd-apps/gitea-runner-gke.yaml: Argo CD Application - servers/gcp/gitea-runner.tf: gitea-runner-gke GCP SA with secretAccessor on gitea-runner-token, Workload Identity binding for ci/gitea-runner, artifactregistry.reader for pulling ci-base image
12 lines
463 B
YAML
12 lines
463 B
YAML
apiVersion: v1
|
|
kind: ServiceAccount
|
|
metadata:
|
|
name: gitea-runner
|
|
namespace: ci
|
|
annotations:
|
|
# Workload Identity — allows ESO (and optionally the runner pod) to
|
|
# authenticate to GCP Secret Manager as the gitea-runner-gke GCP SA
|
|
# without a JSON key file.
|
|
# The GCP SA binding is in servers/gcp/gitea-runner.tf (gitea_runner_gke_workload_identity).
|
|
iam.gke.io/gcp-service-account: gitea-runner-gke@neuron-785695.iam.gserviceaccount.com
|