b572f5720b
- Replace GKE_CLUSTER_ENDPOINT placeholder with real endpoint (34.63.89.52) in all three Argo CD Application manifests - Fix gitea GCP SA account_id from 'gitea' (5 chars, too short) to 'gitea-gke' to satisfy GCP's 6-30 char constraint - Update serviceaccount.yaml annotation to match new SA email (gitea-gke@...)
11 lines
403 B
YAML
11 lines
403 B
YAML
apiVersion: v1
|
|
kind: ServiceAccount
|
|
metadata:
|
|
name: gitea
|
|
namespace: gitea
|
|
annotations:
|
|
# Workload Identity — allows the Cloud SQL Auth Proxy sidecar to authenticate
|
|
# to Cloud SQL as the gitea GCP SA without a JSON key file.
|
|
# The GCP SA binding is in servers/gcp/gke.tf (gitea_workload_identity).
|
|
iam.gke.io/gcp-service-account: gitea-gke@neuron-785695.iam.gserviceaccount.com
|