Move portal workloads to registry digests
This commit is contained in:
parent
52b57c99f7
commit
f854969a01
6 changed files with 42 additions and 17 deletions
|
|
@ -6,9 +6,11 @@ no public Ingress until the KeyCape authorization-code/PKCE edge and
|
|||
must remain impossible because the application accepts identity only from a
|
||||
trusted edge marker plus verified claims.
|
||||
|
||||
For the current pre-production bootstrap the image is imported directly into
|
||||
k3s and uses `imagePullPolicy: Never`. Replace it with the immutable Forgejo
|
||||
OCI digest after the OpenBao package-publisher lane is available.
|
||||
The portal image is published through the activity-core workload-scoped
|
||||
Forgejo package credential and deployed from
|
||||
`forgejo.coulomb.social/coulomb/user-engine` by immutable digest. The public
|
||||
package read was verified without an image pull Secret; publishing still uses
|
||||
the ExternalSecret-backed credential and temporary client state.
|
||||
|
||||
The CloudNativePG operator creates `user-engine-pg-app`, including its `uri`
|
||||
field. `user-engine-runtime` contains only the generated edge marker and must
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue