ImageUpdateAutomation only lists ImagePolicy objects in its own
namespace (image-automation-controller's getPolicies() scopes the
List() to obj.Namespace, confirmed by reading v1.2.4 source) - the
$imagepolicy marker's namespace:name is only used to match against
that pre-filtered list, not to broaden the search. Our
ImageUpdateAutomation lived in flux-system while its ImagePolicy
lived in hello-app, so the policy was invisible and Setters always
found zero markers to update ("repository up-to-date" forever),
regardless of correct marker syntax/RBAC/policy resolution.
Moved ImageUpdateAutomation into the hello-app namespace (alongside
its ImagePolicy), keeping a cross-namespace sourceRef back to the
flux-system GitRepository. Also fixed the commit messageTemplate,
which used the removed .Updated field (v1.2.4 requires .Changed).
Verified live: Flux pushed commit 0273f15 updating deployment.yaml's
tag on its own, and the cluster rolled out that image without any CI
involvement. Removed the update-deployment-tag CI workaround job
accordingly - it's redundant now and would otherwise race with
Flux's own commits.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GJNvvV3RrvX6TRZGAKEUeY
52 lines
2.3 KiB
YAML
52 lines
2.3 KiB
YAML
name: build-hello-app
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
paths:
|
|
- "apps/hello-app/src/**"
|
|
|
|
jobs:
|
|
build-and-push:
|
|
runs-on: docker
|
|
# kaniko builds the image itself with no daemon and no special host
|
|
# privileges, so the runner host only ever needs a rootless Podman
|
|
# socket to launch this container — never docker.sock, never sudo.
|
|
container:
|
|
image: gcr.io/kaniko-project/executor:debug
|
|
options: --entrypoint ""
|
|
steps:
|
|
# actions/checkout@v4 needs a Node.js runtime, which this minimal
|
|
# kaniko image doesn't have (no package manager to add it either) -
|
|
# fetch the repo as a plain tarball from Forgejo's archive endpoint
|
|
# instead, using the tools that are actually present (wget, tar).
|
|
- name: Checkout (manual - no git/node in this image)
|
|
run: |
|
|
echo "workspace is: ${{ github.workspace }}"
|
|
mkdir -p "${{ github.workspace }}"
|
|
wget --header="Authorization: token ${{ secrets.FORGEJO_TOKEN }}" \
|
|
-O "${{ github.workspace }}/source.tar.gz" \
|
|
"https://git.boglabob.com/${{ github.repository }}/archive/${{ github.sha }}.tar.gz"
|
|
tar -xzf "${{ github.workspace }}/source.tar.gz" --strip-components=1 -C "${{ github.workspace }}"
|
|
rm "${{ github.workspace }}/source.tar.gz"
|
|
|
|
- name: Write registry auth
|
|
run: |
|
|
mkdir -p /kaniko/.docker
|
|
AUTH=$(printf '%s:%s' "${{ vars.FORGEJO_USER }}" "${{ secrets.FORGEJO_TOKEN }}" | base64 -w0)
|
|
printf '{"auths":{"git.boglabob.com":{"auth":"%s"}}}' "$AUTH" > /kaniko/.docker/config.json
|
|
|
|
- name: Inject build info
|
|
run: |
|
|
SHORT_SHA="${GITHUB_SHA::7}"
|
|
BUILD_TIME=$(date -u +%Y-%m-%dT%H:%M:%SZ)
|
|
sed -i "s/__GIT_SHA__/$SHORT_SHA/; s/__BUILD_TIME__/$BUILD_TIME/" apps/hello-app/src/index.html
|
|
|
|
- name: Build and push
|
|
run: |
|
|
TAG="main-${GITHUB_SHA::7}-$(date +%s)"
|
|
/kaniko/executor \
|
|
--context="${{ github.workspace }}/apps/hello-app/src" \
|
|
--dockerfile="${{ github.workspace }}/apps/hello-app/src/Dockerfile" \
|
|
--destination="git.boglabob.com/${{ vars.FORGEJO_ORG }}/hello-app:$TAG" \
|
|
--destination="git.boglabob.com/${{ vars.FORGEJO_ORG }}/hello-app:latest"
|