No description
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-09-24 17:39:39 +00:00
.github/workflows feat: mirror CloudFront-only charts into Harbor 2026-09-24 17:39:39 +00:00
README.md feat: mirror CloudFront-only charts into Harbor 2026-09-24 17:39:39 +00:00

charts

Third-party Helm charts that our cluster cannot take from their upstream location are mirrored here, into our own Harbor, as OCI artifacts.

Why a mirror at all

Harbor and Vault publish their chart from a git repository, and both chart repositories (helm.goharbor.io, helm.releases.hashicorp.com) are served by CloudFront. Measured from our network: curl -4 https://helm.goharbor.io/index.yaml answers 200 with an honest Content-Length: 95085, then stalls the transfer after 11203 bytes (90 s timeout), and HashiCorp's index answers 403. A HelmRepository source cannot be built from either, so both apps took their chart from a GitRepository — and a chart in a git repository is exactly what no cluster-level check can inflate.

What is here

Mirror Charts (.github/workflows/mirror-charts.yaml) packages the chart from the upstream release tag and pushes it to oci://harbor.grachevko.ru/charts, where the cluster takes it with an OCIRepository. The workflow runs daily and is idempotent: a chart version that is already mirrored is skipped before it is packaged. It can also be started by hand with a chart and a version.

Adding a chart is an entry in the matrix of that workflow. The upstream chart has to be at the root of its repository, the tag has to be a release tag, and the artifact has to be new to Harbor. Nothing is forked: the chart is packaged from the release archive of the upstream tag.

The tag rule

The OCI tag of an artifact is the CHART version, not the release tag: upstream may tag v1.19.2 while Chart.yaml says 1.19.2. An OCIRepository in the cluster and Renovate both reference the chart version, so a bump has to be the chart version too.

Credentials

Repository secrets HARBOR_ROBOT_USER and HARBOR_ROBOT_TOKEN: a robot account of the charts project in Harbor with push and pull rights. Harbor requires authentication to push even into a public project, which is why the push is not anonymous. The values live in the Forgejo repository settings and never in this repository.

Consumers

grachevko/home-ops — the harbor and vault apps take their chart from oci://harbor.grachevko.ru/charts/<name>.