| Filename | Latest commit message | Latest commit date |
|---|---|---|
| .github/workflows | ||
| README.md | ||
charts
Third-party Helm charts that our cluster cannot take from their upstream location are mirrored here, into our own Harbor, as OCI artifacts.
Why a mirror at all
Harbor and Vault publish their chart from a git repository, and both chart repositories
(helm.goharbor.io, helm.releases.hashicorp.com) are served by CloudFront. Measured from our
network: curl -4 https://helm.goharbor.io/index.yaml answers 200 with an honest
Content-Length: 95085, then stalls the transfer after 11203 bytes (90 s timeout), and
HashiCorp's index answers 403. A HelmRepository source cannot be built from either, so both
apps took their chart from a GitRepository — and a chart in a git repository is exactly what no
cluster-level check can inflate.
What is here
Mirror Charts (.github/workflows/mirror-charts.yaml) packages the chart from the upstream
release tag and pushes it to oci://harbor.grachevko.ru/charts, where the cluster takes it with
an OCIRepository. The workflow runs daily and is idempotent: a chart version that is already
mirrored is skipped before it is packaged. It can also be started by hand with a chart and a
version.
Adding a chart is an entry in the matrix of that workflow. The upstream chart has to be at the root of its repository, the tag has to be a release tag, and the artifact has to be new to Harbor. Nothing is forked: the chart is packaged from the release archive of the upstream tag.
The tag rule
The OCI tag of an artifact is the CHART version, not the release tag: upstream may tag v1.19.2
while Chart.yaml says 1.19.2. An OCIRepository in the cluster and Renovate both reference
the chart version, so a bump has to be the chart version too.
Credentials
Repository secrets HARBOR_ROBOT_USER and HARBOR_ROBOT_TOKEN: a robot account of the charts
project in Harbor with push and pull rights. Harbor requires authentication to push even into a
public project, which is why the push is not anonymous. The values live in the Forgejo repository
settings and never in this repository.
Consumers
grachevko/home-ops — the harbor and vault apps take their chart from oci://harbor.grachevko.ru/charts/<name>.