feat: mirror CloudFront-only charts into Harbor #1
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/mirror-workflow"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What this repo is
Charts our cluster cannot take from their upstream location. The workflow packages a chart from its upstream release tag and pushes it to
oci://harbor.grachevko.ru/charts, and the cluster takes it from there with anOCIRepository.Why
Harbor and Vault publish their chart from a git repository, and both chart repositories (
helm.goharbor.io,helm.releases.hashicorp.com) are served by CloudFront: measured from our network,curl -4 https://helm.goharbor.io/index.yamlanswers 200 withContent-Length: 95085and then stalls after 11203 bytes (90 s timeout), while HashiCorp's index answers 403. A HelmRepository source cannot be built from either, so both apps in grachevko/home-ops take their chart from a GitRepository today, and a chart in a git repository is what no cluster-level check can inflate.What lands here
.github/workflows/mirror-charts.yaml: daily schedule plusworkflow_dispatchwithchartandversioninputs; idempotent, a chart version already present in Harbor is skipped before packaging; the push is verified withhelm show chartagainst the registry.README.md: what the repo is for, how to add a chart, the tag rule and which secrets it needs.Verified
helm packageoutput names (harbor-1.19.2.tgz, vault-0.34.1.tgz).zizmor --offlinereports no findings: inputs and secrets reach the script throughenv:, because interpolating them intorun:is a template-injection finding.chartsexists and is public (checked anonymously through its API) and is empty, so the first run has both charts to push. The repository secretsHARBOR_ROBOT_USERandHARBOR_ROBOT_TOKENare already set here and are not read by the workflow at rest.After merge
Run
Mirror Chartsonce withchart: all. Expected: two artifacts (harbor:1.19.2,vault:0.34.1), pullable anonymously, after which grachevko/home-ops can switch both apps to anOCIRepositoryof this mirror and bring the cluster-level chart check.Rollback
Revert the commit: the workflow disappears, nothing else depends on it yet.