feat: deploy backstage latest via Flux image automation
yaml / yaml (pull_request) Successful in 23s

Install image-reflector and image-automation controllers, track the digest
behind backstage:latest, and let flux-bot commit digest updates to main.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-10-01 16:05:13 +00:00
co-authored by Claude Opus 5.5
parent 53e2854993
commit 7f5bef829f
10 changed files with 1422 additions and 2 deletions
@@ -0,0 +1,26 @@
# CI pushes only :latest from main; follow the digest behind it. Old digests
# lose their tag and are collected by zot GC, so the deployment must keep
# tracking the current one.
apiVersion: image.toolkit.fluxcd.io/v1
kind: ImageRepository
metadata:
name: backstage
namespace: flux-system
spec:
image: zot.ad.ddupan.top/panxiao81/backstage
interval: 1m
---
apiVersion: image.toolkit.fluxcd.io/v1
kind: ImagePolicy
metadata:
name: backstage
namespace: flux-system
spec:
imageRepositoryRef:
name: backstage
filterTags:
pattern: '^latest$'
policy:
alphabetical: {}
digestReflectionPolicy: Always
interval: 1m
@@ -0,0 +1,19 @@
# Gitea token of the private `flux-bot` user: collaborator with write on
# homelab-infra only, token scoped to write:repository. Stored in OpenBao as
# username/password because that is the basic-auth Secret shape Flux reads.
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: homelab-infra-write
namespace: flux-system
spec:
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
name: openbao
target:
creationPolicy: Owner
name: homelab-infra-write
dataFrom:
- extract:
key: k8s/flux-image-automation
@@ -0,0 +1,15 @@
# Write-capable source used only by ImageUpdateAutomation. The flux-system
# GitRepository stays anonymous and read-only.
apiVersion: source.toolkit.fluxcd.io/v1
kind: GitRepository
metadata:
name: homelab-infra-write
namespace: flux-system
spec:
interval: 10m
ref:
branch: main
secretRef:
name: homelab-infra-write
timeout: 60s
url: http://gitea-http.gitea.svc.cluster.local:3000/panxiao81/homelab-infra.git
@@ -0,0 +1,28 @@
# Commits digest changes straight to main (no PR): dev images are expected to
# deploy as soon as CI pushes them. Scoped to apps/backstage so a stray setter
# elsewhere cannot be rewritten.
apiVersion: image.toolkit.fluxcd.io/v1
kind: ImageUpdateAutomation
metadata:
name: homelab-infra
namespace: flux-system
spec:
interval: 1m
sourceRef:
kind: GitRepository
name: homelab-infra-write
git:
checkout:
ref:
branch: main
commit:
author:
name: flux-bot
email: [email protected]
messageTemplate: |
chore(image): update {{ range .Changed.Changes }}{{ .OldValue }} -> {{ .NewValue }} {{ end }}
push:
branch: main
update:
path: ./apps/backstage
strategy: Setters
@@ -0,0 +1,7 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- external-secret.yaml
- gitrepository.yaml
- imageupdateautomation.yaml
- backstage.yaml