feat: deploy backstage latest via Flux image automation
yaml / yaml (pull_request) Successful in 23s
yaml / yaml (pull_request) Successful in 23s
Install image-reflector and image-automation controllers, track the digest behind backstage:latest, and let flux-bot commit digest updates to main. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
@@ -18,3 +18,13 @@ OCI digest 固定镜像。
|
|||||||
|
|
||||||
Flux 等待 ExternalSecret 和 Deployment 就绪;任何前置缺失都会使该
|
Flux 等待 ExternalSecret 和 Deployment 就绪;任何前置缺失都会使该
|
||||||
Kustomization 保持 NotReady,而不会回退到明文 Secret。
|
Kustomization 保持 NotReady,而不会回退到明文 Secret。
|
||||||
|
|
||||||
|
## 镜像更新
|
||||||
|
|
||||||
|
`panxiao81/backstage` 的 CI 在 main push 后只推送 `:latest`。
|
||||||
|
`platform/flux-image-automation` 跟踪 `latest` 背后的 digest,由 `flux-bot`
|
||||||
|
直接提交到本仓库 main,不经过 PR。`deployment.yaml` 中 image 行的
|
||||||
|
`$imagepolicy` 注释是 setter 标记,删除后自动更新会静默停止。
|
||||||
|
|
||||||
|
旧 digest 失去 tag 后会被 zot GC 回收(24h),因此不要把 Deployment 手工固定到
|
||||||
|
一个已不是 `latest` 的 digest 并长期保留。
|
||||||
|
|||||||
@@ -27,7 +27,7 @@ spec:
|
|||||||
type: RuntimeDefault
|
type: RuntimeDefault
|
||||||
containers:
|
containers:
|
||||||
- name: backstage
|
- name: backstage
|
||||||
image: zot.ad.ddupan.top/panxiao81/backstage@sha256:008a3ccf832c9ee061ef03766022789a7539bd9d001a658af2e9f3ff59a9a5cc
|
image: zot.ad.ddupan.top/panxiao81/backstage:latest@sha256:008a3ccf832c9ee061ef03766022789a7539bd9d001a658af2e9f3ff59a9a5cc # {"$imagepolicy": "flux-system:backstage"}
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
env:
|
env:
|
||||||
- name: BACKSTAGE_BASE_URL
|
- name: BACKSTAGE_BASE_URL
|
||||||
|
|||||||
@@ -0,0 +1,16 @@
|
|||||||
|
apiVersion: kustomize.toolkit.fluxcd.io/v1
|
||||||
|
kind: Kustomization
|
||||||
|
metadata:
|
||||||
|
name: flux-image-automation
|
||||||
|
namespace: flux-system
|
||||||
|
spec:
|
||||||
|
dependsOn:
|
||||||
|
- name: external-secrets
|
||||||
|
interval: 10m
|
||||||
|
path: ./platform/flux-image-automation
|
||||||
|
prune: true
|
||||||
|
sourceRef:
|
||||||
|
kind: GitRepository
|
||||||
|
name: flux-system
|
||||||
|
timeout: 5m
|
||||||
|
wait: true
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -8,6 +8,7 @@ resources:
|
|||||||
- apps/external-secrets.yaml
|
- apps/external-secrets.yaml
|
||||||
- apps/gitea.yaml
|
- apps/gitea.yaml
|
||||||
- apps/backstage.yaml
|
- apps/backstage.yaml
|
||||||
|
- apps/flux-image-automation.yaml
|
||||||
- apps/http-echo.yaml
|
- apps/http-echo.yaml
|
||||||
- apps/openebs.yaml
|
- apps/openebs.yaml
|
||||||
- apps/nats.yaml
|
- apps/nats.yaml
|
||||||
|
|||||||
@@ -0,0 +1,26 @@
|
|||||||
|
# CI pushes only :latest from main; follow the digest behind it. Old digests
|
||||||
|
# lose their tag and are collected by zot GC, so the deployment must keep
|
||||||
|
# tracking the current one.
|
||||||
|
apiVersion: image.toolkit.fluxcd.io/v1
|
||||||
|
kind: ImageRepository
|
||||||
|
metadata:
|
||||||
|
name: backstage
|
||||||
|
namespace: flux-system
|
||||||
|
spec:
|
||||||
|
image: zot.ad.ddupan.top/panxiao81/backstage
|
||||||
|
interval: 1m
|
||||||
|
---
|
||||||
|
apiVersion: image.toolkit.fluxcd.io/v1
|
||||||
|
kind: ImagePolicy
|
||||||
|
metadata:
|
||||||
|
name: backstage
|
||||||
|
namespace: flux-system
|
||||||
|
spec:
|
||||||
|
imageRepositoryRef:
|
||||||
|
name: backstage
|
||||||
|
filterTags:
|
||||||
|
pattern: '^latest$'
|
||||||
|
policy:
|
||||||
|
alphabetical: {}
|
||||||
|
digestReflectionPolicy: Always
|
||||||
|
interval: 1m
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
# Gitea token of the private `flux-bot` user: collaborator with write on
|
||||||
|
# homelab-infra only, token scoped to write:repository. Stored in OpenBao as
|
||||||
|
# username/password because that is the basic-auth Secret shape Flux reads.
|
||||||
|
apiVersion: external-secrets.io/v1
|
||||||
|
kind: ExternalSecret
|
||||||
|
metadata:
|
||||||
|
name: homelab-infra-write
|
||||||
|
namespace: flux-system
|
||||||
|
spec:
|
||||||
|
refreshInterval: 1h
|
||||||
|
secretStoreRef:
|
||||||
|
kind: ClusterSecretStore
|
||||||
|
name: openbao
|
||||||
|
target:
|
||||||
|
creationPolicy: Owner
|
||||||
|
name: homelab-infra-write
|
||||||
|
dataFrom:
|
||||||
|
- extract:
|
||||||
|
key: k8s/flux-image-automation
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
# Write-capable source used only by ImageUpdateAutomation. The flux-system
|
||||||
|
# GitRepository stays anonymous and read-only.
|
||||||
|
apiVersion: source.toolkit.fluxcd.io/v1
|
||||||
|
kind: GitRepository
|
||||||
|
metadata:
|
||||||
|
name: homelab-infra-write
|
||||||
|
namespace: flux-system
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
ref:
|
||||||
|
branch: main
|
||||||
|
secretRef:
|
||||||
|
name: homelab-infra-write
|
||||||
|
timeout: 60s
|
||||||
|
url: http://gitea-http.gitea.svc.cluster.local:3000/panxiao81/homelab-infra.git
|
||||||
@@ -0,0 +1,28 @@
|
|||||||
|
# Commits digest changes straight to main (no PR): dev images are expected to
|
||||||
|
# deploy as soon as CI pushes them. Scoped to apps/backstage so a stray setter
|
||||||
|
# elsewhere cannot be rewritten.
|
||||||
|
apiVersion: image.toolkit.fluxcd.io/v1
|
||||||
|
kind: ImageUpdateAutomation
|
||||||
|
metadata:
|
||||||
|
name: homelab-infra
|
||||||
|
namespace: flux-system
|
||||||
|
spec:
|
||||||
|
interval: 1m
|
||||||
|
sourceRef:
|
||||||
|
kind: GitRepository
|
||||||
|
name: homelab-infra-write
|
||||||
|
git:
|
||||||
|
checkout:
|
||||||
|
ref:
|
||||||
|
branch: main
|
||||||
|
commit:
|
||||||
|
author:
|
||||||
|
name: flux-bot
|
||||||
|
email: [email protected]
|
||||||
|
messageTemplate: |
|
||||||
|
chore(image): update {{ range .Changed.Changes }}{{ .OldValue }} -> {{ .NewValue }} {{ end }}
|
||||||
|
push:
|
||||||
|
branch: main
|
||||||
|
update:
|
||||||
|
path: ./apps/backstage
|
||||||
|
strategy: Setters
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- external-secret.yaml
|
||||||
|
- gitrepository.yaml
|
||||||
|
- imageupdateautomation.yaml
|
||||||
|
- backstage.yaml
|
||||||
Reference in New Issue
Block a user