feat: deploy backstage latest via Flux image automation
yaml / yaml (pull_request) Successful in 23s
yaml / yaml (pull_request) Successful in 23s
Install image-reflector and image-automation controllers, track the digest behind backstage:latest, and let flux-bot commit digest updates to main. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
@@ -18,3 +18,13 @@ OCI digest 固定镜像。
|
||||
|
||||
Flux 等待 ExternalSecret 和 Deployment 就绪;任何前置缺失都会使该
|
||||
Kustomization 保持 NotReady,而不会回退到明文 Secret。
|
||||
|
||||
## 镜像更新
|
||||
|
||||
`panxiao81/backstage` 的 CI 在 main push 后只推送 `:latest`。
|
||||
`platform/flux-image-automation` 跟踪 `latest` 背后的 digest,由 `flux-bot`
|
||||
直接提交到本仓库 main,不经过 PR。`deployment.yaml` 中 image 行的
|
||||
`$imagepolicy` 注释是 setter 标记,删除后自动更新会静默停止。
|
||||
|
||||
旧 digest 失去 tag 后会被 zot GC 回收(24h),因此不要把 Deployment 手工固定到
|
||||
一个已不是 `latest` 的 digest 并长期保留。
|
||||
|
||||
@@ -27,7 +27,7 @@ spec:
|
||||
type: RuntimeDefault
|
||||
containers:
|
||||
- name: backstage
|
||||
image: zot.ad.ddupan.top/panxiao81/backstage@sha256:008a3ccf832c9ee061ef03766022789a7539bd9d001a658af2e9f3ff59a9a5cc
|
||||
image: zot.ad.ddupan.top/panxiao81/backstage:latest@sha256:008a3ccf832c9ee061ef03766022789a7539bd9d001a658af2e9f3ff59a9a5cc # {"$imagepolicy": "flux-system:backstage"}
|
||||
imagePullPolicy: IfNotPresent
|
||||
env:
|
||||
- name: BACKSTAGE_BASE_URL
|
||||
|
||||
@@ -0,0 +1,16 @@
|
||||
apiVersion: kustomize.toolkit.fluxcd.io/v1
|
||||
kind: Kustomization
|
||||
metadata:
|
||||
name: flux-image-automation
|
||||
namespace: flux-system
|
||||
spec:
|
||||
dependsOn:
|
||||
- name: external-secrets
|
||||
interval: 10m
|
||||
path: ./platform/flux-image-automation
|
||||
prune: true
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
name: flux-system
|
||||
timeout: 5m
|
||||
wait: true
|
||||
File diff suppressed because it is too large
Load Diff
@@ -8,6 +8,7 @@ resources:
|
||||
- apps/external-secrets.yaml
|
||||
- apps/gitea.yaml
|
||||
- apps/backstage.yaml
|
||||
- apps/flux-image-automation.yaml
|
||||
- apps/http-echo.yaml
|
||||
- apps/openebs.yaml
|
||||
- apps/nats.yaml
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
# CI pushes only :latest from main; follow the digest behind it. Old digests
|
||||
# lose their tag and are collected by zot GC, so the deployment must keep
|
||||
# tracking the current one.
|
||||
apiVersion: image.toolkit.fluxcd.io/v1
|
||||
kind: ImageRepository
|
||||
metadata:
|
||||
name: backstage
|
||||
namespace: flux-system
|
||||
spec:
|
||||
image: zot.ad.ddupan.top/panxiao81/backstage
|
||||
interval: 1m
|
||||
---
|
||||
apiVersion: image.toolkit.fluxcd.io/v1
|
||||
kind: ImagePolicy
|
||||
metadata:
|
||||
name: backstage
|
||||
namespace: flux-system
|
||||
spec:
|
||||
imageRepositoryRef:
|
||||
name: backstage
|
||||
filterTags:
|
||||
pattern: '^latest$'
|
||||
policy:
|
||||
alphabetical: {}
|
||||
digestReflectionPolicy: Always
|
||||
interval: 1m
|
||||
@@ -0,0 +1,19 @@
|
||||
# Gitea token of the private `flux-bot` user: collaborator with write on
|
||||
# homelab-infra only, token scoped to write:repository. Stored in OpenBao as
|
||||
# username/password because that is the basic-auth Secret shape Flux reads.
|
||||
apiVersion: external-secrets.io/v1
|
||||
kind: ExternalSecret
|
||||
metadata:
|
||||
name: homelab-infra-write
|
||||
namespace: flux-system
|
||||
spec:
|
||||
refreshInterval: 1h
|
||||
secretStoreRef:
|
||||
kind: ClusterSecretStore
|
||||
name: openbao
|
||||
target:
|
||||
creationPolicy: Owner
|
||||
name: homelab-infra-write
|
||||
dataFrom:
|
||||
- extract:
|
||||
key: k8s/flux-image-automation
|
||||
@@ -0,0 +1,15 @@
|
||||
# Write-capable source used only by ImageUpdateAutomation. The flux-system
|
||||
# GitRepository stays anonymous and read-only.
|
||||
apiVersion: source.toolkit.fluxcd.io/v1
|
||||
kind: GitRepository
|
||||
metadata:
|
||||
name: homelab-infra-write
|
||||
namespace: flux-system
|
||||
spec:
|
||||
interval: 10m
|
||||
ref:
|
||||
branch: main
|
||||
secretRef:
|
||||
name: homelab-infra-write
|
||||
timeout: 60s
|
||||
url: http://gitea-http.gitea.svc.cluster.local:3000/panxiao81/homelab-infra.git
|
||||
@@ -0,0 +1,28 @@
|
||||
# Commits digest changes straight to main (no PR): dev images are expected to
|
||||
# deploy as soon as CI pushes them. Scoped to apps/backstage so a stray setter
|
||||
# elsewhere cannot be rewritten.
|
||||
apiVersion: image.toolkit.fluxcd.io/v1
|
||||
kind: ImageUpdateAutomation
|
||||
metadata:
|
||||
name: homelab-infra
|
||||
namespace: flux-system
|
||||
spec:
|
||||
interval: 1m
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
name: homelab-infra-write
|
||||
git:
|
||||
checkout:
|
||||
ref:
|
||||
branch: main
|
||||
commit:
|
||||
author:
|
||||
name: flux-bot
|
||||
email: [email protected]
|
||||
messageTemplate: |
|
||||
chore(image): update {{ range .Changed.Changes }}{{ .OldValue }} -> {{ .NewValue }} {{ end }}
|
||||
push:
|
||||
branch: main
|
||||
update:
|
||||
path: ./apps/backstage
|
||||
strategy: Setters
|
||||
@@ -0,0 +1,7 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- external-secret.yaml
|
||||
- gitrepository.yaml
|
||||
- imageupdateautomation.yaml
|
||||
- backstage.yaml
|
||||
Reference in New Issue
Block a user