Author SHA1 Message Date
panxiao81 f44d4349a7 Merge pull request 'Backstage 改为 RollingUpdate' (#180) from feat/backstage-rolling-update into main
yaml / yaml (push) Successful in 27s
2026-10-01 19:36:17 +00:00
panxiao81 9368ac559e Merge pull request 'zot:backstage 仓库只保留 latest' (#179) from feat/zot-backstage-retention into main
yaml / yaml (push) Successful in 31s
2026-10-01 19:35:58 +00:00
panxiao81andClaude Opus 5.5 fef75ad34f feat(backstage): switch to RollingUpdate
yaml / yaml (pull_request) Successful in 26s
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-01 19:35:12 +00:00
panxiao81andClaude Opus 5.5 0c7728fe0b feat(zot): keep only latest for the backstage repository
yaml / yaml (pull_request) Successful in 33s
Backstage dev images are tracked by digest behind :latest, so the per-commit
sha tags pushed before that change only accumulate. Retain every tag in all
other repositories via an explicit catch-all policy.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-01 19:34:38 +00:00
flux-bot a4e2c60346 chore(image): update zot.ad.ddupan.top/panxiao81/backstage:latest@sha256:da55be5c2f5c8b33de2d87ee0ef02edeacf52a349c8b19a5fac9be4152b2723d -> zot.ad.ddupan.top/panxiao81/backstage:latest@sha256:476b40ea5cdf7301edb4f5dab5a012686a0009d1b0f1fce21fab34b969543ebb
yaml / yaml (push) Successful in 24s
2026-10-01 17:38:53 +00:00
panxiao81 746d326292 Merge pull request '同步 iam-admin-ui 登记为 audience + groups 模型' (#177) from docs/iam-console-audience into main
Reviewed-on: #177
2026-10-01 17:29:34 +00:00
panxiao81andClaude Opus 5.5 4a6b5c8a1d 同步 iam-admin-ui 登记为 audience + groups 模型
iam-login 客户端管理 API 改为校验 audience 与 groups,iam-admin-ui
相应登记为 scope openid groups 与 audience iam-login。

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-01 17:28:26 +00:00
4 changed files with 35 additions and 9 deletions
+9 -2
View File
@@ -8,8 +8,15 @@ metadata:
backstage.io/kubernetes-id: homelab-backstage
spec:
replicas: 1
# Backstage is multi-instance safe (scheduler locks, event bus, and auth keys
# live in PostgreSQL), so surge one new pod and keep the old one serving
# until it is ready. Migrations run on the new pod while the old one still
# serves; revisit if an upgrade ships a backward-incompatible migration.
strategy:
type: Recreate
type: RollingUpdate
rollingUpdate:
maxSurge: 1
maxUnavailable: 0
selector:
matchLabels:
app.kubernetes.io/name: backstage
@@ -27,7 +34,7 @@ spec:
type: RuntimeDefault
containers:
- name: backstage
image: zot.ad.ddupan.top/panxiao81/backstage:latest@sha256:da55be5c2f5c8b33de2d87ee0ef02edeacf52a349c8b19a5fac9be4152b2723d # {"$imagepolicy": "flux-system:backstage"}
image: zot.ad.ddupan.top/panxiao81/backstage:latest@sha256:476b40ea5cdf7301edb4f5dab5a012686a0009d1b0f1fce21fab34b969543ebb # {"$imagepolicy": "flux-system:backstage"}
imagePullPolicy: IfNotPresent
env:
- name: BACKSTAGE_BASE_URL
+6 -5
View File
@@ -27,9 +27,10 @@ Hydra 回调为 `/oauth2/start`、`/oauth2/consent`、`/oauth2/logout`;默认
### 客户端管理 `/console`
iam-login 的客户端管理 API 只接受 Hydra 签发、带 `iam.clients.manage` scope 的 access token;
`/console` 是调用该 API 的前端,在 Hydra 中登记为普通 **public** 客户端 `iam-admin-ui`。
该 scope 只在 consent 时发给 `iam-admin-ui` 且直接属于管理组的用户,规则在 iam-login。
iam-login 的客户端管理 API 是普通 resource server:只接受 Hydra 签发、`aud` 含 `iam-login`
且 `groups` 含管理组的 access token。`/console` 是调用该 API 的前端,在 Hydra 中登记为普通
**public** 客户端 `iam-admin-ui`;只有它被允许申请 audience `iam-login`(Hydra 按客户端登记的
audience 白名单执行),所以其他应用拿到的管理员 token 不能调用该 API。
浏览器直接向 Hydra 换取 token,因此 `hydra.yaml` 为 public 端口开启 CORS,只允许开发实例
origin;不放行 cookie 凭据。Gitea 等服务端客户端不受影响。
@@ -42,11 +43,11 @@ curl -fsS -X POST http://127.0.0.1:18445/admin/clients -H 'Content-Type: applica
"client_id": "iam-admin-ui", "client_name": "IAM 管理",
"redirect_uris": ["https://laptop.tail7e769.ts.net:18082/console/callback"],
"grant_types": ["authorization_code"], "response_types": ["code"],
"scope": "openid iam.clients.manage", "token_endpoint_auth_method": "none",
"scope": "openid groups", "audience": ["iam-login"], "token_endpoint_auth_method": "none",
"subject_type": "public", "metadata": {"iam_login_enabled": true}}'
```
开发实例另需 `iam.clients.admin-ui-client-id=iam-admin-ui`;未配置时 `/console` 不提供,API
开发实例另需 `iam.clients.admin-ui-client-id=iam-admin-ui` 与 `iam.clients.admin-groups`(组名);未配置时 `/console` 不提供,API
无法获得可用 token(fail closed)。
从 Gitea `/user/oauth2/hydra` 发起,应进入新密码/Passkey 页,确认授权后返回原账号,核对
+5 -2
View File
@@ -26,8 +26,11 @@ SPIRE 认证链路已经验证,但当前没有常驻 publisher 或删除授权
`/var/lib/registry` 是 `emptyDir`,仅用于运行时本地工作数据。
两个单副本实例共用同一 bucket 和前缀:`zot` 负责鉴权写入,`zot-reader` 负责匿名
读取。关闭跨仓库 dedupe,不额外部署 Redis/DynamoDB 缓存。只有写入实例启用 GC,
暂不配置自动删除已发布版本的 retention policy。增加副本、启用 dedupe 或搜索等
读取。关闭跨仓库 dedupe,不额外部署 Redis/DynamoDB 缓存。只有写入实例启用 GC。
retention policy 只针对 `panxiao81/backstage`:仅保留 `latest`,历史 sha tag 与失去
tag 的 digest 在 24h 后回收(dev 镜像由 Flux 跟踪 `latest` 的 digest)。其余仓库由
`**` 兜底策略保留全部 tag,行为与未配置 retention 时一致;新增按仓库的清理规则时,
必须放在兜底策略之前,否则不会生效。增加副本、启用 dedupe 或搜索等
扩展前,需要重新检查共享元数据与缓存的持久化要求。
凭据链路:
+15
View File
@@ -27,6 +27,21 @@ configFiles:
"gc": true,
"gcDelay": "24h",
"gcInterval": "24h",
"retention": {
"delay": "24h",
"policies": [
{
"repositories": ["panxiao81/backstage"],
"deleteUntagged": true,
"keepTags": [{ "patterns": ["^latest$"] }]
},
{
"repositories": ["**"],
"deleteUntagged": true,
"keepTags": [{ "patterns": [".*"] }]
}
]
},
"storageDriver": {
"name": "s3",
"region": "us-east-1",