@@ -31,6 +31,44 @@ spec:
|
|||||||
volumeMounts:
|
volumeMounts:
|
||||||
- mountPath: /var/run/argocd
|
- mountPath: /var/run/argocd
|
||||||
name: var-files
|
name: var-files
|
||||||
|
- name: ghcr-auth
|
||||||
|
image: quay.io/argoproj/argocd:v3.4.3
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
args:
|
||||||
|
- /bin/cp --update=none /usr/local/bin/argocd /var/run/argocd/argocd && /bin/ln -s /var/run/argocd/argocd /var/run/argocd/argocd-cmp-server
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
|
readOnlyRootFilesystem: true
|
||||||
|
runAsNonRoot: true
|
||||||
|
seccompProfile:
|
||||||
|
type: RuntimeDefault
|
||||||
|
env:
|
||||||
|
- name: HELM_CONFIG_HOME
|
||||||
|
value: /helm-auth
|
||||||
|
- name: HELM_REGISTRY_CONFIG
|
||||||
|
value: /helm-auth/config.json
|
||||||
|
- name: GITEA_USERNAME
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: gitea-basic-authregcred
|
||||||
|
key: username
|
||||||
|
- name: GITEA_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: gitea-basic-authregcred
|
||||||
|
key: password
|
||||||
|
volumeMounts:
|
||||||
|
- name: registry-auth-dir
|
||||||
|
mountPath: /helm-auth
|
||||||
|
command:
|
||||||
|
- /bin/bash
|
||||||
|
- -exc
|
||||||
|
- 'echo -n $GITEA_PASSWORD | helm registry login git.olb42.com --username $GITEA_USERNAME --password-stdin -'
|
||||||
containers:
|
containers:
|
||||||
- name: argocd-lovely-plugin
|
- name: argocd-lovely-plugin
|
||||||
image: ghcr.io/crumbhole/lovely:1.2.4
|
image: ghcr.io/crumbhole/lovely:1.2.4
|
||||||
@@ -55,3 +93,8 @@ spec:
|
|||||||
volumes:
|
volumes:
|
||||||
- name: lovely-tmp
|
- name: lovely-tmp
|
||||||
emptyDir: {}
|
emptyDir: {}
|
||||||
|
- name: registry-auth-dir
|
||||||
|
emptyDir: {}
|
||||||
|
volumeMounts:
|
||||||
|
- name: registry-auth-dir
|
||||||
|
mountPath: /helm-auth
|
||||||
|
|||||||
Reference in New Issue
Block a user