Add Gitea Actions deploy pipeline + deployer RBAC

- .gitea/workflows/deploy.yaml: PRs run a server-side dry-run; pushes to
  main apply the kustomization and wait for all rollouts. Modeled on
  socktop-webterm's pipeline; uses the same KUBECONFIG secret convention
  and gitea-deployer ServiceAccount.
- rbac/gitea-deployer.yaml: ClusterRole/Binding (admin bootstrap, outside
  the root kustomization) — repo resource kinds only, no secrets access,
  no delete verbs, no RBAC escalation. Applied to the cluster 2026-07-26.
- One-time env->secretKeyRef migration executed against the cluster;
  README updated.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
jasonwitty
2026-07-26 02:37:49 -07:00
parent 8afac39d03
commit 96e1825629
4 changed files with 165 additions and 13 deletions
+1
View File
@@ -1,3 +1,4 @@
# Real secrets never go in git — only *.example.yaml templates do.
apps/**/secret.yaml
*.secret.yaml
.deploy-kubeconfig.b64