Add Gitea Actions deploy pipeline + deployer RBAC
- .gitea/workflows/deploy.yaml: PRs run a server-side dry-run; pushes to main apply the kustomization and wait for all rollouts. Modeled on socktop-webterm's pipeline; uses the same KUBECONFIG secret convention and gitea-deployer ServiceAccount. - rbac/gitea-deployer.yaml: ClusterRole/Binding (admin bootstrap, outside the root kustomization) — repo resource kinds only, no secrets access, no delete verbs, no RBAC escalation. Applied to the cluster 2026-07-26. - One-time env->secretKeyRef migration executed against the cluster; README updated. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -1,3 +1,4 @@
|
||||
# Real secrets never go in git — only *.example.yaml templates do.
|
||||
apps/**/secret.yaml
|
||||
*.secret.yaml
|
||||
.deploy-kubeconfig.b64
|
||||
|
||||
Reference in New Issue
Block a user