hub v0.127.0 deployed: manifest image tag + required OFFSITE_SECRET_KEY (Secret/offsite-secret-key, created out-of-band)
gates / gates (push) Successful in 29s
gates / gates (push) Successful in 29s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
+11
-1
@@ -128,7 +128,7 @@ spec:
|
||||
spec:
|
||||
containers:
|
||||
- name: hub
|
||||
image: gitea.dooplex.hu/admin/felhom-hub:0.126.0
|
||||
image: gitea.dooplex.hu/admin/felhom-hub:0.127.0
|
||||
ports:
|
||||
- containerPort: 8080
|
||||
name: http
|
||||
@@ -155,6 +155,16 @@ spec:
|
||||
secretKeyRef:
|
||||
name: report-api
|
||||
key: REPORT_API_KEY
|
||||
# Decision 69 / R-821 (v0.127.0): the AES-256 key that seals every Storage Box sub-account
|
||||
# password at rest. Out-of-band Secret/offsite-secret-key (NOT committed;
|
||||
# documentation/runbooks/secrets.md). NOT optional: without it the hub refuses to store or
|
||||
# use any sub-account password, so a missing Secret must fail the pod rather than boot a hub
|
||||
# whose off-site registrar is silently off.
|
||||
- name: OFFSITE_SECRET_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: offsite-secret-key
|
||||
key: OFFSITE_SECRET_KEY
|
||||
- name: REGISTRY_USERNAME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
|
||||
Reference in New Issue
Block a user