hub v0.127.0 deployed: manifest image tag + required OFFSITE_SECRET_KEY (Secret/offsite-secret-key, created out-of-band)
gates / gates (push) Successful in 29s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-03 16:58:23 +02:00
parent f417cdede1
commit cdfcc47b15
+11 -1
View File
@@ -128,7 +128,7 @@ spec:
spec:
containers:
- name: hub
image: gitea.dooplex.hu/admin/felhom-hub:0.126.0
image: gitea.dooplex.hu/admin/felhom-hub:0.127.0
ports:
- containerPort: 8080
name: http
@@ -155,6 +155,16 @@ spec:
secretKeyRef:
name: report-api
key: REPORT_API_KEY
# Decision 69 / R-821 (v0.127.0): the AES-256 key that seals every Storage Box sub-account
# password at rest. Out-of-band Secret/offsite-secret-key (NOT committed;
# documentation/runbooks/secrets.md). NOT optional: without it the hub refuses to store or
# use any sub-account password, so a missing Secret must fail the pod rather than boot a hub
# whose off-site registrar is silently off.
- name: OFFSITE_SECRET_KEY
valueFrom:
secretKeyRef:
name: offsite-secret-key
key: OFFSITE_SECRET_KEY
- name: REGISTRY_USERNAME
valueFrom:
secretKeyRef: