From cdfcc47b1557e776a51d3aa593a6377fbdb929a4 Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Sat, 3 Oct 2026 16:58:23 +0200 Subject: [PATCH] hub v0.127.0 deployed: manifest image tag + required OFFSITE_SECRET_KEY (Secret/offsite-secret-key, created out-of-band) Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- manifests/hub.yaml | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/manifests/hub.yaml b/manifests/hub.yaml index 678ea7bb..e0a340a1 100644 --- a/manifests/hub.yaml +++ b/manifests/hub.yaml @@ -128,7 +128,7 @@ spec: spec: containers: - name: hub - image: gitea.dooplex.hu/admin/felhom-hub:0.126.0 + image: gitea.dooplex.hu/admin/felhom-hub:0.127.0 ports: - containerPort: 8080 name: http @@ -155,6 +155,16 @@ spec: secretKeyRef: name: report-api key: REPORT_API_KEY + # Decision 69 / R-821 (v0.127.0): the AES-256 key that seals every Storage Box sub-account + # password at rest. Out-of-band Secret/offsite-secret-key (NOT committed; + # documentation/runbooks/secrets.md). NOT optional: without it the hub refuses to store or + # use any sub-account password, so a missing Secret must fail the pod rather than boot a hub + # whose off-site registrar is silently off. + - name: OFFSITE_SECRET_KEY + valueFrom: + secretKeyRef: + name: offsite-secret-key + key: OFFSITE_SECRET_KEY - name: REGISTRY_USERNAME valueFrom: secretKeyRef: