chore(gitea): add git.forust.xyz route
ci / lint-compose (push) Successful in 9s
ci / lint-actionlint (push) Successful in 5s
ci / lint-shellcheck (push) Successful in 7s
ci / lint-prettier (push) Successful in 12s
ci / lint-ruff (push) Successful in 6s
ci / lint-yaml (push) Successful in 9s
ci / lint-dockerfiles (push) Successful in 4s
ci / validate (push) Successful in 5s
renovate-ci / validate-renovate (push) Successful in 8s
ci / build (push) Successful in 17s

This commit is contained in:
forust committed 2026-10-03 11:07:48 +02:00
1 parent 22c2f1e108
commit 78e6363fe2
2 files changed
+3 -9

No files matched your search

+1
View File
@@ -8,6 +8,7 @@ spec:
dnsNames: dnsNames:
- gcr.forust.xyz - gcr.forust.xyz
- gitea.forust.xyz - gitea.forust.xyz
- git.forust.xyz
issuerRef: issuerRef:
name: letsencrypt-prod name: letsencrypt-prod
kind: ClusterIssuer kind: ClusterIssuer
+2 -9
View File
@@ -7,18 +7,11 @@ spec:
entryPoints: entryPoints:
- websecure - websecure
routes: routes:
- match: Host(`gitea.forust.xyz`) - match: Host(`gitea.forust.xyz`) || Host(`git.forust.xyz`)
kind: Rule kind: Rule
services: services:
- name: gitea-service - name: gitea-service
port: 3000 port: 3000
# Registry route: NO crowdsec-bouncer.
# A deploy burst (runner Action API polls, `docker manifest inspect` per
# own image, containerd pulls, smoke probes) fires hundreds of parallel
# registry calls, and a ban on the runner breaks every later job. This
# route only serves authenticated OCI traffic - registry tokens and
# basic-auth are already handled by gitea - and scanners get nothing
# useful from /v2, so there is no bruteforce surface to protect here.
- match: Host(`gcr.forust.xyz`) && PathPrefix(`/v2`) - match: Host(`gcr.forust.xyz`) && PathPrefix(`/v2`)
kind: Rule kind: Rule
services: services:
@@ -36,7 +29,7 @@ spec:
entryPoints: entryPoints:
- websecure - websecure
routes: routes:
- match: Host(`gitea.workstation.internal`) || Host(`gitea.gigaforust.internal`) - match: (Host(`gitea.workstation.internal`) || Host(`gitea.gigaforust.internal`)) || (Host(`git.workstation.internal`) || Host(`git.gigaforust.internal`))
kind: Rule kind: Rule
services: services:
- name: gitea-service - name: gitea-service