ci / lint-prettier (push) Successful in 3s
ci / lint-ruff (push) Successful in 1s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 2s
ci / build (push) Skipped
ci / deploy-userbot-panel (push) Skipped
CronJob adguard-cert-sync (daily 03:17) copies the public cert/key for dns.forust.xyz from Traefik acme.json into Secret adguard-certs, which AdGuard mounts for DNS-over-TLS on :853. - least-privilege RBAC: read pods/exec in ns traefik, get/update/patch Secret adguard-certs and get/patch adguard-deployment in ns adguard - script selects the PROD resolver entry only, matches main domain or SANs, compares sha256 hashes, patches the secret and restarts the deployment ONLY on change; exits non-zero and touches nothing when Traefik holds no cert yet (HTTP-01 currently cannot complete)