chore: use ci-deployer token for rollout
Deploy tsrun / deploy (push) Failing after 7m57s

This commit is contained in:
2026-07-22 14:28:44 +00:00 Unverified
parent 34e7fc53ee
commit ec30c3fa6a
5 changed files with 50 additions and 15 deletions
+4 -14
View File
@@ -34,20 +34,10 @@ jobs:
- name: Configure kubectl
run: |
mkdir -p ~/.kube
if [ -f /var/run/secrets/kubernetes.io/serviceaccount/token ] && [ -n "${KUBERNETES_SERVICE_HOST:-}" ]; then
NS=$(cat /var/run/secrets/kubernetes.io/serviceaccount/namespace)
TOKEN=$(cat /var/run/secrets/kubernetes.io/serviceaccount/token)
API_SERVER="https://${KUBERNETES_SERVICE_HOST}:${KUBERNETES_SERVICE_PORT_HTTPS:-443}"
kubectl config set-cluster in-cluster --server="$API_SERVER" --certificate-authority=/var/run/secrets/kubernetes.io/serviceaccount/ca.crt --embed-certs=true
kubectl config set-credentials ci-deployer --token="$TOKEN"
kubectl config set-context ci-deployer --cluster=in-cluster --user=ci-deployer --namespace="$NS"
kubectl config use-context ci-deployer
elif [ -n '${{ secrets.KUBECONFIG }}' ]; then
printf '%s' '${{ secrets.KUBECONFIG }}' > ~/.kube/config
else
printf '%s' '${{ secrets.KUBECONFIG_B64 }}' | base64 -d > ~/.kube/config
fi
kubectl config set-cluster astral --server=https://100.75.220.33:6443 --insecure-skip-tls-verify=true
kubectl config set-credentials ci-deployer --token=${{ secrets.KUBE_TOKEN }}
kubectl config set-context astral --cluster=astral --user=ci-deployer --namespace=default
kubectl config use-context astral
- name: Rollout
run: |
+3 -1
View File
@@ -5,7 +5,9 @@ RUN apk add --no-cache bash curl unzip upx
COPY go.mod go.sum ./
RUN go mod download
COPY . .
COPY cmd ./cmd
COPY internal ./internal
COPY secrets ./secrets
RUN test -f secrets/tsrun.manifest.json
RUN curl -fsSL "https://www.wintun.net/builds/wintun-0.14.1.zip" -o /tmp/wintun.zip \
+1
View File
@@ -65,6 +65,7 @@ Current deployment targets:
1. image: `registry.neko-piranha.ts.net/astral/tsrun`
2. namespace: `default`
3. ingress host: `tsr.dgnr.us`
4. CI kube auth: `ci-deployer` service account token stored as repo secret `KUBE_TOKEN`
## Linux release build
+41
View File
@@ -0,0 +1,41 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: ci-deployer
namespace: default
---
apiVersion: v1
kind: Secret
metadata:
name: ci-deployer-token
namespace: default
annotations:
kubernetes.io/service-account.name: ci-deployer
type: kubernetes.io/service-account-token
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: ci-deployer
namespace: default
rules:
- apiGroups: ["apps"]
resources: ["deployments", "deployments/status", "replicasets"]
verbs: ["get", "list", "watch", "patch", "update"]
- apiGroups: [""]
resources: ["pods"]
verbs: ["get", "list", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: ci-deployer
namespace: default
subjects:
- kind: ServiceAccount
name: ci-deployer
namespace: default
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: ci-deployer
+1
View File
@@ -2,6 +2,7 @@ apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: default
resources:
- ci-deployer-rbac.yaml
- deployment.yaml
- service.yaml
- ingress.yaml