30 lines
1.2 KiB
Plaintext
30 lines
1.2 KiB
Plaintext
# -----------------------------------------------------------------------------
|
|||
|
|
# OPTIONAL: cluster-side Harbor pull secret.
|
||
|
|
#
|
||
|
|
# This is NOT needed for the CI build/push (that uses Gitea Actions secrets).
|
||
|
|
# Create it only if the same k3s cluster must *pull* the private images that the
|
||
|
|
# pipeline pushes to Harbor (e.g. when you later deploy those images here).
|
||
|
|
#
|
||
|
|
# Easiest way to create it (recommended over editing this file by hand):
|
||
|
|
#
|
||
|
|
# kubectl create secret docker-registry harbor-pull \
|
||
|
|
# --namespace <your-app-namespace> \
|
||
|
|
# --docker-server=harbor.example.com \
|
||
|
|
# --docker-username='robot$ci' \
|
||
|
|
# --docker-password='REPLACE_WITH_ROBOT_TOKEN'
|
||
|
|
#
|
||
|
|
# Then reference it from your workloads:
|
||
|
|
# spec.imagePullSecrets: [{ name: harbor-pull }]
|
||
|
|
#
|
||
|
|
# The manifest below is the equivalent declarative form (base64 dockerconfigjson).
|
||
|
|
# -----------------------------------------------------------------------------
|
||
|
|
apiVersion: v1
|
||
|
|
kind: Secret
|
||
|
|
metadata:
|
||
|
|
name: harbor-pull
|
||
|
|
namespace: default
|
||
|
|
type: kubernetes.io/dockerconfigjson
|
||
|
|
data:
|
||
|
|
# echo -n '{"auths":{"harbor.example.com":{"username":"robot$ci","password":"TOKEN","auth":"<base64 user:pass>"}}}' | base64 -w0
|
||
|
|
.dockerconfigjson: REPLACE_WITH_BASE64_DOCKERCONFIGJSON
|