Files
container_builder/k3s/40-harbor-secret.yaml.example
2026-08-27 10:46:36 +02:00

30 lines
1.2 KiB
Plaintext

# -----------------------------------------------------------------------------
# OPTIONAL: cluster-side Harbor pull secret.
#
# This is NOT needed for the CI build/push (that uses Gitea Actions secrets).
# Create it only if the same k3s cluster must *pull* the private images that the
# pipeline pushes to Harbor (e.g. when you later deploy those images here).
#
# Easiest way to create it (recommended over editing this file by hand):
#
# kubectl create secret docker-registry harbor-pull \
# --namespace <your-app-namespace> \
# --docker-server=harbor.example.com \
# --docker-username='robot$ci' \
# --docker-password='REPLACE_WITH_ROBOT_TOKEN'
#
# Then reference it from your workloads:
# spec.imagePullSecrets: [{ name: harbor-pull }]
#
# The manifest below is the equivalent declarative form (base64 dockerconfigjson).
# -----------------------------------------------------------------------------
apiVersion: v1
kind: Secret
metadata:
name: harbor-pull
namespace: default
type: kubernetes.io/dockerconfigjson
data:
# echo -n '{"auths":{"harbor.example.com":{"username":"robot$ci","password":"TOKEN","auth":"<base64 user:pass>"}}}' | base64 -w0
.dockerconfigjson: REPLACE_WITH_BASE64_DOCKERCONFIGJSON