Full migration off Scaleway Container Registry to internal GitLab registry backed by MinIO S3. All 4 images (ci-builder, ci-builder-cpu, foxhunt-runtime, foxhunt-training-runtime) rebuilt in internal registry. Registry & images: - All image refs → gitlab-registry.foxhunt.svc.cluster.local:5000/root/foxhunt/ - imagePullSecrets: scw-registry → gitlab-registry - Kaniko build template: two-step DAG (git-clone → kaniko-build) with shared PVC - Kaniko layer cache enabled at root/foxhunt/cache - AWS_ACCESS_KEY_ID: $SCW_ACCESS_KEY → $MINIO_ACCESS_KEY in .gitlab-ci.yml Network policies: - ci-pipeline: add HTTP/80, registry/5000, webservice/8181 egress rules DNS & Tailscale proxy cleanup: - Remove ci, prometheus, monitor DNS records (no longer exposed) - Rename s3 → minio DNS record - Remove Argo UI, Prometheus, monitor nginx server blocks - Remove argo-htpasswd volume mount - Tailscale proxy nodeSelector: infra → platform Terraform cleanup: - Delete infra/modules/registry/ (SCW CR namespace) - Delete infra/modules/object-storage/ (SCW S3 buckets) - Delete infra/modules/secrets/ (SCW secrets) - Delete corresponding live configs - TF state backend: S3 → GitLab HTTP Argo workflows: - Add events/ (GitLab push eventsource + ci-pipeline sensor) - ci-pipeline + training templates: SCW → internal registry - Delete obsolete compile-training-template.yaml Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
64 lines
2.2 KiB
YAML
64 lines
2.2 KiB
YAML
apiVersion: batch/v1
|
|
kind: Job
|
|
metadata:
|
|
name: gitlab-postgres-init
|
|
namespace: foxhunt
|
|
labels:
|
|
app.kubernetes.io/name: gitlab-postgres-init
|
|
app.kubernetes.io/part-of: foxhunt
|
|
spec:
|
|
ttlSecondsAfterFinished: 300
|
|
backoffLimit: 3
|
|
template:
|
|
spec:
|
|
nodeSelector:
|
|
k8s.scaleway.com/pool-name: infra
|
|
restartPolicy: Never
|
|
containers:
|
|
- name: init
|
|
image: timescale/timescaledb:latest-pg16
|
|
command:
|
|
- bash
|
|
- -c
|
|
- |
|
|
set -euo pipefail
|
|
export PGPASSWORD="$POSTGRES_PASSWORD"
|
|
|
|
until pg_isready -h postgres -U foxhunt; do
|
|
echo "Waiting for postgres..."
|
|
sleep 2
|
|
done
|
|
|
|
echo "Creating gitlab user..."
|
|
psql -h postgres -U foxhunt -d foxhunt -tc \
|
|
"SELECT 1 FROM pg_roles WHERE rolname='gitlab'" | grep -q 1 || \
|
|
psql -h postgres -U foxhunt -d foxhunt -c \
|
|
"CREATE ROLE gitlab WITH LOGIN PASSWORD '${GITLAB_DB_PASSWORD}'"
|
|
|
|
echo "Creating gitlab database..."
|
|
psql -h postgres -U foxhunt -tc \
|
|
"SELECT 1 FROM pg_database WHERE datname='gitlab'" | grep -q 1 || \
|
|
psql -h postgres -U foxhunt -c \
|
|
"CREATE DATABASE gitlab OWNER gitlab"
|
|
|
|
echo "Creating extensions..."
|
|
psql -h postgres -U foxhunt -d gitlab -c "CREATE EXTENSION IF NOT EXISTS pg_trgm;"
|
|
psql -h postgres -U foxhunt -d gitlab -c "CREATE EXTENSION IF NOT EXISTS btree_gist;"
|
|
|
|
echo "Granting permissions..."
|
|
psql -h postgres -U foxhunt -d gitlab -c "GRANT ALL PRIVILEGES ON DATABASE gitlab TO gitlab;"
|
|
psql -h postgres -U foxhunt -d gitlab -c "GRANT ALL ON SCHEMA public TO gitlab;"
|
|
|
|
echo "GitLab database initialized successfully."
|
|
env:
|
|
- name: POSTGRES_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: db-credentials
|
|
key: password
|
|
- name: GITLAB_DB_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: gitlab-secrets
|
|
key: db-password
|