Fix app image pulls and Harbor kubelet auth for user workloads.
Route k3s registry mirrors through harbor-core ClusterIP with hostname-only auth keys, use HTTP EXT_ENDPOINT so OAuth tokens work on port 80, extend deploy readiness timeout, and harden Kaniko build/dockerfile fallbacks. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -2,6 +2,8 @@
|
||||
# Proxy-cache only works through harbor-core (not harbor-registry or Traefik /v2/ alone).
|
||||
#
|
||||
# Apply: ./scripts/apply-k3s-registries.sh
|
||||
# Harbor EXT_ENDPOINT should be http://registry.abrban.com so OAuth realm uses HTTP
|
||||
# (kubelet mirror hits harbor-core on :80; https://<clusterIP>:443 times out).
|
||||
|
||||
mirrors:
|
||||
registry.abrban.com:
|
||||
|
||||
Reference in New Issue
Block a user