All four CronJobs share the same image + run_job entrypoint and import
Settings(), which requires git_token. Only git-sync and the Deployment
supplied these. Added GIT_REPO_URL/GIT_USERNAME/GIT_TOKEN secret env vars
to the other three CronJobs to prevent the same pydantic ValidationError
crash at import.
The deadline-checker container crashed at import (pydantic ValidationError:
git_token field required) because the CronJob pod did not mount GIT_TOKEN
from myorg-assistant-secret, unlike the main Deployment. Added the three
git-related secret env vars so Settings() validates.
CronJob pods were stuck in ImagePullBackOff because they referenced
the local-only image 'myorg-assistant:latest' which is not present
on the node. Switch all 5 cronjobs to the Gitea registry image
git.rogi.casa/roger/myorg-assistant/myorg-assistant:fcf79bf
(matching the Deployment), set imagePullPolicy: Always, and add
imagePullSecrets: gitea-registry so they can authenticate to the
private registry.
The ingresses referenced a Cloudflare OriginIssuer 'prod-issuer' whose CRD
and controller are not installed in the cluster, so cert-manager could not
issue certs and Traefik served a default cert (invalid SSL). Switch to the
existing letsencrypt-prod ClusterIssuer with specific hostnames + per-app
secrets, matching the working ingresses (http-01 cannot issue wildcards).