All 5 CronJob manifests (deadline-checker, evening-summary, git-sync,
morning-briefing, waiting-followup) referenced 'myorg-assistant:latest'
—a bare local image name that doesn't exist on any node. The main
Deployment already uses git.rogi.casa/roger/myorg-assistant/myorg-assistant:fcf79bf.
Changes per cronjob:
- image: myorg-assistant:latest → git.rogi.casa/.../myorg-assistant:fcf79bf
- imagePullPolicy: IfNotPresent → Always (match Deployment)
- Add imagePullSecrets: gitea-registry (required for private registry)
This fixes 4 pods stuck in ImagePullBackOff for ~6+ hours.
The ingresses referenced a Cloudflare OriginIssuer 'prod-issuer' whose CRD
and controller are not installed in the cluster, so cert-manager could not
issue certs and Traefik served a default cert (invalid SSL). Switch to the
existing letsencrypt-prod ClusterIssuer with specific hostnames + per-app
secrets, matching the working ingresses (http-01 cannot issue wildcards).