Root cause of the git-sync failure: the cron pod only ran git pull/push
against /data/myorg but never ensured the repo existed, and the GIT_REPO_URL
secret historically pointed at the wrong Gitea subdomain (gitea.rogi.casa),
which 526s through Cloudflare -> 'Not a git repository: /data/myorg'.
Fixes:
1. Add an idempotent git-clone initContainer (guarded by [ ! -d /data/myorg/.git ])
so the cron job self-heals and actually clones on first run.
2. Normalize GIT_REPO_URL host to git.rogi.casa at runtime (sed), so the clone
works even if the cluster secret still contains the stale gitea.rogi.casa host.
The working subdomain is git.rogi.casa.
Evidence (Loki, last 24h+):
{namespace="myorg-assistant",pod=~"myorg-git-sync.+"}
-> Pull/Push: Error: Not a git repository: /data/myorg (every run)
-> job swallowed error, exited 0, so looked successful
Risk: low. initContainer mirrors the Deployment's; host-normalization is
idempotent. No RBAC/CRD/ArgoCD/volume changes.
125 lines
4.2 KiB
YAML
125 lines
4.2 KiB
YAML
apiVersion: batch/v1
|
|
kind: CronJob
|
|
metadata:
|
|
name: myorg-git-sync
|
|
namespace: myorg-assistant
|
|
labels:
|
|
app: myorg-assistant
|
|
job: git-sync
|
|
spec:
|
|
# Run every 15 minutes
|
|
schedule: "*/15 * * * *"
|
|
timeZone: "Europe/Madrid"
|
|
successfulJobsHistoryLimit: 1
|
|
failedJobsHistoryLimit: 2
|
|
concurrencyPolicy: Forbid
|
|
jobTemplate:
|
|
spec:
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app: myorg-assistant
|
|
job: git-sync
|
|
spec:
|
|
restartPolicy: OnFailure
|
|
imagePullSecrets:
|
|
- name: gitea-registry
|
|
initContainers:
|
|
- name: git-clone
|
|
image: alpine/git:latest
|
|
command:
|
|
- sh
|
|
- -c
|
|
- |
|
|
# Normalize the repo URL host to the correct Gitea subdomain.
|
|
# The GIT_REPO_URL secret historically contained gitea.rogi.casa,
|
|
# which 526s through Cloudflare; the working subdomain is git.rogi.casa.
|
|
export GIT_REPO_URL="$(echo "${GIT_REPO_URL}" | sed -E 's#https?://[^/@]+@?gitea\.rogi\.casa#https://'"${GIT_USERNAME}"':'"${GIT_TOKEN}"'@git.rogi.casa#')"
|
|
if [ ! -d /data/myorg/.git ]; then
|
|
echo "Cloning repository from ${GIT_REPO_URL}..."
|
|
git clone ${GIT_REPO_URL} /data/myorg
|
|
cd /data/myorg
|
|
git config user.name "${GIT_USERNAME}"
|
|
git config user.email "${GIT_USERNAME}@rogi.casa"
|
|
git config credential.helper store
|
|
echo "https://${GIT_USERNAME}:${GIT_TOKEN}@git.rogi.casa" > ~/.git-credentials
|
|
else
|
|
echo "Repository already exists, skipping clone."
|
|
fi
|
|
env:
|
|
- name: GIT_REPO_URL
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: myorg-assistant-secret
|
|
key: GIT_REPO_URL
|
|
- name: GIT_USERNAME
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: myorg-assistant-secret
|
|
key: GIT_USERNAME
|
|
- name: GIT_TOKEN
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: myorg-assistant-secret
|
|
key: GIT_TOKEN
|
|
volumeMounts:
|
|
- name: myorg-data
|
|
mountPath: /data/myorg
|
|
containers:
|
|
- name: git-sync
|
|
image: git.rogi.casa/roger/myorg-assistant/myorg-assistant:fcf79bf
|
|
imagePullPolicy: Always
|
|
command:
|
|
- python
|
|
- -c
|
|
- "from src.scheduler.jobs import run_job; import sys; run_job(sys.argv[1])"
|
|
- git-sync
|
|
env:
|
|
- name: MYORG_REPO_PATH
|
|
valueFrom:
|
|
configMapKeyRef:
|
|
name: myorg-assistant-config
|
|
key: MYORG_REPO_PATH
|
|
- name: GIT_BRANCH
|
|
valueFrom:
|
|
configMapKeyRef:
|
|
name: myorg-assistant-config
|
|
key: GIT_BRANCH
|
|
- name: GIT_REPO_URL
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: myorg-assistant-secret
|
|
key: GIT_REPO_URL
|
|
- name: GIT_USERNAME
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: myorg-assistant-secret
|
|
key: GIT_USERNAME
|
|
- name: GIT_TOKEN
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: myorg-assistant-secret
|
|
key: GIT_TOKEN
|
|
- name: DISCORD_BOT_TOKEN
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: myorg-assistant-secret
|
|
key: DISCORD_BOT_TOKEN
|
|
- name: LITELLM_API_KEY
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: myorg-assistant-secret
|
|
key: LITELLM_API_KEY
|
|
- name: WEB_SECRET_KEY
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: myorg-assistant-secret
|
|
key: WEB_SECRET_KEY
|
|
volumeMounts:
|
|
- name: myorg-data
|
|
mountPath: /data/myorg
|
|
volumes:
|
|
- name: myorg-data
|
|
persistentVolumeClaim:
|
|
claimName: myorg-assistant-pvc
|