diff --git a/internal/build/jobspec.go b/internal/build/jobspec.go index fe7044f..22c16fd 100644 --- a/internal/build/jobspec.go +++ b/internal/build/jobspec.go @@ -211,9 +211,16 @@ func BuildJob(p JobParams) (*batchv1.Job, error) { "--context=" + contextPath, "--destination=" + p.ImageRef, // The internal registry is in-cluster only and may serve plain HTTP; - // it is never a public ingress (spec §17). + // it is never a public ingress (spec §17). Both directions need the + // insecure flags: --insecure/--skip-tls-verify cover the PUSH, while + // the pull side needs its own pair — a Dockerfile's `FROM + // registry.felis.svc:5000/...` otherwise fails with "server gave + // HTTP response to HTTPS client", breaking every build based on a + // platform image (the canonical modpack shape). "--insecure", "--skip-tls-verify", + "--insecure-pull", + "--skip-tls-verify-pull", }, VolumeMounts: kanikoMounts, Resources: corev1.ResourceRequirements{Limits: limits, Requests: buildRequests(limits)}, diff --git a/internal/build/jobspec_test.go b/internal/build/jobspec_test.go index 5ad6d8e..f0bb97a 100644 --- a/internal/build/jobspec_test.go +++ b/internal/build/jobspec_test.go @@ -177,6 +177,15 @@ func TestBuildJobKanikoPushesAndTrivyGates(t *testing.T) { if !hasArg(kaniko.Args, "--destination="+p.ImageRef) { t.Errorf("kaniko must push to %q, args=%v", p.ImageRef, kaniko.Args) } + // The pull direction needs its own flags: --insecure/--skip-tls-verify only + // cover the push, and without the pull pair a Dockerfile's `FROM` fails + // against the plain-HTTP registry ("server gave HTTP response to HTTPS + // client") — the live failure this guards. + for _, flag := range []string{"--insecure-pull", "--skip-tls-verify-pull"} { + if !hasArg(kaniko.Args, flag) { + t.Errorf("kaniko args = %v, want %s so base-image pulls use plain HTTP", kaniko.Args, flag) + } + } if len(job.Spec.Template.Spec.Containers) != 1 { t.Fatalf("expected exactly one (trivy) main container")