fix(build): let kaniko pull base images from the plain-HTTP registry — push-only insecure flags broke every FROM registry.felis.svc build (#70)

This commit is contained in:
Lemon-miaow committed 2026-09-24 02:56:56 +08:00
1 parent 7791ed74f2
commit ac403b9cd3
2 files changed
+17 -1

No files matched your search

+8 -1
View File
@@ -211,9 +211,16 @@ func BuildJob(p JobParams) (*batchv1.Job, error) {
"--context=" + contextPath,
"--destination=" + p.ImageRef,
// The internal registry is in-cluster only and may serve plain HTTP;
// it is never a public ingress (spec §17).
// it is never a public ingress (spec §17). Both directions need the
// insecure flags: --insecure/--skip-tls-verify cover the PUSH, while
// the pull side needs its own pair — a Dockerfile's `FROM
// registry.felis.svc:5000/...` otherwise fails with "server gave
// HTTP response to HTTPS client", breaking every build based on a
// platform image (the canonical modpack shape).
"--insecure",
"--skip-tls-verify",
"--insecure-pull",
"--skip-tls-verify-pull",
},
VolumeMounts: kanikoMounts,
Resources: corev1.ResourceRequirements{Limits: limits, Requests: buildRequests(limits)},
+9
View File
@@ -177,6 +177,15 @@ func TestBuildJobKanikoPushesAndTrivyGates(t *testing.T) {
if !hasArg(kaniko.Args, "--destination="+p.ImageRef) {
t.Errorf("kaniko must push to %q, args=%v", p.ImageRef, kaniko.Args)
}
// The pull direction needs its own flags: --insecure/--skip-tls-verify only
// cover the push, and without the pull pair a Dockerfile's `FROM` fails
// against the plain-HTTP registry ("server gave HTTP response to HTTPS
// client") — the live failure this guards.
for _, flag := range []string{"--insecure-pull", "--skip-tls-verify-pull"} {
if !hasArg(kaniko.Args, flag) {
t.Errorf("kaniko args = %v, want %s so base-image pulls use plain HTTP", kaniko.Args, flag)
}
}
if len(job.Spec.Template.Spec.Containers) != 1 {
t.Fatalf("expected exactly one (trivy) main container")