From ae6e9256c65dbfd4791eb95a2ebb087b855a7c2d Mon Sep 17 00:00:00 2001 From: Lemon-miaow Date: Wed, 23 Sep 2026 15:56:44 +0800 Subject: [PATCH] =?UTF-8?q?docs(troubleshooting):=208e=20=E2=80=94=20apply?= =?UTF-8?q?=20build-image=20overrides=20through=20the=20config=20Secret=20?= =?UTF-8?q?(restart=20alone=20does=20not)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- docs/troubleshooting.md | 17 +++++++++++++++-- 1 file changed, 15 insertions(+), 2 deletions(-) diff --git a/docs/troubleshooting.md b/docs/troubleshooting.md index 008e120..9bdf334 100644 --- a/docs/troubleshooting.md +++ b/docs/troubleshooting.md @@ -413,8 +413,21 @@ build_cpu_limit = "2" build_mem_limit = "4Gi" ``` -then restart `felis-api` (it renders the Job from this config). Unset fields keep -the defaults. +Put them in **both** `/etc/felis/felis.host.toml` (host-side CLI) and +`/etc/felis/felis.pod.toml` (the file rendered into the API's `felis-config` +Secret — the two differ only in the database URL; the setup screens re-render +the Secret from the pod file, so edits made only through `kubectl` on the live +Secret are lost at the next reconfigure). A Deployment restart alone is NOT +enough — the API Pod mounts the Secret, never the host file. Re-render the +Secret from the pod file, then roll `felis-api`: + +```sh +kubectl -n felis create secret generic felis-config \ + --from-file=felis.toml=/etc/felis/felis.pod.toml --dry-run=client -o yaml | kubectl apply -f - +kubectl -n felis rollout restart deployment/felis-api +``` + +Unset fields keep the defaults. `trivy_db_repository` is not optional on an egress-locked box. Trivy fetches its vulnerability DB from `mirror.gcr.io`/`ghcr.io` unless told otherwise, and the