Register Gitea webhook 14 for oikos-console deploy
Created via the Gitea API (POST /repos/dtoro/Homelab-Docs/hooks) rather than the UI, since the existing PAT turned out to have sufficient scope. Webhook id 14: http://192.168.8.205:9831/deploy, push events, main branch filter, active. The shared secret was generated and registered with Gitea before the apps-side bootstrap ran (order reversed from the usual install.sh-first flow, since direct SSH deploy to apps is still pending operator execution — see oikos/console/deploy/README.md). Stored as secrets/oikos-console-deploy-secret.yaml (SOPS, recipient: apps only) rather than left as a local plaintext file, with explicit operator sign-off. When the apps-side install runs, skip webhook/install.sh's random-secret generation and write this exact value into /etc/oikos-console-deploy/secret instead. infrastructure/auto-deploy.md updated with the real webhook id (was "not yet registered"). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
10
.sops.yaml
10
.sops.yaml
@@ -123,4 +123,14 @@ creation_rules:
|
||||
age: >-
|
||||
age1xkklkvnk5z0fsnh6cfgv70hy9ksfy8rdprwerzw4yk3p4p7cxcqs2yvpz6,
|
||||
age1duyl8mkpgu80uv934dy8q7enqjms6yvdz264hme8uryuxmvvqesq6rusq0
|
||||
|
||||
- path_regex: ^secrets/oikos-console-deploy-secret\.yaml$
|
||||
# Shared HMAC secret for the Gitea deploy webhook (id 14) ->
|
||||
# oikos-console-deploy.service on apps (105). Generated + registered
|
||||
# with Gitea before the apps-side install ran (see
|
||||
# oikos/console/deploy/README.md "Status") — write this exact value
|
||||
# into /etc/oikos-console-deploy/secret rather than letting
|
||||
# webhook/install.sh generate a fresh one.
|
||||
age: >-
|
||||
age1duyl8mkpgu80uv934dy8q7enqjms6yvdz264hme8uryuxmvvqesq6rusq0
|
||||
# webhook noop 2026-05-20T18:16:57+02:00
|
||||
|
||||
Reference in New Issue
Block a user