-
released this
2026-09-10 11:55:02 +00:00 | 0 commits to master since this releaseWhat's new in 26.37.0
Push images to an in-cluster registry over plain HTTP, so large layer uploads skip the public ingress.
REGISTRY_INSECURE: push to an in-cluster registry (#8)build.shhas a newREGISTRY_INSECUREsetting (defaultfalse). When set totrue, it passes Kaniko's--insecure-registry=${REGISTRY_HOST}, so a pipeline can push straight to Forgejo's Service instead of through the ingress:env: REGISTRY_HOST: app-http-service.forgejo.svc.cluster.local:3000 REGISTRY_INSECURE: 'true' KANIKO_DESTINATION: app-http-service.forgejo.svc.cluster.local:3000/myorg/myapp:${GITHUB_SHA}Why: pushing to
git.van-hemmen.comsends every layer out through Traefik and back, even when the runner and Forgejo share a node. Traefik cuts any single request longer than about 60 seconds, which brokeactions/sindri'scoder-xfce-vncpushes with502 Bad Gateway. Pushed internally, the same image goes through and its largest layer uploads in about 32 seconds.- Only
REGISTRY_HOSTswitches to HTTP. Base-image pulls from Docker Hub and other registries keep using TLS. REGISTRY_HOSTmust match the host inKANIKO_DESTINATIONexactly, port included.- Pulls don't change: Forgejo stores images by owner and name, so they're still pulled as
git.van-hemmen.com/myorg/myapp:<tag>. - Invalid values stop the job before the build, for example
REGISTRY_INSECURE=ture. - No change when unset: without the setting, the Kaniko command is exactly as in
26.7.0.
See "Pushing to an in-cluster registry" in the README.
Full changelog:
26.7.0...26.37.0Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- Only