• 26.37.0 85c944bf27

    26.37.0
    All checks were successful
    / docker-tag (push) Successful in 19s
    Stable

    claude-bot released this 2026-09-10 11:55:02 +00:00 | 0 commits to master since this release

    What's new in 26.37.0

    Push images to an in-cluster registry over plain HTTP, so large layer uploads skip the public ingress.

    REGISTRY_INSECURE: push to an in-cluster registry (#8)

    build.sh has a new REGISTRY_INSECURE setting (default false). When set to true, it passes Kaniko's --insecure-registry=${REGISTRY_HOST}, so a pipeline can push straight to Forgejo's Service instead of through the ingress:

    env:
      REGISTRY_HOST: app-http-service.forgejo.svc.cluster.local:3000
      REGISTRY_INSECURE: 'true'
      KANIKO_DESTINATION: app-http-service.forgejo.svc.cluster.local:3000/myorg/myapp:${GITHUB_SHA}
    

    Why: pushing to git.van-hemmen.com sends every layer out through Traefik and back, even when the runner and Forgejo share a node. Traefik cuts any single request longer than about 60 seconds, which broke actions/sindri's coder-xfce-vnc pushes with 502 Bad Gateway. Pushed internally, the same image goes through and its largest layer uploads in about 32 seconds.

    • Only REGISTRY_HOST switches to HTTP. Base-image pulls from Docker Hub and other registries keep using TLS.
    • REGISTRY_HOST must match the host in KANIKO_DESTINATION exactly, port included.
    • Pulls don't change: Forgejo stores images by owner and name, so they're still pulled as git.van-hemmen.com/myorg/myapp:<tag>.
    • Invalid values stop the job before the build, for example REGISTRY_INSECURE=ture.
    • No change when unset: without the setting, the Kaniko command is exactly as in 26.7.0.

    See "Pushing to an in-cluster registry" in the README.

    Full changelog: 26.7.0...26.37.0

    Downloads