deploy(dev): pin sandbox to sha-d0a1cee6 + IfNotPresent pull policy

Puts today's merged dev on the sandbox (S/MIME, offline replica, SRC
branding) without waiting on CI, which still can't push anywhere: GitLab's
registry vhost serves Rails/dependency-proxy (see .gitlab-ci.yml) and GHCR
needs a PAT that only a human can mint.

The amd64 image was built locally and side-loaded into all three nodes'
containerd via `microk8s ctr images import`, so IfNotPresent is required -
Always would ignore the local image and try to pull a tag no registry has.
IfNotPresent is the correct policy for immutable sha- tags regardless; see
the comment in patch-image-pull-policy.yaml for the full runbook.
This commit is contained in:
Bernd Rodler
2026-08-05 19:47:28 +02:00
parent 2e8bb9983a
commit 9b5870ca69
3 changed files with 31 additions and 1 deletions
@@ -8,4 +8,4 @@ kind: Component
images: images:
- name: ghcr.io/brvncde-dotcom/vncmail-plus-dev - name: ghcr.io/brvncde-dotcom/vncmail-plus-dev
newName: ghcr.io/brvncde-dotcom/vncmail-plus-dev newName: ghcr.io/brvncde-dotcom/vncmail-plus-dev
newTag: latest newTag: sha-d0a1cee6
@@ -8,6 +8,7 @@ resources:
patches: patches:
- path: patch-ingress.yaml - path: patch-ingress.yaml
- path: patch-image-pull-policy.yaml
components: components:
- image-tag - image-tag
@@ -0,0 +1,29 @@
# base/deployment.yaml sets imagePullPolicy: Always, which is the right
# default for a mutable tag like :latest. The dev overlay pins an immutable
# sha-<commit> tag instead (see image-tag/), and for an immutable tag Always
# is pure waste - the content behind that tag can never change, so re-pulling
# it on every pod start only adds a registry round-trip and a hard dependency
# on the registry being reachable at scheduling time.
#
# It is also load-bearing right now: until CI can actually push (GitLab's
# registry vhost serves Rails, not the registry - see .gitlab-ci.yml's
# "Registry history" note), sha- tagged images are side-loaded straight into
# each node's containerd:
#
# docker save --platform linux/amd64 -o vncmail.tar <image>:<tag>
# scp vncmail.tar dev-k8s-N:/tmp/ && ssh dev-k8s-N \
# 'microk8s ctr images import /tmp/vncmail.tar'
#
# imported to ALL of dev-k8s-1/2/3 so the pod can schedule anywhere. With
# Always, kubelet would ignore that local image and fail on a registry pull
# for a tag the registry has never seen.
apiVersion: apps/v1
kind: Deployment
metadata:
name: vncmail-plus
spec:
template:
spec:
containers:
- name: vncmail-plus
imagePullPolicy: IfNotPresent