7915346868
scan.yaml / test (push) Successful in 8s
chore(deps): update gitea/gitea docker tag to v28 (#58)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [gitea/gitea](https://github.com/go-gitea/gitea) | major | `1.27.3` → `28.0.0` |

---

### Release Notes

<details>
<summary>go-gitea/gitea (gitea/gitea)</summary>

### [`v28.0.0`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#2800---2026-09-30)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.27.3...v28.0.0)

- BREAKING
  - Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#&#8203;39426](https://github.com/go-gitea/gitea/pull/39426))
  - Feat(actions)!: add RUN\_RETENTION\_DAYS to delete old action runs ([#&#8203;38855](https://github.com/go-gitea/gitea/pull/38855))

- SECURITY
  - Fix(git): reject invalid and duplicate Git objects on push ([#&#8203;39472](https://github.com/go-gitea/gitea/pull/39472))
  - Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#&#8203;39426](https://github.com/go-gitea/gitea/pull/39426))
  - Fix(ssh): identify presented public keys by fingerprint ([#&#8203;39423](https://github.com/go-gitea/gitea/pull/39423))
  - Fix(actions): keep cancelled and unapproved fork PR runs behind the approval gate ([#&#8203;39399](https://github.com/go-gitea/gitea/pull/39399))
  - Fix(deps): update golang.org/x/crypto SSH to address denial of service ([#&#8203;39219](https://github.com/go-gitea/gitea/pull/39219))
  - Fix(repo): enforce repository-scoped authorization for team access, deletion, and package unlinking ([#&#8203;39063](https://github.com/go-gitea/gitea/pull/39063))

- FEATURES
  - Feat(actions): update actionslib, support `self:`, misc fixes ([#&#8203;39358](https://github.com/go-gitea/gitea/pull/39358))
  - Feat(api): list all packages for site administrators ([#&#8203;38968](https://github.com/go-gitea/gitea/pull/38968))
  - Feat: manage bot accounts from the admin UI, API and CLI ([#&#8203;38966](https://github.com/go-gitea/gitea/pull/38966))
  - Feat(user): Personal access tokens can be regenerated ([#&#8203;38907](https://github.com/go-gitea/gitea/pull/38907))
  - Feat(actions): support `$/` prefix in reusable workflow `uses:` ([#&#8203;38822](https://github.com/go-gitea/gitea/pull/38822))
  - Feat(actions): add force-cancel workflow run API ([#&#8203;38756](https://github.com/go-gitea/gitea/pull/38756))
  - Feat(licenses): support REUSE specification in licenses ([#&#8203;38720](https://github.com/go-gitea/gitea/pull/38720))
  - Feat(api): add project APIs ([#&#8203;38691](https://github.com/go-gitea/gitea/pull/38691))
  - Feat(webhook): fire repository event on repo rename ([#&#8203;38641](https://github.com/go-gitea/gitea/pull/38641))
  - Feat: admin impersonates a user ([#&#8203;38614](https://github.com/go-gitea/gitea/pull/38614))
  - Feat(actions): add build queue view ([#&#8203;38585](https://github.com/go-gitea/gitea/pull/38585))
  - Feat(setting): add shared \[redis] section as default for redis-backed subsystems ([#&#8203;38550](https://github.com/go-gitea/gitea/pull/38550))
  - Feat(repo): prioritize well-known READMEs and optimize discovery ([#&#8203;38532](https://github.com/go-gitea/gitea/pull/38532))
  - Feat(actions): implement adaptive auto-refresh for workflow runs list ([#&#8203;38329](https://github.com/go-gitea/gitea/pull/38329))
  - Feat(auth): add `disable-2fa` command ([#&#8203;38275](https://github.com/go-gitea/gitea/pull/38275))
  - Feat: Add audit logging ([#&#8203;38189](https://github.com/go-gitea/gitea/pull/38189))
  - Feat(repo): add quick repository switcher to repo header ([#&#8203;38188](https://github.com/go-gitea/gitea/pull/38188))
  - Feat(repo): support file exclusion logic in .gitea/template in template generation ([#&#8203;38064](https://github.com/go-gitea/gitea/pull/38064))
  - Feat(web): Add org removal functionality to admin user details page ([#&#8203;38013](https://github.com/go-gitea/gitea/pull/38013))
  - Feat: add watch options ([#&#8203;37571](https://github.com/go-gitea/gitea/pull/37571))
  - Feat: add deploy tokens ([#&#8203;37306](https://github.com/go-gitea/gitea/pull/37306))
  - Feat(diff): Add search and extension filter to diff sidebar ([#&#8203;37068](https://github.com/go-gitea/gitea/pull/37068))
  - Feat: Replace SSE with WebSocket for UI notifications ([#&#8203;36965](https://github.com/go-gitea/gitea/pull/36965))
  - Feat(actions): Add artifact preview in Actions run view ([#&#8203;36754](https://github.com/go-gitea/gitea/pull/36754))
  - Feat(packages): add support for uploading helm provenance files ([#&#8203;36695](https://github.com/go-gitea/gitea/pull/36695))
  - Feat: Add support for dynamic matrix evaluation in Gitea Actions workflows ([#&#8203;36564](https://github.com/go-gitea/gitea/pull/36564))
  - Feat: Add max-parallel Support for Gitea Actions ([#&#8203;36357](https://github.com/go-gitea/gitea/pull/36357))
  - Feat(actions): Add Actions API endpoints for workflow run management and logs ([#&#8203;35382](https://github.com/go-gitea/gitea/pull/35382))
  - Feat: Add block on pending codeowner reviews branch protection ([#&#8203;34995](https://github.com/go-gitea/gitea/pull/34995))

- ENHANCEMENTS
  - Enhance: allow auto-closing PRs from PRs ([#&#8203;39393](https://github.com/go-gitea/gitea/pull/39393))
  - Enhance(actions): add pending job status and align job statuses with GitHub ([#&#8203;39376](https://github.com/go-gitea/gitea/pull/39376))
  - Enhance(acme): add configurable ACME profile ([#&#8203;39375](https://github.com/go-gitea/gitea/pull/39375))
  - Enhance(emoji): update to Unicode 17, unify and lazy-load emoji data ([#&#8203;39363](https://github.com/go-gitea/gitea/pull/39363))
  - Enhance: improve issue-pattern capture groups and support both internal\&external trackers enabled ([#&#8203;39354](https://github.com/go-gitea/gitea/pull/39354))
  - Enhance: update mermaid to v12 ([#&#8203;39331](https://github.com/go-gitea/gitea/pull/39331))
  - Enhance(notifications): mark current notification page as read ([#&#8203;39294](https://github.com/go-gitea/gitea/pull/39294))
  - Enhance: support `ETag` on streamed repository archives, support `If-None-Match: *` ([#&#8203;39289](https://github.com/go-gitea/gitea/pull/39289))
  - Enhance: truncate but show long lines in diffs ([#&#8203;39279](https://github.com/go-gitea/gitea/pull/39279))
  - Enhance(packages): implement npm single-version API and add per-version repository ([#&#8203;39267](https://github.com/go-gitea/gitea/pull/39267))
  - Enhance: move window\.config to JSON, improve CSP format ([#&#8203;39236](https://github.com/go-gitea/gitea/pull/39236))
  - Enhance: improve commit page header ([#&#8203;39229](https://github.com/go-gitea/gitea/pull/39229))
  - Enhance: Improve validation errors for secrets/variables ([#&#8203;39221](https://github.com/go-gitea/gitea/pull/39221))
  - Enhance(repo): check full repo name for dangerous operations ([#&#8203;39213](https://github.com/go-gitea/gitea/pull/39213))
  - Enhance(web): hide attachment dropzone on preview tab in combo editor ([#&#8203;39204](https://github.com/go-gitea/gitea/pull/39204))
  - Enhance(web): show attachment URL and UUID in dropzone preview ([#&#8203;39203](https://github.com/go-gitea/gitea/pull/39203))
  - Enhance(actions): make workflow dispatch choice dropdown support search ([#&#8203;39154](https://github.com/go-gitea/gitea/pull/39154))
  - Enhance(repo): unify diff stats on commit pages, misc diff tweaks ([#&#8203;39134](https://github.com/go-gitea/gitea/pull/39134))
  - Enhance: use browser's locale to detect week's first day for the contribution map ([#&#8203;38995](https://github.com/go-gitea/gitea/pull/38995))
  - Enhance(ui): forced colors mode enhancements ([#&#8203;38991](https://github.com/go-gitea/gitea/pull/38991))
  - Enhance: user-friendly packages setup manual ([#&#8203;38946](https://github.com/go-gitea/gitea/pull/38946))
  - Enhance: inherit team access for all units ([#&#8203;38938](https://github.com/go-gitea/gitea/pull/38938))
  - Enhance(admin): show impersonation banner and keep password change with the user ([#&#8203;38924](https://github.com/go-gitea/gitea/pull/38924))
  - Enhance(ui): tint toast backgrounds by level ([#&#8203;38919](https://github.com/go-gitea/gitea/pull/38919))
  - Enhance(repo): add default object format setting ([#&#8203;38877](https://github.com/go-gitea/gitea/pull/38877))
  - Enhance(actions): set ref\_protected in context ([#&#8203;38852](https://github.com/go-gitea/gitea/pull/38852))
  - Enhance(ui): restyle toasts ([#&#8203;38842](https://github.com/go-gitea/gitea/pull/38842))
  - Enhance: refine repo watching ([#&#8203;38835](https://github.com/go-gitea/gitea/pull/38835))
  - Enhance: fall back to DEFAULT\_TEMPLATE.md when style-specific template is missing ([#&#8203;38803](https://github.com/go-gitea/gitea/pull/38803))
  - Enhance(api): add GitHub-compatible /repos/{owner}/{repo}/commits/{ref} endpoint ([#&#8203;38770](https://github.com/go-gitea/gitea/pull/38770))
  - Enhance(api): expose file mode in contents API response ([#&#8203;38713](https://github.com/go-gitea/gitea/pull/38713))
  - Enhance(tls): use go's tls defaults ([#&#8203;38687](https://github.com/go-gitea/gitea/pull/38687))
  - Enhance(ui): improve luminance calculations ([#&#8203;38682](https://github.com/go-gitea/gitea/pull/38682))
  - Enhance(api): add `tag_filter` query parameter to release list API ([#&#8203;38681](https://github.com/go-gitea/gitea/pull/38681))
  - Enhance(actions): replace `ansi_up` with first-party code ([#&#8203;38619](https://github.com/go-gitea/gitea/pull/38619))
  - Enhance: keep status check list scrolled on merge box reload ([#&#8203;38597](https://github.com/go-gitea/gitea/pull/38597))
  - Enhance(actions): action view enhancements ([#&#8203;38594](https://github.com/go-gitea/gitea/pull/38594))
  - Enhance(ui): tweak tooltip style and misc fixes ([#&#8203;38524](https://github.com/go-gitea/gitea/pull/38524))
  - Enhance: improve e-mail templates ([#&#8203;38396](https://github.com/go-gitea/gitea/pull/38396))
  - Enhance(webhook): add reviewer name to MS Teams review request notifications ([#&#8203;38289](https://github.com/go-gitea/gitea/pull/38289))
  - Enhance: extend <video> tag allowed attributes ([#&#8203;38279](https://github.com/go-gitea/gitea/pull/38279))
  - Enhance(packages/npm): expand version metadata and support npm deprecate ([#&#8203;37890](https://github.com/go-gitea/gitea/pull/37890))

- PERFORMANCE
  - Perf(references): scan only the keyword window before a reference ([#&#8203;39396](https://github.com/go-gitea/gitea/pull/39396))
  - Perf(frontend): enable vite module preload ([#&#8203;39332](https://github.com/go-gitea/gitea/pull/39332))
  - Perf(gitdiff): optimize inline diff highlighting using cache ([#&#8203;38706](https://github.com/go-gitea/gitea/pull/38706))

- BUGFIXES
  - Fix(actions): preserve admitted jobs and runs in their concurrency group ([#&#8203;39461](https://github.com/go-gitea/gitea/pull/39461))
  - Fix(api): commit tree SHA is the commit ID ([#&#8203;39449](https://github.com/go-gitea/gitea/pull/39449))
  - Fix: PR merge ([#&#8203;39442](https://github.com/go-gitea/gitea/pull/39442))
  - Fix(actions): evaluate job-level `if:` before concurrency check ([#&#8203;39437](https://github.com/go-gitea/gitea/pull/39437))
  - Fix(api): allow pending-inline-comment-only reviews ([#&#8203;39433](https://github.com/go-gitea/gitea/pull/39433))
  - Fix: sanitize external render command line arguments ([#&#8203;39417](https://github.com/go-gitea/gitea/pull/39417))
  - Fix(LFS): recalculate repo LFSSize after gc-lfs removes orphaned data ([#&#8203;39406](https://github.com/go-gitea/gitea/pull/39406))
  - Fix(indexer): index full file paths and real offsets in bleve ([#&#8203;39405](https://github.com/go-gitea/gitea/pull/39405))
  - Fix(git): keep leading dashes in git grep search patterns ([#&#8203;39404](https://github.com/go-gitea/gitea/pull/39404))
  - Fix: use clearer message for ldap auth failure ([#&#8203;39392](https://github.com/go-gitea/gitea/pull/39392))
  - Fix(repo): commit page fails to render unsigned commits with a different committer ([#&#8203;39381](https://github.com/go-gitea/gitea/pull/39381))
  - Fix: focus confirm button and use red for delete confirmations ([#&#8203;39350](https://github.com/go-gitea/gitea/pull/39350))
  - Fix(migrations): preserve SHA-256 pull request commit IDs ([#&#8203;39343](https://github.com/go-gitea/gitea/pull/39343))
  - Fix(ui): misc ui fixes ([#&#8203;39336](https://github.com/go-gitea/gitea/pull/39336))
  - Fix(actions): use gitea's clock for actions durations ([#&#8203;39323](https://github.com/go-gitea/gitea/pull/39323))
  - Fix(actions): never show negative running durations ([#&#8203;39322](https://github.com/go-gitea/gitea/pull/39322))
  - Fix: package registry keypair creation race ([#&#8203;39319](https://github.com/go-gitea/gitea/pull/39319))
  - Fix: add default timeout and handle errors for HaveIBeenPwned API ([#&#8203;39316](https://github.com/go-gitea/gitea/pull/39316))
  - Fix(user): unify email validation for registration and settings ([#&#8203;39304](https://github.com/go-gitea/gitea/pull/39304))
  - Fix(ui): use button elements for branch and tag dropdown tabs ([#&#8203;39285](https://github.com/go-gitea/gitea/pull/39285))
  - Fix(auth): fix ssh and gpg key verification on windows ([#&#8203;39283](https://github.com/go-gitea/gitea/pull/39283))
  - Fix(feed): use meaningful lines as comment excerpt ([#&#8203;39276](https://github.com/go-gitea/gitea/pull/39276))
  - Fix(projects): allow max columns to the limit ([#&#8203;39272](https://github.com/go-gitea/gitea/pull/39272))
  - Fix: pass merge commit messages to git via stdin ([#&#8203;39269](https://github.com/go-gitea/gitea/pull/39269))
  - Fix(repo): surface unrelated histories on Sync Fork ([#&#8203;39258](https://github.com/go-gitea/gitea/pull/39258))
  - Fix: avoid nil panic and refactor some trivial problems ([#&#8203;39251](https://github.com/go-gitea/gitea/pull/39251))
  - Fix: restore missing blob file when re-publishing a package ([#&#8203;39239](https://github.com/go-gitea/gitea/pull/39239))
  - Fix(automerge): validate head commit before merge ([#&#8203;39235](https://github.com/go-gitea/gitea/pull/39235))
  - Fix(httplib): prevent leaking localhost:3000 in public links ([#&#8203;39217](https://github.com/go-gitea/gitea/pull/39217))
  - Fix(setting): honor bare -1 for timeout settings ([#&#8203;39181](https://github.com/go-gitea/gitea/pull/39181))
  - Fix: correct repo/attatchment absolute url and release layout ([#&#8203;39178](https://github.com/go-gitea/gitea/pull/39178))
  - Fix(web): populate the reason for "cannot commit to branch" in web editor commit form ([#&#8203;39155](https://github.com/go-gitea/gitea/pull/39155))
  - Fix(process): reap entire process group on cmd.Cancel ([#&#8203;39143](https://github.com/go-gitea/gitea/pull/39143))
  - Fix: recognize linguist language aliases ([#&#8203;39135](https://github.com/go-gitea/gitea/pull/39135))
  - Fix(repo): preserve transfer recipient collaboration ([#&#8203;39042](https://github.com/go-gitea/gitea/pull/39042))
  - Fix(db): make paginated database reads always require "order" option ([#&#8203;39017](https://github.com/go-gitea/gitea/pull/39017))
  - Fix: make local queue PopItem can be notified ([#&#8203;39011](https://github.com/go-gitea/gitea/pull/39011))
  - Fix: classify git failures on stderr, restrict migration failure detail ([#&#8203;39010](https://github.com/go-gitea/gitea/pull/39010))
  - Fix: allow re-requesting uncounted review approvals ([#&#8203;38988](https://github.com/go-gitea/gitea/pull/38988))
  - Fix(actions): allow larger scheduled workflows ([#&#8203;38985](https://github.com/go-gitea/gitea/pull/38985))
  - Fix: resolve actions commit status permission per repository ([#&#8203;38977](https://github.com/go-gitea/gitea/pull/38977))
  - Fix(deps): update module golang.org/x/image to v0.45.0 \[security] ([#&#8203;38930](https://github.com/go-gitea/gitea/pull/38930))
  - Fix(deps): update module golang.org/x/mod to v0.40.0 \[security] ([#&#8203;38914](https://github.com/go-gitea/gitea/pull/38914))
  - Fix: dedupe issue cross-reference timeline entries ([#&#8203;38881](https://github.com/go-gitea/gitea/pull/38881))
  - Fix(server): set `ReadHeaderTimeout` on HTTP servers ([#&#8203;38878](https://github.com/go-gitea/gitea/pull/38878))
  - Fix(repo): avoid a repo-sized temp file for every bundle download ([#&#8203;38863](https://github.com/go-gitea/gitea/pull/38863))
  - Fix(lfs): ensure lock listing paginates with a total order ([#&#8203;38850](https://github.com/go-gitea/gitea/pull/38850))
  - Fix(avatar): use sha256 and inline the federated avatar lookup ([#&#8203;38843](https://github.com/go-gitea/gitea/pull/38843))
  - Fix(gitdiff): render exact-limit diffs and zero-limit comments ([#&#8203;38838](https://github.com/go-gitea/gitea/pull/38838))
  - Fix(deps): update dependency mermaid to v11.16.1 \[security] ([#&#8203;38813](https://github.com/go-gitea/gitea/pull/38813))
  - Fix: misc fixes in pub/gpg/tests ([#&#8203;38809](https://github.com/go-gitea/gitea/pull/38809))
  - Fix: git diff blob excerpt ([#&#8203;38808](https://github.com/go-gitea/gitea/pull/38808))
  - Fix(packages): show error for duplicate cleanup rules [#&#8203;37820](https://github.com/go-gitea/gitea/issues/37820) ([#&#8203;38786](https://github.com/go-gitea/gitea/pull/38786))
  - Fix(actions): fix runner docs link ([#&#8203;38783](https://github.com/go-gitea/gitea/pull/38783))
  - Fix: git cache ([#&#8203;38763](https://github.com/go-gitea/gitea/pull/38763))
  - Fix(actions): evaluate each `${{ }}` part on its own ([#&#8203;38754](https://github.com/go-gitea/gitea/pull/38754))
  - Fix: don't report failed network requests as JavaScript errors ([#&#8203;38732](https://github.com/go-gitea/gitea/pull/38732))
  - Fix(gitdiff): prevent index out of range panic in GetLineTypeMarker ([#&#8203;38728](https://github.com/go-gitea/gitea/pull/38728))
  - Fix(api): document X-Total-Count instead of non-existent X-Total header ([#&#8203;38717](https://github.com/go-gitea/gitea/pull/38717))
  - Fix(actions): dynamic matrix expansion correctness fixes ([#&#8203;38690](https://github.com/go-gitea/gitea/pull/38690))
  - Fix(auth): record last sign-in on reverse proxy login ([#&#8203;38672](https://github.com/go-gitea/gitea/pull/38672))
  - Fix(api): accept fully-qualified refs in contents API ([#&#8203;38650](https://github.com/go-gitea/gitea/pull/38650))
  - Fix(deps): update module github.com/getkin/kin-openapi to v0.144.0 \[security] ([#&#8203;38623](https://github.com/go-gitea/gitea/pull/38623))
  - Fix(deps): update dependency js-yaml to v5.2.2 \[security] ([#&#8203;38622](https://github.com/go-gitea/gitea/pull/38622))
  - Fix: abort superseded issue suggestion requests ([#&#8203;38620](https://github.com/go-gitea/gitea/pull/38620))
  - Fix(issue): display error toast on batch action failures instead of reloading page ([#&#8203;38593](https://github.com/go-gitea/gitea/pull/38593))
  - Fix(deps): update module google.golang.org/grpc to v1.82.1 \[security] ([#&#8203;38567](https://github.com/go-gitea/gitea/pull/38567))
  - Fix(deps): update module github.com/google/go-github/v88 to v89 ([#&#8203;38433](https://github.com/go-gitea/gitea/pull/38433))
  - Fix(deps): update go dependencies ([#&#8203;38429](https://github.com/go-gitea/gitea/pull/38429))
  - Fix(deps): update go dependencies ([#&#8203;38346](https://github.com/go-gitea/gitea/pull/38346))
  - Fix(deps): update npm dependencies ([#&#8203;38342](https://github.com/go-gitea/gitea/pull/38342))
  - Fix(base): correct natural sort of numbers with leading zeros ([#&#8203;38163](https://github.com/go-gitea/gitea/pull/38163))
  - Fix(ui): avoid layout shifts in `overflow-menu` and repo filter ([#&#8203;37818](https://github.com/go-gitea/gitea/pull/37818))
  - Fix: make auth source group sync correctly handle team removal ([#&#8203;37161](https://github.com/go-gitea/gitea/pull/37161))
  - Fix(release): separate publication time from the release date ([#&#8203;36761](https://github.com/go-gitea/gitea/pull/36761))

- TESTING
  - Test: stop tests from writing into `~/.ssh` ([#&#8203;39348](https://github.com/go-gitea/gitea/pull/39348))
  - Test(e2e): log out to switch users in pr-review test ([#&#8203;39328](https://github.com/go-gitea/gitea/pull/39328))
  - Test: release fixtures loader lock before database work ([#&#8203;39263](https://github.com/go-gitea/gitea/pull/39263))
  - Test: speed up tests, fix transaction bug ([#&#8203;39030](https://github.com/go-gitea/gitea/pull/39030))
  - Test: run frontend unit tests in browsers ([#&#8203;38860](https://github.com/go-gitea/gitea/pull/38860))
  - Test(pubsub): stop racing the Redis SUBSCRIBE ack ([#&#8203;38661](https://github.com/go-gitea/gitea/pull/38661))
  - Test(e2e): add pull request merge box test, update AGENTS.md ([#&#8203;38576](https://github.com/go-gitea/gitea/pull/38576))
  - Test(e2e): deterministically wait for event stream in logout propagation test ([#&#8203;38535](https://github.com/go-gitea/gitea/pull/38535))

- BUILD
  - Refactor: fix `go vet` errors related to composite literals ([#&#8203;39341](https://github.com/go-gitea/gitea/pull/39341))
  - Build(gogit): disable gogit builds for stable releases ([#&#8203;39324](https://github.com/go-gitea/gitea/pull/39324))
  - Refactor: replace jquery.are-you-sure with first-party code ([#&#8203;39233](https://github.com/go-gitea/gitea/pull/39233))
  - Refactor: http request binding ([#&#8203;38971](https://github.com/go-gitea/gitea/pull/38971))
  - Refactor: clean up git repo and model migration packages ([#&#8203;38564](https://github.com/go-gitea/gitea/pull/38564))
  - Refactor: prepare to decouple the "model migration" package and "models" package ([#&#8203;38533](https://github.com/go-gitea/gitea/pull/38533))
  - Build: fix snapcraft release ([#&#8203;38260](https://github.com/go-gitea/gitea/pull/38260))
  - Build(release): use native golang toolchain for official release builds ([#&#8203;37828](https://github.com/go-gitea/gitea/pull/37828))

- DOCS
  - Docs(webhook): review\.type comment lists values the webhook never sends ([#&#8203;39451](https://github.com/go-gitea/gitea/pull/39451))
  - Docs(api): document verification and files on the compare endpoint ([#&#8203;39440](https://github.com/go-gitea/gitea/pull/39440))
  - Docs(api): name the unadopted-repository search parameter query ([#&#8203;39370](https://github.com/go-gitea/gitea/pull/39370))
  - Docs: remove unused COOKIE\_USERNAME from app.example.ini ([#&#8203;39365](https://github.com/go-gitea/gitea/pull/39365))
  - Docs: document NOTICE\_ON\_SUCCESS for every cron task ([#&#8203;39352](https://github.com/go-gitea/gitea/pull/39352))
  - Docs: correct ALLOW\_LOCALNETWORKS description in app.example.ini ([#&#8203;39240](https://github.com/go-gitea/gitea/pull/39240))
  - Docs: fix typo in README about app.ini restart ([#&#8203;39223](https://github.com/go-gitea/gitea/pull/39223))
  - Docs: fix dead localization doc link in the READMEs ([#&#8203;39211](https://github.com/go-gitea/gitea/pull/39211))
  - Docs: Update CHANGELOG for release 1.27.3 ([#&#8203;39170](https://github.com/go-gitea/gitea/pull/39170))
  - Docs: Update CHANGELOG for version 1.27.2 ([#&#8203;38923](https://github.com/go-gitea/gitea/pull/38923))
  - Docs: Update PGP key expiration date to July 23, 2027 ([#&#8203;38747](https://github.com/go-gitea/gitea/pull/38747))
  - Docs(api): document 401/403 responses for user key endpoints ([#&#8203;38711](https://github.com/go-gitea/gitea/pull/38711))
  - Docs: Update Changelog for release v1.27.1 ([#&#8203;38670](https://github.com/go-gitea/gitea/pull/38670))
  - Docs: Update Changelog for 1.27 ([#&#8203;38440](https://github.com/go-gitea/gitea/pull/38440))
  - Docs: Update Security docs ([#&#8203;38422](https://github.com/go-gitea/gitea/pull/38422))

- MISC
  - Refactor: make git http respond error message ([#&#8203;39390](https://github.com/go-gitea/gitea/pull/39390))
  - Refactor(api): convert bot accounts through the admin user edit endpoint ([#&#8203;39355](https://github.com/go-gitea/gitea/pull/39355))
  - Refactor: replace AWS SDK with a REST client for CodeCommit migration ([#&#8203;39330](https://github.com/go-gitea/gitea/pull/39330))
  - Refactor: replace Azure Blob SDK with a REST client ([#&#8203;39315](https://github.com/go-gitea/gitea/pull/39315))
  - Refactor: npm route handlers ([#&#8203;39275](https://github.com/go-gitea/gitea/pull/39275))
  - Refactor: GetDiffShortStat and fix panic caused by inconsistent "changed file number" ([#&#8203;39248](https://github.com/go-gitea/gitea/pull/39248))
  - Refactor(templates): update djlint to 1.46.0 and resolve its new findings ([#&#8203;39231](https://github.com/go-gitea/gitea/pull/39231))
  - Refactor: pagination/pager ([#&#8203;39162](https://github.com/go-gitea/gitea/pull/39162))
  - Refactor: share package registry error status classification ([#&#8203;39133](https://github.com/go-gitea/gitea/pull/39133))
  - Refactor: drop two unmaintained dependencies, rename the byte size helpers ([#&#8203;39083](https://github.com/go-gitea/gitea/pull/39083))
  - Refactor(automerge): fix error handling, populate recent automerge tasks on restart ([#&#8203;39001](https://github.com/go-gitea/gitea/pull/39001))
  - Refactor: deploy key and private route handlers ([#&#8203;38999](https://github.com/go-gitea/gitea/pull/38999))
  - Refactor: wiki edit form ([#&#8203;38918](https://github.com/go-gitea/gitea/pull/38918))
  - Refactor: clean up form binding & validation ([#&#8203;38873](https://github.com/go-gitea/gitea/pull/38873))
  - Refactor: markup render ([#&#8203;38864](https://github.com/go-gitea/gitea/pull/38864))
  - Refactor: api token scope check ([#&#8203;38862](https://github.com/go-gitea/gitea/pull/38862))
  - Refactor: replace `gliderlabs/ssh` with `golang.org/x/crypto/ssh` ([#&#8203;38837](https://github.com/go-gitea/gitea/pull/38837))
  - Refactor: form binding validation ([#&#8203;38832](https://github.com/go-gitea/gitea/pull/38832))
  - Refactor: prepare vue components for vapor mode ([#&#8203;38798](https://github.com/go-gitea/gitea/pull/38798))
  - Refactor: use the shared workflow model from actionslib ([#&#8203;38768](https://github.com/go-gitea/gitea/pull/38768))
  - Refactor(modelmigration): thread context through migration functions ([#&#8203;38758](https://github.com/go-gitea/gitea/pull/38758))
  - Refactor: migrate remaining Vue components to `<script setup>` ([#&#8203;38752](https://github.com/go-gitea/gitea/pull/38752))
  - Refactor: introduce trString for frontend ([#&#8203;38741](https://github.com/go-gitea/gitea/pull/38741))
  - Refactor(diff): drive diff DOM init from the global selector observer ([#&#8203;38740](https://github.com/go-gitea/gitea/pull/38740))
  - Refactor(git): clarify GetBranch behavior to make it only gets an existing branch ([#&#8203;38662](https://github.com/go-gitea/gitea/pull/38662))
  - Refactor: replace debounce/throttle deps with first-party code ([#&#8203;38610](https://github.com/go-gitea/gitea/pull/38610))
  - Refactor: hide git repo path details from more packages ([#&#8203;38601](https://github.com/go-gitea/gitea/pull/38601))
  - Refactor: retry file remove/rename when a file is busy and clean up os detection ([#&#8203;38588](https://github.com/go-gitea/gitea/pull/38588))
  - Perf(emoji): optimize FindEmojiSubmatchIndex using slice-based Trie ([#&#8203;38573](https://github.com/go-gitea/gitea/pull/38573))
  - Refactor: implement mcaptcha client and add comments/tests ([#&#8203;38561](https://github.com/go-gitea/gitea/pull/38561))
  - Refactor: use WithRepo instead of WithDir for most git operations, clean up model migrations ([#&#8203;38555](https://github.com/go-gitea/gitea/pull/38555))
  - Refactor: remove Path field from git.Repository ([#&#8203;38552](https://github.com/go-gitea/gitea/pull/38552))
  - Refactor: make git package handle all git operations ([#&#8203;38543](https://github.com/go-gitea/gitea/pull/38543))
  - Refactor: remove unnecessary git command wrapper functions ([#&#8203;38531](https://github.com/go-gitea/gitea/pull/38531))
  - Refactor: git repo and relative path handling ([#&#8203;38522](https://github.com/go-gitea/gitea/pull/38522))
  - Refactor: clean up fragile diff render templates, use backend typed structs ([#&#8203;38517](https://github.com/go-gitea/gitea/pull/38517))
  - Refactor: correct git repo design and fix some legacy problems ([#&#8203;38512](https://github.com/go-gitea/gitea/pull/38512))
  - Refactor: fix legacy problems in cmd/serv.go ([#&#8203;38505](https://github.com/go-gitea/gitea/pull/38505))
  - Refactor: remove Ctx field from git.Repository ([#&#8203;38500](https://github.com/go-gitea/gitea/pull/38500))
  - Refactor: decouple git.Repository(ctx) from git.Commit & git.Tree ([#&#8203;38464](https://github.com/go-gitea/gitea/pull/38464))
  - Refactor: introduce ActivePageTimer to help to do partial page refresh ([#&#8203;38372](https://github.com/go-gitea/gitea/pull/38372))

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/58
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
2026-10-04 21:53:01 +00:00
2026-09-23 20:30:09 +02:00
2026-04-27 11:33:24 +02:00
2026-04-24 08:48:53 +00:00
2026-09-30 10:35:10 +02:00
2026-04-18 18:14:00 +00:00
2026-04-25 11:49:17 +02:00
2026-05-29 15:48:28 +00:00
2026-06-29 17:02:50 +02:00
2026-04-28 20:38:59 +02:00
2026-05-29 15:48:28 +00:00
2026-09-27 22:11:47 +00:00

Kubernetes Cluster - GitOps Configuration

Kubernetes cluster bootstrapping and GitOps configuration repository using ArgoCD for multi-cloud Kubernetes (UpCloud, AWS EKS, Azure AKS, GCP GKE)

GitOps Kubernetes


📚 Complete Documentation

New developers and operators: Please refer to our comprehensive documentation for detailed guides and references:

🎯 START HERE: Documentation Index

Document Description Audience
GitOps Architecture System architecture, repository structure, GitOps workflows, security model Everyone (start here)
Developer Guide Local setup, deploying apps, managing secrets, troubleshooting Developers
Operations Runbook Cluster bootstrap, day-to-day operations, incident response, maintenance Platform Engineers, SREs
Technical Reference Component specs, Helm charts, ArgoCD config, Kyverno policies, API docs Everyone (reference)

🚀 Quick Start

For New Developers

# 1. Clone repositories
git clone https://git.forteapps.net/Forte/launchpad.git
git clone ssh://git@git.forteapps.net:2222/Forte/helm-prod-values.git

# 2. Read the guides
# - Start: docs/GITOPS-ARCHITECTURE.md
# - Follow: docs/DEVELOPER-GUIDE.md

# 3. Deploy your first app (see Developer Guide)

For Operators

# 1. Bootstrap new cluster
./bootstrap.sh

# 2. Verify deployment
kubectl get applications -n argocd
kubectl get pods --all-namespaces

# 3. Read Operations Runbook for day-to-day tasks

📋 Overview

This repository contains the complete GitOps configuration for our Kubernetes cluster, using the App-of-Apps pattern with ArgoCD.

What's Inside

  • Infrastructure Applications: Traefik, Cert-Manager, Kyverno, Prometheus, Grafana, Loki, Tempo, Sealed Secrets, Homepage (platform dashboard)
  • Business Applications: MCP10X, MusicMan, Dot-AI Stack, ArgoCD MCP
  • Policies: Kyverno security policies for secret management, namespace controls, pod verification
  • Monitoring: Full observability stack with metrics, logs, traces, and alerting
  • Secrets: Sealed Secrets for secure Git storage

Key Features

✅ GitOps-Native: Git is the single source of truth ✅ Auto-Sync: Changes automatically deployed (60s reconciliation) ✅ Self-Healing: Manual cluster changes are reverted ✅ Multi-Source: Separate chart templates from configuration ✅ Policy Enforcement: Kyverno ensures security and compliance ✅ Authentication: Automatic sidecar injection (token & OIDC support) ✅ TLS Everywhere: Automatic Let's Encrypt certificates ✅ Full Observability: Prometheus, Grafana, Loki, Tempo integration


🗂️ Repository Structure

.
├── bootstrap.sh                # Cluster initialization (ArgoCD + GitOps)
├── _app-of-apps-{cluster}.yaml # Root ArgoCD Application (per cluster)
│
├── .tofu/                     # Infrastructure provisioning (OpenTofu)
│   ├── platforms/             # Per-platform IaC (one dir per cloud)
│   │   ├── aks/               # Azure AKS (modules/ + dev/ + prod/ + workload/)
│   │   ├── eks/               # AWS EKS
│   │   ├── gke/               # GCP GKE
│   │   └── upc/               # UpCloud
│   ├── configs/               # Platform credentials (git-ignored)
│   │   └── *.env.example      # Template for each platform
│   └── scripts/               # Cluster lifecycle scripts
│       ├── setup-cluster.sh   # Create cluster: ./setup-cluster.sh aks-dev
│       ├── teardown-cluster.sh
│       └── get-kubeconfig.sh
│
├── clusters/                  # Cluster metadata (domain, trustedIPs, etc.)
│
├── infra/                     # Infrastructure ArgoCD Applications (Kustomize multi-cluster)
│   ├── base/                  # Base ArgoCD Application manifests (one dir per component)
│   │   ├── kustomization.yaml # Aggregates all component subdirectories
│   │   ├── traefik-application/
│   │   │   ├── kustomization.yaml
│   │   │   └── traefik-application.yaml
│   │   ├── keycloak/
│   │   │   ├── kustomization.yaml
│   │   │   └── keycloak.yaml
│   │   ├── grafana/
│   │   ├── prometheus/
│   │   ├── ...               # Each component in its own subdirectory
│   │   └── secrets/
│   ├── overlays/              # Per-cluster overrides (Kustomize)
│   │   ├── upc-dev/           # UpCloud Dev — includes all base components
│   │   ├── upc-prod/         # UpCloud Prod — all components + patches
│   │   ├── aks-dev/          # Azure AKS Dev — selective components only
│   │   ├── aks-prod/         # Azure AKS Prod
│   │   ├── eks-dev/           # AWS EKS Dev
│   │   ├── eks-prod/         # AWS EKS Prod
│   │   ├── gke-dev/          # GCP GKE Dev
│   │   └── gke-prod/         # GCP GKE Prod
│   ├── dashboards/            # Grafana dashboard ConfigMaps
│   └── values/                # Helm value overrides
│       ├── base/              # Shared cloud-agnostic values
│       ├── upc-dev/           # UpCloud Dev (storage, LB, pricing)
│       ├── upc-prod/         # UpCloud Prod
│       ├── eks-dev/           # AWS EKS Dev
│       ├── eks-prod/         # AWS EKS Prod
│       ├── aks-dev/        # Azure AKS Dev
│       ├── aks-prod/       # Azure AKS Prod
│       ├── gke-dev/          # GCP GKE Dev
│       └── gke-prod/         # GCP GKE Prod
│
├── apps/                      # Business Applications (Kustomize, same pattern as infra)
│   ├── base/                  # One subdirectory per app
│   │   ├── kustomization.yaml
│   │   ├── musicman/
│   │   ├── mcp10x/
│   │   ├── dot-ai-stack/
│   │   ├── ts-mcp/
│   │   └── argo-mcp/
│   └── overlays/              # Per-cluster: cherry-pick or include all
│       ├── upc-dev/           # All apps
│       ├── upc-prod/         # All apps + patches
│       └── aks-dev/          # Selective apps only
│
├── cluster-resources/         # Cluster-wide Kubernetes resources
│   ├── letsencrypt-issuer.yaml
│   ├── kyverno-config.yaml
│   ├── *-sealed.yaml          # Sealed secrets
│   └── policies/              # Kyverno policies
│       ├── secret-cloner.yaml
│       ├── default-ns-blocker.yaml
│       ├── bare-pod-cleaner.yaml
│       └── auth-sidecar-injector.yaml
│
├── secrets/                   # Application secrets (sealed)
│   └── *-credentials-sealed.yaml
│
├── private/                   # Local-only files (Git-ignored)
│   └── *.yaml                 # Unsealed secrets (never committed)
│
└── docs/                      # 📚 Comprehensive documentation
    ├── README.md              # Documentation index
    ├── GITOPS-ARCHITECTURE.md # Architecture guide
    ├── DEVELOPER-GUIDE.md     # Developer onboarding
    ├── OPERATIONS-RUNBOOK.md  # Operations procedures
    └── REFERENCE.md           # Technical reference

See GitOps Architecture - Repository Structure for detailed explanation.


🏗️ Architecture

Three-Repository Pattern

Repository Purpose Who Edits How Often
launchpad (this repo) ArgoCD Applications, cluster resources Platform / DevOps engineers ✅ Often
forte-helm Generic Helm chart templates Platform engineers ❌ Rarely
helm-prod-values App-specific configuration & versions Developers / CI pipelines ✅ Sometimes

GitOps Workflow

Developer commits code → CI/CD builds image → Updates helm-prod-values → ArgoCD syncs → Deployed to cluster

Learn more: GitOps Architecture - GitOps Workflow


🔧 Common Tasks

Deploy a New Application

See detailed guide: Developer Guide - Deploying Your First Application

Quick version:

  1. Create apps/myapp.yaml (ArgoCD Application manifest)
  2. Create helm-prod-values/myapp/values.yaml (configuration)
  3. Create sealed secrets if needed
  4. Commit and push - ArgoCD auto-syncs!

Update an Existing Application

See detailed guide: Developer Guide - Updating an Existing Application

Quick version:

  • Update code: Push to app repo → CI/CD updates image tag in helm-prod-values
  • Update config: Edit helm-prod-values/myapp/values.yaml → commit → push

Manage Secrets

See detailed guide: Developer Guide - Working with Secrets

# Create plain secret
kubectl create secret generic myapp-creds \
  --from-literal=KEY=value \
  --dry-run=client -o yaml > private/myapp-creds.yaml

# Seal it
kubeseal --format=yaml --cert=pub-cert.pem \
  < private/myapp-creds.yaml > secrets/myapp-creds-sealed.yaml

# Commit sealed version
git add secrets/myapp-creds-sealed.yaml
git commit -m "Add myapp credentials"
git push

Enable Authentication

See detailed guide: Developer Guide - Enabling Authentication

Quick version:

# In helm-prod-values/myapp/values.yaml

# Token-based auth (simple)
auth:
  enabled: true
  type: token
  tokens:
  - your-secret-token-here

# OIDC auth (SSO)
auth:
  enabled: true
  type: oidc
  oidc:
    authority: https://auth.example.com/realms/master
    clientId: myapp

Then create OIDC secret (if using OIDC):

kubectl create secret generic auth-oidc \
  --from-literal=client-secret=your-oidc-secret \
  --from-literal=cookie-secret=$(openssl rand -hex 32) \
  --namespace=myapp | \
  kubeseal --format=yaml --cert=pub-cert.pem --namespace=myapp | \
  kubectl apply -f -

Bootstrap Cluster

See detailed guide: Operations Runbook - Cluster Bootstrap

# Initialize new cluster
./bootstrap.sh

# Verify
kubectl get applications -n argocd
kubectl get pods --all-namespaces

🛠️ Quick Reference

Monitor Applications

# List all ArgoCD applications
kubectl get applications -n argocd

# Watch sync status
kubectl get applications -n argocd -w

# Check specific application
kubectl describe application myapp -n argocd

# View application logs
kubectl logs -n myapp <pod-name>

Access UIs

# ArgoCD UI
kubectl port-forward svc/argocd-server -n argocd 8080:443
# Access: https://localhost:8080 (no auth required)

# Grafana
kubectl port-forward -n monitoring svc/grafana 3000:80
# Access: http://localhost:3000

# Prometheus
kubectl port-forward -n monitoring svc/prometheus-server 9090:80
# Access: http://localhost:9090

Troubleshooting

# Check pod status
kubectl get pods -n myapp

# View pod logs
kubectl logs -n myapp <pod-name>

# Check pod events
kubectl describe pod -n myapp <pod-name>

# Check ArgoCD sync errors
kubectl describe application myapp -n argocd

# Force sync
kubectl patch application myapp -n argocd \
  --type merge -p '{"metadata":{"annotations":{"argocd.argoproj.io/refresh":"hard"}}}'

Full troubleshooting guide: Developer Guide - Troubleshooting


🔐 Security

Secret Management

  • ✅ Sealed Secrets for Git storage
  • ✅ Kyverno auto-clones secrets to namespaces
  • ❌ Never commit plain secrets

Network Security

  • ✅ All traffic TLS-encrypted (Let's Encrypt)
  • ✅ HTTP → HTTPS redirect
  • ✅ Traefik IngressRoute per application

Policy Enforcement

  • ✅ Kyverno policies for security
  • ✅ Default namespace blocked
  • ✅ Bare pods not allowed
  • ✅ Optional authentication sidecar injection

Learn more: GitOps Architecture - Security Model


📊 Infrastructure Components

Component Purpose Namespace Replicas
ArgoCD GitOps controller argocd 1
Traefik Ingress controller traefik 2
Cert-Manager TLS certificates cert-manager 1
Kyverno Policy engine kyverno 1
Sealed Secrets Secret encryption kube-system 1
Prometheus Metrics monitoring 1
Grafana Dashboards monitoring 1
Loki Logs monitoring 1
Tempo Distributed tracing monitoring 1
Fluent-Bit Log shipping monitoring DaemonSet
OpenCost Cost monitoring monitoring 1
Renovate Dependency updates renovate CronJob

Full specs: Technical Reference - Infrastructure Components


🌐 Domains & Networking

  • Local development: *.127.0.0.1.nip.io
  • Production: *.forteapps.net
  • DNS: Manual configuration (contact platform team)
  • TLS: Automatic via Let's Encrypt

📖 Key Concepts

App-of-Apps Pattern

_app-of-apps-{cluster}.yaml is the root Application that manages all other Applications in infra/. Each component in infra/base/ lives in its own subdirectory (e.g., infra/base/grafana/). Overlays can either include all components (via ../../base) or cherry-pick specific ones (via ../../base/grafana, ../../base/prometheus, etc.). Per-cluster patches swap Helm value file paths. Supported clusters: upc-dev, upc-prod, eks-dev, eks-prod, aks-dev, aks-prod, gke-dev, gke-prod.

Multi-Source Pattern

Applications reference both:

  1. Helm charts from forte-helm (templates)
  2. Values from helm-prod-values (configuration)

This separates reusable templates from environment-specific config.

Sync Waves

Applications deploy in order using argocd.argoproj.io/sync-wave:

  • Wave -1: Namespaces
  • Wave 0: Kyverno (policies)
  • Wave 1: Infrastructure
  • Wave 2+: Applications

Auto-Sync & Self-Heal

  • Auto-Sync: ArgoCD automatically deploys Git changes (60s polling)
  • Self-Heal: Manual cluster changes are reverted to match Git
  • Prune: Deleted resources in Git are removed from cluster

Learn more: GitOps Architecture - GitOps Workflow


⚙️ Configuration

ArgoCD Settings

  • Reconciliation: Every 60 seconds
  • Sync timeout: 5 minutes per application
  • Retry policy: 5 attempts with exponential backoff
  • Authentication: Disabled (internal use only)

Application Defaults

  • Auto-sync: Enabled
  • Self-heal: Enabled
  • Prune: Enabled
  • Validation: Server-side validation enabled
  • Server-side apply: Enabled

Full configuration: Technical Reference - ArgoCD Configuration


🆘 Getting Help

Documentation

  1. Start here: Documentation Index
  2. For development: Developer Guide
  3. For operations: Operations Runbook
  4. For reference: Technical Reference

Support

  • Slack: #platform-support
  • Issues: Contact platform team
  • Emergencies: Escalate via Slack

Common Questions

Question Answer
How do I deploy an app? Developer Guide - Deploying Your First Application
How do I manage secrets? Developer Guide - Working with Secrets
App won't sync? Developer Guide - Troubleshooting
How do I bootstrap a cluster? Operations Runbook - Cluster Bootstrap
Where are the logs? Operations Runbook - Monitoring & Alerting

🤝 Contributing

Adding a New Application

  1. Read Developer Guide - Deploying Your First Application
  2. Create ArgoCD Application manifest in apps/
  3. Create Helm values in helm-prod-values/
  4. Create sealed secrets if needed
  5. Commit and push - ArgoCD handles the rest!

Modifying Infrastructure

  1. Read Operations Runbook
  2. Update relevant files in infra/ or cluster-resources/
  3. Test changes in isolated namespace if possible
  4. Commit and push
  5. Monitor sync status in Slack/ArgoCD UI

Updating Documentation

Documentation lives in docs/. To update:

  1. Edit relevant markdown file
  2. Update "Last Updated" date
  3. Submit PR or push directly
  4. Notify team of significant changes

📝 Notes

Current Environment

  • Provider: Multi-cloud (UpCloud, AWS EKS, Azure AKS, GCP GKE)
  • Active clusters: UpCloud (upc-dev, upc-prod)
  • Environment: Production (internal use only)
  • Auth: Disabled for ArgoCD (internal access)
  • Backup: Gitea daily backup to S3-compatible storage

Known Limitations

  • Secret rotation not automated
  • DNS management is manual

Future improvements: See Operations Runbook - Disaster Recovery


📚 Additional Resources

External Documentation

  • forte-helm - Helm chart templates
  • helm-prod-values - Application values

📄 License

Internal use only. Not for public distribution.


👥 Maintainers

Platform Team

  • Contact: #platform-support on Slack
  • Issues: Create issue in repository or contact team directly

Last Updated: 2026-04-22 Documentation Version: 1.0.0

🚀 Ready to get started? Check out the Documentation Index!

S
Description
k8s launchpad
Readme
2.5 MiB
Languages
HCL 64.1%
Shell 35.9%