ci: migrate to Portainer Git stack + registry-pushed image
Some checks failed
Deploy / deploy (push) Failing after 24s

- Compose: build → image:latest from Gitea registry (ci namespace)
- Workflow: build + push image + POST Portainer webhook (vs. host docker compose up)
- Drop transient .env write — secrets now live in Portainer stack Env
- Add crowdsec@file middleware (defense-in-depth project rule)

Repo secrets required: REGISTRY_TOKEN, PORTAINER_WEBHOOK_URL.
Rollback branch: pre-portainer-migration.
This commit is contained in:
2026-06-20 12:16:56 +02:00
parent ff8ed3428f
commit 3f1d2341ce
2 changed files with 17 additions and 35 deletions

View File

@@ -1,8 +1,6 @@
services:
crowdsec-admin:
build:
context: ./app
image: crowdsec-admin:local
image: git.domverse-berlin.eu/ci/crowdsec-admin/app:${TAG:-latest}
container_name: crowdsec-admin
restart: unless-stopped
networks:
@@ -21,7 +19,7 @@ services:
- "traefik.http.routers.crowdsec-admin.rule=Host(`crowdsec.domverse-berlin.eu`)"
- "traefik.http.routers.crowdsec-admin.entrypoints=https"
- "traefik.http.routers.crowdsec-admin.tls.certresolver=http"
- "traefik.http.routers.crowdsec-admin.middlewares=authentik@docker"
- "traefik.http.routers.crowdsec-admin.middlewares=crowdsec@file,authentik@docker"
- "traefik.http.services.crowdsec-admin.loadbalancer.server.port=8000"
- "kuma.crowdsec-admin.http.name=CrowdSec Admin"