Skip to content

kagent, Substrate, CloudNativePG and the bundled Flux controllers from gsoci #580

Description

@teemow

Problem

After #575 the rendered defaults of both charts still name images and chart sources off gsoci.azurecr.io in exactly these places, which make verify-images tolerates by name (its PENDING list) until this issue lands:

  • components.kagent / kagent-crds: the chart source oci://ghcr.io/giantswarm/kagent/helm; the kagent line's images (kagent.registry: ghcr.io — the controller, the UI, and the Go ADK and Claude harness images the chart stamps by digest).
  • components.substrate / substrate-crds: the chart source oci://ghcr.io/giantswarm/substrate/helm; the Substrate line's images (substrate.image.registry: ghcr.io/giantswarm/substrate — ateapi, atecontroller, atelet, atenet, podcertcontroller — and the derived worker image ghcr.io/giantswarm/substrate/ateom-gvisor:<pin>). The substrate chart's own third-party defaults (postgres, rustfs/rustfs, amazon/aws-cli from Docker Hub) are the line's and follow mirror the KServe serving images and sign every mirrored digest retagger#1227.
  • components.cloudnative-pg: the upstream operator chart oci://ghcr.io/cloudnative-pg/charts.
  • The bundled Flux engine: flux-engine.instance.distribution.registry: ghcr.io/fluxcd, the controller images the operator installs.

Proposed solution

Acceptance criteria

  • make verify-images passes with no pending entry.
  • agentlab boots the platform — kagent, Substrate, the engine — pulling from gsoci only: crictl images on the node lists no ghcr.io image (the three lines' images: proven; the CloudNativePG operator image still comes with its upstream chart).

Related

#575 (the defaults and the check), giantswarm/retagger#1229 (the mirrors), giantswarm/retagger#1227 (the serving images), epic giantswarm/giantswarm#37853.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions