feat: route internet registry verification through proxy - #98
Draft
y-eight wants to merge 1 commit into
Draft
Conversation
The webhook verification path honors HTTP_PROXY/HTTPS_PROXY/NO_PROXY via go-containerregistry's DefaultTransport, but the proxy env vars were only injected into the init containers, not the main webhook container that verifies pod images at admission time. - Inject proxy env vars into the main webhook container (chart) - Make proxy support explicit via proxyTransport() in buildRemoteOpts - Document the .telekom.de NO_PROXY use case Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | 0 |
| Duplication | 0 |
NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The webhook could not verify images hosted on internet registries that are only reachable through a forward proxy. While the verification path (go-containerregistry's
DefaultTransport) already honorsHTTP_PROXY/HTTPS_PROXY/NO_PROXYviahttp.ProxyFromEnvironment, those env vars were only injected into the init containers (which verify the webhook's own images at startup) — not the main webhook container that verifies pod images at admission time.Changes
HTTP_PROXY/HTTPS_PROXY/NO_PROXYinto the main webhook container (gated byproxy.enabled), matching the init containers.proxyTransport()(clonesremote.DefaultTransportwithhttp.ProxyFromEnvironment), wired intobuildRemoteOptsthroughremote.WithTransport..telekom.deuse case.Usage
Set
NO_PROXYto reach internal registries directly so only non-*.telekom.deimages go through the proxy:Verification
go build ./...✅go vet ./webhook/✅go test ./webhook/✅helm templaterenders proxy env on the webhook container and both init containers ✅