Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 8 additions & 8 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -225,7 +225,7 @@ jobs:
# Un package GHCR nouvellement créé par GITHUB_TOKEN est parfois privé par
# défaut malgré un dépôt public : après le tout premier passage de ce job,
# vérifier la visibilité de chaque package sur
# https://github.com/orgs/open-eidas/packages et la passer sur « Public »
# https://github.com/orgs/otspi/packages et la passer sur « Public »
# si nécessaire (Package settings > Change visibility).
publish:
name: Publication des images (GHCR)
Expand Down Expand Up @@ -276,26 +276,26 @@ jobs:
file: ${{ matrix.dockerfile }}
push: true
tags: |
ghcr.io/open-eidas/${{ matrix.image }}:latest
ghcr.io/open-eidas/${{ matrix.image }}:${{ github.sha }}
ghcr.io/otspi/${{ matrix.image }}:latest
ghcr.io/otspi/${{ matrix.image }}:${{ github.sha }}
cache-from: type=gha
cache-to: type=gha,mode=max
build-args: |
VERSION=${{ github.sha }}
CACHEBUST=${{ steps.cachebust.outputs.value }}

# Épingle les images de staging sur ce commit dans open-eidas/deploy —
# Épingle les images de staging sur ce commit dans otspi/deploy —
# jamais sur le cluster ni sur ArgoCD directement : cette CI n'a et
# n'aura aucun accès à l'un ou l'autre. C'est le self-heal d'ArgoCD,
# déjà configuré sur l'Application open-eidas-staging, qui applique le
# changement une fois poussé ici.
#
# Nécessite que le secret organisation OPENEIDAS_DEPLOY_APP_ID (identifiant
# de la GitHub App dédiée, écriture seule sur open-eidas/deploy) et le
# de la GitHub App dédiée, écriture seule sur otspi/deploy) et le
# secret OPENEIDAS_DEPLOY_APP_PRIVATE_KEY existent — sans eux, ce job est
# ignoré (pas d'échec bloquant tant que la App n'est pas créée).
pin-staging:
name: Épingle les images de staging (open-eidas/deploy)
name: Épingle les images de staging (otspi/deploy)
runs-on: ubuntu-latest
needs: publish
if: github.event_name == 'push' && github.ref == 'refs/heads/dev'
Expand All @@ -322,7 +322,7 @@ jobs:
- uses: actions/checkout@v4
if: steps.has-app.outputs.configured == 'true'
with:
repository: open-eidas/deploy
repository: otspi/deploy
token: ${{ steps.app-token.outputs.token }}

- name: Met à jour les tags d'image dans apps/open-eidas-staging.yaml
Expand Down Expand Up @@ -370,7 +370,7 @@ jobs:
echo "Aucun changement de tag, rien à pousser."
exit 0
fi
git commit -m "Épingle le staging sur open-eidas/open-eidas@${GITHUB_SHA}"
git commit -m "Épingle le staging sur otspi/open-eidas@${GITHUB_SHA}"
git push origin main

helm-lint:
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@

# Open eIDAS — Les services de confiance eIDAS comme infrastructure ouverte

[![CI](https://github.com/open-eidas/open-eidas/actions/workflows/ci.yml/badge.svg)](https://github.com/open-eidas/open-eidas/actions/workflows/ci.yml)
[![CI](https://github.com/otspi/open-eidas/actions/workflows/ci.yml/badge.svg)](https://github.com/otspi/open-eidas/actions/workflows/ci.yml)
[![Licence EUPL-1.2 OU AGPL-3.0](https://img.shields.io/badge/licence-EUPL--1.2%20%7C%20AGPL--3.0-blue.svg)](#licence)
[![Site Web](https://img.shields.io/badge/Site%20Web-open--eidas.eu-003399?style=flat-square)](https://open-eidas.eu)
[![Contact](https://img.shields.io/badge/Contact-contact%40open--eidas.eu-0F2042?style=flat-square)](mailto:contact@open-eidas.eu)
Expand Down
8 changes: 4 additions & 4 deletions deploy/helm/open-eidas/values-staging.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
# Préalables sur le cluster cible, gérés hors de ce chart :
# - un listener HTTPS par hôte (api/pki/ocsp.staging.open-eidas.eu) sur la
# Gateway API "shared-gateway" (namespace "ingress"), chacun avec son
# Certificate cert-manager — voir open-eidas/deploy pour ce qui EST géré
# Certificate cert-manager — voir otspi/deploy pour ce qui EST géré
# par ce dépôt (Application ArgoCD, Cluster CloudNativePG, SealedSecret) ;
# - trois enregistrements DNS (A ou CNAME) pointant vers l'adresse publique
# de shared-gateway :
Expand All @@ -14,15 +14,15 @@
# certificat de la CA émettrice)
# ocsp.staging.open-eidas.eu -> répondeur OCSP (AIA ocsp)
# - le Secret "open-eidas-generated" (scellé via kubeseal, voir
# open-eidas/deploy) présent dans le namespace open-eidas-staging avant
# otspi/deploy) présent dans le namespace open-eidas-staging avant
# le premier déploiement — il fournit à la fois les valeurs sensibles de
# ce chart et les identifiants de bootstrap du Cluster CloudNativePG.
#
# Utilisation :
# helm install open-eidas deploy/helm/open-eidas \
# --namespace open-eidas-staging --create-namespace \
# -f deploy/helm/open-eidas/values-staging.yaml
# ou via l'app-of-apps open-eidas/deploy (apps/open-eidas-staging.yaml).
# ou via l'app-of-apps otspi/deploy (apps/open-eidas-staging.yaml).

secrets:
# Contient postgres-password, tsa-pin, ocsp-pin, ca-root-pin,
Expand All @@ -33,7 +33,7 @@ secrets:
existingSecret: open-eidas-generated

postgres:
# Cluster CloudNativePG géré par open-eidas/deploy (hors de ce chart), pas
# Cluster CloudNativePG géré par otspi/deploy (hors de ce chart), pas
# le StatefulSet postgres intégré.
external:
enabled: true
Expand Down
8 changes: 4 additions & 4 deletions deploy/helm/open-eidas/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@ imagePullPolicy: IfNotPresent

tsa:
image:
repository: ghcr.io/open-eidas/open-eidas-tsa
repository: ghcr.io/otspi/open-eidas-tsa
tag: "latest"
replicaCount: 1
service:
Expand Down Expand Up @@ -84,7 +84,7 @@ tsa:

ocsp:
image:
repository: ghcr.io/open-eidas/open-eidas-ocsp-responder
repository: ghcr.io/otspi/open-eidas-ocsp-responder
tag: "latest"
replicaCount: 1
service:
Expand Down Expand Up @@ -123,7 +123,7 @@ ocsp:
# remplace OpenXPKI : voir INDEPENDANCE.md.
ca:
image:
repository: ghcr.io/open-eidas/open-eidas-ca
repository: ghcr.io/otspi/open-eidas-ca
tag: "latest"
service:
port: 8320
Expand Down Expand Up @@ -232,7 +232,7 @@ ca:
raConsole:
enabled: false
image:
repository: ghcr.io/open-eidas/open-eidas-ra-console
repository: ghcr.io/otspi/open-eidas-ra-console
tag: "latest"
service:
port: 8330
Expand Down
2 changes: 1 addition & 1 deletion docs/WEBUI.md
Original file line number Diff line number Diff line change
Expand Up @@ -1827,7 +1827,7 @@ ca:
```yaml
raConsole:
image:
repository: ghcr.io/open-eidas/open-eidas-ra-console
repository: ghcr.io/otspi/open-eidas-ra-console
tag: "latest"
replicaCount: 1
service:
Expand Down
Loading