The hermes-agent-image pipeline failed intermittently on external network: Kaniko's docker.io fallback for the base image is IPv6-broken from build pods, and the "Validate reviewed release source" stage pip-installed pytest from files.pythonhosted.org (DNS failures). Neither should touch the public internet. Base image: repoint the Dockerfile FROM from docker.io to the in-cluster Harbor "mirror" project, keeping the exact content-addressed index digest (9c841866...) and both arch leaves. A Flux-managed one-shot Job (services/harbor/hermes-agent-base-mirror-job.yaml, suspend: true like the cassandra bootstrap job) runs `skopeo copy --all` from docker.io into Harbor using the same Vault-injected admin credential as the existing Harbor immutability jobs; a tiny fail-closed helper ensures the public target project first. Digest pinning and multi-arch are preserved; Kaniko pulls it over the internal insecure registry with no docker.io fallback. Test deps: install pytest/PyYAML fully offline (`pip --no-index --find-links`) from a reviewed in-repo wheelhouse (ci/vendor/hermes-agent-test-wheels) matching the arm64 python:3.12 build container, so the validate stage never resolves a public index. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BvMSXH8VH2tMWXanb8SJdf
titan-iac
Flux-managed Kubernetes desired-state config for bstein.dev.
Canonical source URL:
ssh://git@scm.bstein.dev:2242/atlas/titan-iac.git
Scope
This repo contains cluster configuration consumed by Flux:
- platform/infrastructure manifests
- service manifests and kustomizations
- operational scripts for render/reconcile workflows
Apply model
I use Git + Flux as the source of truth and avoid manual in-cluster edits for durable changes.
Description
Languages
Python
74%
JavaScript
10.2%
Shell
6.2%
TypeScript
3.9%
Go
2.1%
Other
3.4%