Skip to content

fix: call Knotree Registry through the in-cluster service - #9

Merged
vantanminh merged 1 commit into
mainfrom
fix/registry-in-cluster-origin
Oct 3, 2026
Merged

vantanminh merged 1 commit into
mainfrom
fix/registry-in-cluster-origin

Conversation

@vantanminh

Copy link
Copy Markdown
Owner

Summary

On prod, POST /integrations/knotree-registry/authorize (and the callback) returns REGISTRY_CONSENT_FAILED.

Cloud's server-side calls to https://registry.knotree.com go out through Cloudflare, which can challenge datacenter traffic. Commit c3aa38e worked around the same problem for Accounts with SSO_SERVICE_ORIGIN.

Changes

  • New optional config KNOTREE_REGISTRY_SERVICE_ORIGIN. Only http://registry.knotree-registry.svc.cluster.local is accepted; any other value falls back to the public URL with a warning.
  • These server-to-server calls now use that origin:
    • consent requests and exchange, for both the account and the per-repository flows
    • the picker's list APIs
    • /auth/token
    • manifest digest lookups
  • authorization_url is still checked against the public URL. Registry builds that URL from its own PUBLIC_REGISTRY_URL.
  • Consent failures are now logged with the HTTP status or transport error instead of only returning the generic REGISTRY_CONSENT_FAILED.
  • The key is in optional_config, so preflight still passes before the variable is set.

Test plan

  • cargo test: 120 passed, including the new server_calls_only_use_the_in_cluster_registry_service.
  • Deploy contract tests: unchanged. test_remote_gate fails locally only because Windows has no bash.

🤖 Generated with Claude Code

…lare

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vantanminh
vantanminh merged commit d91345f into main Oct 3, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant