# GitLab cross-site replication Phase 2b - exposes home's Rails internal # API (port 8181, a dedicated internal-only listener, deliberately NOT # exposed through the public Istio ingress on 8080) to the VPS's Gitaly # node. Gitaly's gitlab-shell hooks call POST /api/v4/internal/{allowed, # pre_receive,post_receive} against this whenever the VPS node is # primary for a repository (per-repository election can cause this even # in normal operation) or after a real failover. # # Reached over the same public UniFi WAN forward already used for # Postgres/Gitaly, not the Netbird mesh directly (confirmed live that # path doesn't accept inbound connections to home). Port stays 8181 # (unlike Gitaly's separate 8075/8076 split) - global.workhorse.tls. # enabled in values.yaml replaces the plaintext listener with TLS on # this SAME port rather than adding a second one. Carries the # gitlab_shell_secret in a header, so this needed TLS just as much as # Gitaly's gRPC did - see gitaly-tls-certificate.yaml's second # Certificate (gitlab-workhorse-tls) and the # gitlab-internal-api.ha.huskypup.net CoreDNS rewrite. apiVersion: v1 kind: Service metadata: name: ha-gitlab-internal-api namespace: gitlab spec: type: NodePort selector: app: webservice release: gitlab ports: - port: 8181 targetPort: 8181 nodePort: 32449