Test cluster.helm_oci_auth in sylva-core CI
Test cluster.helm_oci_auth in sylva-core CI
This MR supports sylva-projects/sylva-core!9272 (merged) (sylva-projects/sylva-core#4345 (closed)), which adds cluster.helm_oci_auth to pull the RKE2 bootstrap charts from an OCI registry that requires authentication.
All RKE2 CI deployments pull the metallb chart with credentials. While registry.gitlab.com allows anonymous pulls of these charts, it rejects wrong credentials, so a deployment fails if the credentials are not passed correctly. The other charts are still pulled anonymously, which keeps that path tested too.
The token only gives read access to a public registry, so it is stored in plain text and allowlisted in .gitleaks.toml, like the existing sample-repo deploy tokens.
sylva-core!9272 points SYLVA_CI_VALUES_REVISION at this branch for testing. Once this MR is merged and tagged, !9272 will use the tag instead.
AI assistance:
Claude Code (claude-opus-5) was used on this change: working out how sylva-core CI loads these values and pulls the RKE2 charts, drafting the values and allowlist change, checking the deploy token against the registry, and running gitleaks locally with and without the allowlist entry. The commit carries an Assisted-by: trailer.
What I verified myself: Reviewed the full diff, ran the sylva-core!9272 deployment pipeline https://gitlab.com/sylva-projects/sylva-core/-/pipelines/2882114422 (capm3/RKE2/SUSE) against this branch. The result was that both clusters deployed successfully, with helm_oci_auth.metallb in their cluster values and the metallb credentials file on both control planes.