saurabh3460/image-webhook
README
openssl req -x509 -newkey rsa:4096 -keyout tls.key -out tls.crt -days 365 -nodes -subj "/CN=webhook.default.svc"
kubectl create secret tls webhook-tls --cert=tls.crt --key=tls.key
- Apply the webhook:
kubectl apply -f deployment.yaml
kubectl apply -f webhook.yaml
- Create a test pod:
apiVersion: v1
kind: Pod
metadata:
name: test-pod
spec:
containers:
- name: test
image: ghcr.io/my-app:v1
- Check if the image is modified:
kubectl get pod test-pod -o jsonpath="{.spec.containers[*].image}"
- If ghcr.io is unavailable, the webhook replaces it with public.ecr.aws/my-app:v1.