diff --git a/clusters/production/webhook-receiver.yaml b/clusters/production/webhook-receiver.yaml index 3ffc661..1d22509 100644 --- a/clusters/production/webhook-receiver.yaml +++ b/clusters/production/webhook-receiver.yaml @@ -6,9 +6,12 @@ metadata: name: gitea-receiver namespace: flux-system spec: - type: gitea - events: - - push + # This Flux version's Receiver CRD has no "gitea" type - valid values are + # generic, generic-hmac, generic-oidc, github, gitlab, bitbucket, harbor, + # dockerhub, quay, gcr, nexus, acr, cdevents. "generic" accepts any POST + # to the hook path without payload/signature parsing, which is fine here: + # worst case is an early sync trigger, not a permission escalation. + type: generic secretRef: name: gitea-webhook-token resources: