I'm very new to Helm/K8 (like a week) - so please be as ELI5 as you can.
I'm trying to setup my local Kubernetes instance to host a GitLab Runner for use within our organisation's internal GitLab repo.
I've had to setup a proxy on the settings of Docker Desktop, in order to keep comms between K8s and our GitLab open.
My gitlab runner exists purely because of: Docker Desktop, K8s, our internal GitLab, and values.yaml (https://gitlab.com/gitlab-org/charts/gitlab-runner/blob/master/values.yaml) which has been edited so that "gitlabUrl" is our internal one, and "runnerRegistrationToken" is the one GitLab provided me with. I don't have other YAML files or anything like that.
It can pick up jobs just fine! Which was great, for a learner like me.
The problem is, due to the Docker's rate limit, there are clearly too many people using the proxy for a similar thing, and so my Gitlab runners eventually stop being deployed after a certain time.
So, I used my Docker Hub credentials to create a regcred, and put it in the same namespace as "gitlab-runner". I then uninstalled the Helm release, deleted the "gitlab/gitlab-runner" image off of Docker Desktop (to remove the chance of the image still thinking I was using the proxy PUBLICALLY and not with my regcred - maybe that's now how it works though?).. and then reinstalled the runner via Helm.
However, I'm having a bit of a difficult time understanding how to actually implement the regcred within Helm. I'm finding the documentation quite hard to follow as a newbie.
Looking at values.yaml I can see that "imagePullSecrets" exists both at top level, then again within rbac, and then again within [[runners]] config.
What I can see online regarding each:
For the top level one, the comment above it says to check out https://kubernetes.io/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod This links shows an example of "pod.yaml", and it looks very different to the layout of values.yaml - already confusing (for me). An explanation of this, and how it's different from the rest would be great.
For the RBAC section, I don't know enough about RBAC to know if it would help. Currently, rbac says created:false, so I doubt if I changed imagePullSecrets to say anything that it would actually do something. Maybe I do need RBAC enabled for this kind of thing? I don't know enough about it to say.
For the bit within [[runners]] config: I believe "imagePullSecrets: []" is now image_pull_secrets: []" post helm 1 (im using helm 3) as described in https://gitlab.com/gitlab-org/charts/gitlab-runner/-/issues/222 which leads to https://docs.gitlab.com/runner/executors/kubernetes.html This seems to make sense to me, maybe this is where it's meant to go?
I have tried putting it in each of the 3, but don't know for sure whether I was just within the boundaries of the daily rate limit, or if the changes made actually were in effect.
TLDR; My longwinded question is, which one do I put my regcred inside? I just want to be able to have a few runners inside my K8 namespace which can pick up jobs all day long using my regcred - that's as simple as I want it right now. Please be kind! I'm really new to this.