initial commit
This commit is contained in:
@@ -0,0 +1,29 @@
|
||||
# Operations
|
||||
|
||||
## Storage prerequisites
|
||||
|
||||
- This repo keeps retained application storage in `manifest/base/state/persistentvolumeclaim.yaml`.
|
||||
- The PVC depends on the storage class policy of the target cluster. For dynamic Longhorn provisioning, verify the backing `StorageClass` and Longhorn volume reclaim policy keep the volume data after the workload is removed.
|
||||
- If you switch to the optional static NFS PV example in `manifest/overlays/production/storage/persistentvolume-nfs.yaml`, keep `persistentVolumeReclaimPolicy: Retain`.
|
||||
- The namespace is not owned by this repo. Argo CD creates it with `CreateNamespace=true`, so this dormant refactor does not prune namespaces.
|
||||
|
||||
## Dormant transition flow
|
||||
|
||||
1. Push a protected tag in the form `dormant/<repo-name>/production`.
|
||||
2. Gitea Actions creates a short-lived branch that changes `bootstrap/applicationset.yaml` to target `manifest/overlays/dormant`.
|
||||
3. The workflow opens a pull request against `main`.
|
||||
4. Review the PR, confirm the storage prerequisite above, and merge only when you want Argo CD to prune runtime resources.
|
||||
5. To reactivate, open a normal PR that switches the `overlay` field back to `production`.
|
||||
|
||||
## Required Gitea protections
|
||||
|
||||
- Protect `main` so direct pushes are blocked and PR review is required.
|
||||
- Protect the tag pattern `dormant/*` so only approved operators can trigger dormancy proposals.
|
||||
- Keep branch protection and tag protection separate. Branch protection does not restrict who can create trigger tags.
|
||||
- Store a repo secret named `GITEA_TOKEN` with permission to push branches and open pull requests.
|
||||
|
||||
## Safe rollout notes
|
||||
|
||||
- Dormant mode keeps only retained state. Runtime resources, service exposure, and ingress are removed.
|
||||
- Merge the dormant PR only after confirming no shared component or external dependency still needs the runtime path.
|
||||
- The example component under `manifest/components/example-component` stays untouched because it is shared template material and is not owned by the runtime-state split.
|
||||
Reference in New Issue
Block a user