Files
flannel/OPERATIONS.md
2026-08-22 15:17:22 +01:00

30 lines
2.0 KiB
Markdown

# Operations
## Storage prerequisites
- This repo keeps retained application storage in `manifest/base/state/persistentvolumeclaim.yaml`.
- The PVC depends on the storage class policy of the target cluster. For dynamic Longhorn provisioning, verify the backing `StorageClass` and Longhorn volume reclaim policy keep the volume data after the workload is removed.
- If you switch to the optional static NFS PV example in `manifest/overlays/production/storage/persistentvolume-nfs.yaml`, keep `persistentVolumeReclaimPolicy: Retain`.
- The namespace is not owned by this repo. Argo CD creates it with `CreateNamespace=true`, so this dormant refactor does not prune namespaces.
## Dormant transition flow
1. Push a protected tag in the form `dormant/<repo-name>/production`.
2. Gitea Actions creates a short-lived branch that changes `bootstrap/applicationset.yaml` to target `manifest/overlays/dormant`.
3. The workflow opens a pull request against `main`.
4. Review the PR, confirm the storage prerequisite above, and merge only when you want Argo CD to prune runtime resources.
5. To reactivate, open a normal PR that switches the `overlay` field back to `production`.
## Required Gitea protections
- Protect `main` so direct pushes are blocked and PR review is required.
- Protect the tag pattern `dormant/*` so only approved operators can trigger dormancy proposals.
- Keep branch protection and tag protection separate. Branch protection does not restrict who can create trigger tags.
- Store a repo secret named `GITEA_TOKEN` with permission to push branches and open pull requests.
## Safe rollout notes
- Dormant mode keeps only retained state. Runtime resources, service exposure, and ingress are removed.
- Merge the dormant PR only after confirming no shared component or external dependency still needs the runtime path.
- The example component under `manifest/components/example-component` stays untouched because it is shared template material and is not owned by the runtime-state split.