feat: initial ArgoCD GitOps self-management setup
Validate manifests / validate (push) Failing after 4s

- Base references upstream ArgoCD v3.3.6 install.yaml
- Production overlay applies all cluster customizations:
  - KSOPS CMP sidecar on argocd-repo-server
  - Custom ConfigMaps (argocd-cm, argocd-cmd-params-cm, argocd-rbac-cm, argocd-notifications-cm)
  - Redis migrated to shared-redis.data:6379
  - Traefik IngressRoute for argocd.olb42.com
  - SOPS-encrypted secrets (age key, redis auth, gitea tokens, repo-creds)
- Bootstrap Application with prune:false for safe self-management
This commit is contained in:
2026-04-19 23:36:09 +01:00
commit 40eb3b842c
17 changed files with 531 additions and 0 deletions
@@ -0,0 +1,27 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: argocd-notifications-cm
namespace: argocd
data:
service.webhook.gitea: |
url: https://git.olb42.com
headers:
- name: Authorization
value: token $GITEA_TOKEN
- name: Content-Type
value: application/json
template.gitea-create-issue: |
webhook:
gitea:
method: POST
path: /api/v1/repos/olb42/k8s-manifests/issues
body: |
{
"title": "Deploy failed: {{.app.metadata.name}}",
"body": "## Deployment Failure\n\n**App:** `{{.app.metadata.name}}`\n**Namespace:** `{{.app.spec.destination.namespace}}`\n**Sync status:** `{{.app.status.sync.status}}`\n**Health:** `{{.app.status.health.status}}`\n\n### Conditions\n```\n{{range .app.status.conditions}}{{.message}}\n{{end}}```\n\n[View in ArgoCD](https://argocd.olb42.com/applications/{{.app.metadata.name}})",
"labels": [1]
}
trigger.on-deploy-failed: |
- when: app.status.health.status == 'Degraded' || app.status.sync.status == 'Unknown'
send: [gitea-create-issue]