feat: initial ArgoCD GitOps self-management setup
Validate manifests / validate (push) Failing after 4s
Validate manifests / validate (push) Failing after 4s
- Base references upstream ArgoCD v3.3.6 install.yaml - Production overlay applies all cluster customizations: - KSOPS CMP sidecar on argocd-repo-server - Custom ConfigMaps (argocd-cm, argocd-cmd-params-cm, argocd-rbac-cm, argocd-notifications-cm) - Redis migrated to shared-redis.data:6379 - Traefik IngressRoute for argocd.olb42.com - SOPS-encrypted secrets (age key, redis auth, gitea tokens, repo-creds) - Bootstrap Application with prune:false for safe self-management
This commit is contained in:
@@ -0,0 +1,117 @@
|
|||||||
|
name: Validate manifests
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
validate:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Install tools
|
||||||
|
run: |
|
||||||
|
curl -sL https://github.com/yannh/kubeconform/releases/latest/download/kubeconform-linux-amd64.tar.gz \
|
||||||
|
| tar xz -C /usr/local/bin
|
||||||
|
|
||||||
|
# Traefik IngressRoute is a CRD, so kubeconform needs an extra schema source.
|
||||||
|
mkdir -p .ci-schemas/traefik.io
|
||||||
|
curl -fsSL https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/traefik.io/ingressroute_v1alpha1.json \
|
||||||
|
-o .ci-schemas/traefik.io/ingressroute_v1alpha1.json
|
||||||
|
cp .ci-schemas/traefik.io/ingressroute_v1alpha1.json .ci-schemas/traefik.io/IngressRoute_v1alpha1.json
|
||||||
|
cp .ci-schemas/traefik.io/ingressroute_v1alpha1.json .ci-schemas/traefik.io/IngressRoute.json
|
||||||
|
cp .ci-schemas/traefik.io/ingressroute_v1alpha1.json .ci-schemas/traefik.io/ingressroute.json
|
||||||
|
|
||||||
|
# ArgoCD Application is also a CRD.
|
||||||
|
mkdir -p .ci-schemas/argoproj.io
|
||||||
|
curl -fsSL https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/argoproj.io/application_v1alpha1.json \
|
||||||
|
-o .ci-schemas/argoproj.io/application_v1alpha1.json
|
||||||
|
cp .ci-schemas/argoproj.io/application_v1alpha1.json .ci-schemas/argoproj.io/Application_v1alpha1.json
|
||||||
|
cp .ci-schemas/argoproj.io/application_v1alpha1.json .ci-schemas/argoproj.io/Application.json
|
||||||
|
cp .ci-schemas/argoproj.io/application_v1alpha1.json .ci-schemas/argoproj.io/application.json
|
||||||
|
|
||||||
|
- name: kubeconform - raw YAML
|
||||||
|
run: |
|
||||||
|
bootstrap_enabled=false
|
||||||
|
if [ -f bootstrap/config.yaml ] && grep -Eq '^[[:space:]]*enabled:[[:space:]]*true[[:space:]]*$' bootstrap/config.yaml; then
|
||||||
|
bootstrap_enabled=true
|
||||||
|
fi
|
||||||
|
|
||||||
|
mapfile -t manifests < <(
|
||||||
|
find . -type f -name '*.yaml' \
|
||||||
|
! -path './.gitea/*' \
|
||||||
|
! -name '.sops.yaml' \
|
||||||
|
! -name '*.secret.yaml' \
|
||||||
|
! -name 'kustomization.yaml' \
|
||||||
|
! \( -name 'secret*.yaml' \) \
|
||||||
|
! \( -path '*/config/*' -prune \) \
|
||||||
|
! -path './bootstrap/config.yaml' \
|
||||||
|
| sort
|
||||||
|
)
|
||||||
|
|
||||||
|
if [ "$bootstrap_enabled" != "true" ]; then
|
||||||
|
filtered=()
|
||||||
|
for manifest in "${manifests[@]}"; do
|
||||||
|
[ "$manifest" = "./bootstrap/application.yaml" ] && continue
|
||||||
|
filtered+=("$manifest")
|
||||||
|
done
|
||||||
|
manifests=("${filtered[@]}")
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ "${#manifests[@]}" -eq 0 ]; then
|
||||||
|
echo "No manifests found"
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
printf '%s\n' "${manifests[@]}" \
|
||||||
|
| xargs kubeconform \
|
||||||
|
-strict \
|
||||||
|
-kubernetes-version 1.35.0 \
|
||||||
|
-schema-location default \
|
||||||
|
-schema-location '.ci-schemas/{{.Group}}/{{.ResourceKind}}{{.KindSuffix}}.json' \
|
||||||
|
-schema-location '.ci-schemas/{{.Group}}/{{.ResourceKind}}_{{.ResourceAPIVersion}}.json' \
|
||||||
|
-summary
|
||||||
|
|
||||||
|
- name: SOPS - check no secret files committed unencrypted
|
||||||
|
run: |
|
||||||
|
fail=0
|
||||||
|
|
||||||
|
while IFS= read -r file; do
|
||||||
|
if ! grep -q 'sops:' "$file"; then
|
||||||
|
echo "ERROR: $file appears to be unencrypted"
|
||||||
|
fail=1
|
||||||
|
fi
|
||||||
|
done < <(
|
||||||
|
find . -type f \( -name '*.secret.yaml' -o -name '*.enc.yaml' \) | sort
|
||||||
|
)
|
||||||
|
|
||||||
|
exit "$fail"
|
||||||
|
|
||||||
|
- name: Apply bootstrap Application
|
||||||
|
env:
|
||||||
|
KUBECONFIG_B64: ${{ secrets.KUBECONFIG_B64 }}
|
||||||
|
run: |
|
||||||
|
if [ "${GITHUB_EVENT_NAME:-}" != "push" ] || [ "${GITHUB_REF:-}" != "refs/heads/main" ]; then
|
||||||
|
echo "Skipping bootstrap apply: only push events on main may apply"
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ ! -f bootstrap/config.yaml ] || ! grep -Eq '^[[:space:]]*enabled:[[:space:]]*true[[:space:]]*$' bootstrap/config.yaml; then
|
||||||
|
echo "Skipping bootstrap apply: bootstrap/config.yaml is not enabled"
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ -z "${KUBECONFIG_B64:-}" ]; then
|
||||||
|
echo "Warning: KUBECONFIG_B64 secret not set — skipping bootstrap apply"
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
curl -fsSL https://dl.k8s.io/release/$(curl -fsSL https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl \
|
||||||
|
-o /usr/local/bin/kubectl
|
||||||
|
chmod +x /usr/local/bin/kubectl
|
||||||
|
|
||||||
|
mkdir -p "${HOME}/.kube"
|
||||||
|
printf '%s' "$KUBECONFIG_B64" | base64 -d > "${HOME}/.kube/config"
|
||||||
|
|
||||||
|
kubectl apply -f bootstrap/application.yaml
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
.DS_Store
|
||||||
|
.idea/
|
||||||
|
.vscode/
|
||||||
|
*.swp
|
||||||
|
*.swo
|
||||||
|
|
||||||
|
# Local plaintext twins for sync-managed secrets. Keep these untracked.
|
||||||
|
manifest/overlays/**/secret.yaml
|
||||||
|
manifest/components/**/secret.yaml
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
creation_rules:
|
||||||
|
- path_regex: manifest/(overlays|components)/.*/.*\.enc\.yaml$
|
||||||
|
age: age1s0gzgh8c00tgnkgxrqyz2nu0k56xvc9ev3jdenkmu90egux9xfmsxvvj43
|
||||||
|
- path_regex: manifest/(overlays|components)/.*/secret\.secret\.yaml$
|
||||||
|
age: age1s0gzgh8c00tgnkgxrqyz2nu0k56xvc9ev3jdenkmu90egux9xfmsxvvj43
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
apiVersion: argoproj.io/v1alpha1
|
||||||
|
kind: Application
|
||||||
|
metadata:
|
||||||
|
name: argocd-production
|
||||||
|
namespace: argocd
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/managed-by: argocd
|
||||||
|
app.kubernetes.io/name: argocd
|
||||||
|
spec:
|
||||||
|
project: default
|
||||||
|
source:
|
||||||
|
repoURL: http://gitea-ha-http.apps:3000/olb42/argocd.git
|
||||||
|
targetRevision: main
|
||||||
|
path: manifest/overlays/production
|
||||||
|
plugin:
|
||||||
|
name: ksops
|
||||||
|
destination:
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
namespace: argocd
|
||||||
|
syncPolicy:
|
||||||
|
automated:
|
||||||
|
# prune: false — ArgoCD self-managing itself; never auto-prune to avoid
|
||||||
|
# accidentally removing ArgoCD components and losing cluster management.
|
||||||
|
prune: false
|
||||||
|
selfHeal: true
|
||||||
|
syncOptions:
|
||||||
|
- CreateNamespace=false
|
||||||
|
- ApplyOutOfSyncOnly=true
|
||||||
|
- ServerSideApply=true
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
enabled: true
|
||||||
|
target_namespace: argocd
|
||||||
|
apply_from_branch: main
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
namespace: argocd
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- https://raw.githubusercontent.com/argoproj/argo-cd/v3.3.6/manifests/install.yaml
|
||||||
@@ -0,0 +1,95 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: argocd-cm
|
||||||
|
namespace: argocd
|
||||||
|
data:
|
||||||
|
accounts.homepage: apiKey
|
||||||
|
accounts.mcpserver: apiKey
|
||||||
|
exec.enabled: "true"
|
||||||
|
kustomize.buildOptions: --enable-helm
|
||||||
|
resource.customizations.ignoreResourceUpdates.ConfigMap: |
|
||||||
|
jqPathExpressions:
|
||||||
|
- '.metadata.annotations."cluster-autoscaler.kubernetes.io/last-updated"'
|
||||||
|
- '.metadata.annotations."control-plane.alpha.kubernetes.io/leader"'
|
||||||
|
resource.customizations.ignoreResourceUpdates.Endpoints: |
|
||||||
|
jsonPointers:
|
||||||
|
- /metadata
|
||||||
|
- /subsets
|
||||||
|
resource.customizations.ignoreResourceUpdates.all: |
|
||||||
|
jsonPointers:
|
||||||
|
- /status
|
||||||
|
resource.customizations.ignoreResourceUpdates.apps_ReplicaSet: |
|
||||||
|
jqPathExpressions:
|
||||||
|
- '.metadata.annotations."deployment.kubernetes.io/desired-replicas"'
|
||||||
|
- '.metadata.annotations."deployment.kubernetes.io/max-replicas"'
|
||||||
|
- '.metadata.annotations."rollout.argoproj.io/desired-replicas"'
|
||||||
|
resource.customizations.ignoreResourceUpdates.argoproj.io_Application: |
|
||||||
|
jqPathExpressions:
|
||||||
|
- '.metadata.annotations."notified.notifications.argoproj.io"'
|
||||||
|
- '.metadata.annotations."argocd.argoproj.io/refresh"'
|
||||||
|
- '.metadata.annotations."argocd.argoproj.io/hydrate"'
|
||||||
|
- '.operation'
|
||||||
|
resource.customizations.ignoreResourceUpdates.argoproj.io_Rollout: |
|
||||||
|
jqPathExpressions:
|
||||||
|
- '.metadata.annotations."notified.notifications.argoproj.io"'
|
||||||
|
resource.customizations.ignoreResourceUpdates.autoscaling_HorizontalPodAutoscaler: |
|
||||||
|
jqPathExpressions:
|
||||||
|
- '.metadata.annotations."autoscaling.alpha.kubernetes.io/behavior"'
|
||||||
|
- '.metadata.annotations."autoscaling.alpha.kubernetes.io/conditions"'
|
||||||
|
- '.metadata.annotations."autoscaling.alpha.kubernetes.io/metrics"'
|
||||||
|
- '.metadata.annotations."autoscaling.alpha.kubernetes.io/current-metrics"'
|
||||||
|
resource.customizations.ignoreResourceUpdates.discovery.k8s.io_EndpointSlice: |
|
||||||
|
jsonPointers:
|
||||||
|
- /metadata
|
||||||
|
- /endpoints
|
||||||
|
- /ports
|
||||||
|
resource.exclusions: |
|
||||||
|
- apiGroups:
|
||||||
|
- ''
|
||||||
|
- discovery.k8s.io
|
||||||
|
kinds:
|
||||||
|
- Endpoints
|
||||||
|
- EndpointSlice
|
||||||
|
- apiGroups:
|
||||||
|
- coordination.k8s.io
|
||||||
|
kinds:
|
||||||
|
- Lease
|
||||||
|
- apiGroups:
|
||||||
|
- authentication.k8s.io
|
||||||
|
- authorization.k8s.io
|
||||||
|
kinds:
|
||||||
|
- SelfSubjectReview
|
||||||
|
- TokenReview
|
||||||
|
- LocalSubjectAccessReview
|
||||||
|
- SelfSubjectAccessReview
|
||||||
|
- SelfSubjectRulesReview
|
||||||
|
- SubjectAccessReview
|
||||||
|
- apiGroups:
|
||||||
|
- certificates.k8s.io
|
||||||
|
kinds:
|
||||||
|
- CertificateSigningRequest
|
||||||
|
- apiGroups:
|
||||||
|
- cert-manager.io
|
||||||
|
kinds:
|
||||||
|
- CertificateRequest
|
||||||
|
- apiGroups:
|
||||||
|
- cilium.io
|
||||||
|
kinds:
|
||||||
|
- CiliumIdentity
|
||||||
|
- CiliumEndpoint
|
||||||
|
- CiliumEndpointSlice
|
||||||
|
- apiGroups:
|
||||||
|
- kyverno.io
|
||||||
|
- reports.kyverno.io
|
||||||
|
- wgpolicyk8s.io
|
||||||
|
kinds:
|
||||||
|
- PolicyReport
|
||||||
|
- ClusterPolicyReport
|
||||||
|
- EphemeralReport
|
||||||
|
- ClusterEphemeralReport
|
||||||
|
- AdmissionReport
|
||||||
|
- ClusterAdmissionReport
|
||||||
|
- BackgroundScanReport
|
||||||
|
- ClusterBackgroundScanReport
|
||||||
|
- UpdateRequest
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: argocd-cmd-params-cm
|
||||||
|
namespace: argocd
|
||||||
|
data:
|
||||||
|
redis.server: shared-redis.data:6379
|
||||||
|
server.insecure: "true"
|
||||||
@@ -0,0 +1,26 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: argocd-cmp-cm
|
||||||
|
namespace: argocd
|
||||||
|
data:
|
||||||
|
ksops.yaml: |
|
||||||
|
apiVersion: argoproj.io/v1alpha1
|
||||||
|
kind: ConfigManagementPlugin
|
||||||
|
metadata:
|
||||||
|
name: ksops
|
||||||
|
spec:
|
||||||
|
generate:
|
||||||
|
command: ["sh", "-c"]
|
||||||
|
args:
|
||||||
|
- |
|
||||||
|
if [ -n "$ARGOCD_ENV_BRANCH_SLUG" ]; then
|
||||||
|
sed -i "s/BRANCH_SLUG_PLACEHOLDER/$ARGOCD_ENV_BRANCH_SLUG/g" kustomization.yaml
|
||||||
|
fi
|
||||||
|
if [ -n "$ARGOCD_ENV_IMAGE_TAG" ]; then
|
||||||
|
kustomize edit set image "ngorse/swarm-dns-watcher:$ARGOCD_ENV_IMAGE_TAG"
|
||||||
|
fi
|
||||||
|
kustomize build --enable-alpha-plugins --enable-exec .
|
||||||
|
discover:
|
||||||
|
find:
|
||||||
|
glob: "**/kustomization.yaml"
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: argocd-notifications-cm
|
||||||
|
namespace: argocd
|
||||||
|
data:
|
||||||
|
service.webhook.gitea: |
|
||||||
|
url: https://git.olb42.com
|
||||||
|
headers:
|
||||||
|
- name: Authorization
|
||||||
|
value: token $GITEA_TOKEN
|
||||||
|
- name: Content-Type
|
||||||
|
value: application/json
|
||||||
|
template.gitea-create-issue: |
|
||||||
|
webhook:
|
||||||
|
gitea:
|
||||||
|
method: POST
|
||||||
|
path: /api/v1/repos/olb42/k8s-manifests/issues
|
||||||
|
body: |
|
||||||
|
{
|
||||||
|
"title": "Deploy failed: {{.app.metadata.name}}",
|
||||||
|
"body": "## Deployment Failure\n\n**App:** `{{.app.metadata.name}}`\n**Namespace:** `{{.app.spec.destination.namespace}}`\n**Sync status:** `{{.app.status.sync.status}}`\n**Health:** `{{.app.status.health.status}}`\n\n### Conditions\n```\n{{range .app.status.conditions}}{{.message}}\n{{end}}```\n\n[View in ArgoCD](https://argocd.olb42.com/applications/{{.app.metadata.name}})",
|
||||||
|
"labels": [1]
|
||||||
|
}
|
||||||
|
trigger.on-deploy-failed: |
|
||||||
|
- when: app.status.health.status == 'Degraded' || app.status.sync.status == 'Unknown'
|
||||||
|
send: [gitea-create-issue]
|
||||||
@@ -0,0 +1,12 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: argocd-rbac-cm
|
||||||
|
namespace: argocd
|
||||||
|
data:
|
||||||
|
policy.csv: |
|
||||||
|
p, role:app-manager, applications, *, */*, allow
|
||||||
|
p, role:app-viewer, applications, get, */*, allow
|
||||||
|
g, mcpserver, role:app-manager
|
||||||
|
g, homepage, role:app-viewer
|
||||||
|
policy.default: role:readonly
|
||||||
@@ -0,0 +1,36 @@
|
|||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: argocd-server
|
||||||
|
namespace: argocd
|
||||||
|
annotations:
|
||||||
|
gethomepage.dev/app: argocd-server
|
||||||
|
gethomepage.dev/description: CI Service
|
||||||
|
gethomepage.dev/enabled: "true"
|
||||||
|
gethomepage.dev/href: https://argocd.olb42.com
|
||||||
|
gethomepage.dev/icon: argo-cd
|
||||||
|
gethomepage.dev/name: Argo-CD
|
||||||
|
gethomepage.dev/namespace: argocd
|
||||||
|
gethomepage.dev/widget.key: '{{HOMEPAGE_VAR_ARGOCD_TOKEN}}'
|
||||||
|
gethomepage.dev/widget.type: argocd
|
||||||
|
gethomepage.dev/widget.url: http://argocd-server.argocd
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- kind: Rule
|
||||||
|
match: Host(`argocd.olb42.com`)
|
||||||
|
priority: 10
|
||||||
|
services:
|
||||||
|
- name: argocd-server
|
||||||
|
port: 80
|
||||||
|
scheme: http
|
||||||
|
- kind: Rule
|
||||||
|
match: Host(`argocd.olb42.com`) && Header(`Content-Type`, `application/grpc`)
|
||||||
|
priority: 11
|
||||||
|
services:
|
||||||
|
- name: argocd-server
|
||||||
|
port: 80
|
||||||
|
scheme: h2c
|
||||||
|
tls:
|
||||||
|
secretName: olb42-com-tls
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: ksops-cmp-config
|
||||||
|
namespace: argocd
|
||||||
|
data:
|
||||||
|
plugin.yaml: |
|
||||||
|
apiVersion: argoproj.io/v1alpha1
|
||||||
|
kind: ConfigManagementPlugin
|
||||||
|
metadata:
|
||||||
|
name: ksops
|
||||||
|
spec:
|
||||||
|
version: v1.0
|
||||||
|
discover:
|
||||||
|
find:
|
||||||
|
glob: "**/ksops-generator.yaml"
|
||||||
|
generate:
|
||||||
|
command:
|
||||||
|
- kustomize
|
||||||
|
- build
|
||||||
|
- --enable-alpha-plugins
|
||||||
|
- --enable-exec
|
||||||
|
- .
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
apiVersion: viaduct.ai/v1
|
||||||
|
kind: ksops
|
||||||
|
metadata:
|
||||||
|
name: argocd-secret-generator
|
||||||
|
annotations:
|
||||||
|
config.kubernetes.io/function: |
|
||||||
|
exec:
|
||||||
|
path: ksops
|
||||||
|
files:
|
||||||
|
- ./secret.enc.yaml
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
namespace: argocd
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- ../../base
|
||||||
|
- argocd-cmp-cm.yaml
|
||||||
|
- ksops-cmp-config.yaml
|
||||||
|
- ingressroute.yaml
|
||||||
|
|
||||||
|
patches:
|
||||||
|
- path: argocd-cm-patch.yaml
|
||||||
|
- path: argocd-cmd-params-cm-patch.yaml
|
||||||
|
- path: argocd-rbac-cm-patch.yaml
|
||||||
|
- path: argocd-notifications-cm-patch.yaml
|
||||||
|
- path: repo-server-patch.yaml
|
||||||
|
|
||||||
|
# KSOPS decrypts secret.enc.yaml at render time.
|
||||||
|
# The presence of ksops-generator.yaml activates the KSOPS CMP plugin.
|
||||||
|
generators:
|
||||||
|
- ksops-generator.yaml
|
||||||
@@ -0,0 +1,61 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: argocd-repo-server
|
||||||
|
namespace: argocd
|
||||||
|
spec:
|
||||||
|
template:
|
||||||
|
spec:
|
||||||
|
initContainers:
|
||||||
|
- name: copyutil
|
||||||
|
image: quay.io/argoproj/argocd:v3.3.6
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
args:
|
||||||
|
- /bin/cp --update=none /usr/local/bin/argocd /var/run/argocd/argocd && /bin/ln -s /var/run/argocd/argocd /var/run/argocd/argocd-cmp-server
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
|
readOnlyRootFilesystem: true
|
||||||
|
runAsNonRoot: true
|
||||||
|
seccompProfile:
|
||||||
|
type: RuntimeDefault
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /var/run/argocd
|
||||||
|
name: var-files
|
||||||
|
containers:
|
||||||
|
- name: ksops
|
||||||
|
image: viaductoss/ksops:v4.3.2
|
||||||
|
command:
|
||||||
|
- /var/run/argocd/argocd-cmp-server
|
||||||
|
env:
|
||||||
|
- name: SOPS_AGE_KEY_FILE
|
||||||
|
value: /age/key.txt
|
||||||
|
securityContext:
|
||||||
|
runAsNonRoot: true
|
||||||
|
runAsUser: 999
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /var/run/argocd
|
||||||
|
name: var-files
|
||||||
|
- mountPath: /home/argocd/cmp-server/plugins
|
||||||
|
name: plugins
|
||||||
|
- mountPath: /home/argocd/cmp-server/config/plugin.yaml
|
||||||
|
name: argocd-cmp-cm
|
||||||
|
subPath: ksops.yaml
|
||||||
|
- mountPath: /age
|
||||||
|
name: age-key
|
||||||
|
readOnly: true
|
||||||
|
- mountPath: /tmp
|
||||||
|
name: cmp-tmp
|
||||||
|
volumes:
|
||||||
|
- name: argocd-cmp-cm
|
||||||
|
configMap:
|
||||||
|
name: argocd-cmp-cm
|
||||||
|
- name: age-key
|
||||||
|
secret:
|
||||||
|
secretName: argocd-age-key
|
||||||
|
- name: cmp-tmp
|
||||||
|
emptyDir: {}
|
||||||
@@ -0,0 +1,41 @@
|
|||||||
|
apiVersion: ENC[AES256_GCM,data:nAs=,iv:DjVwuYqCpa9e9TY59qPUqG2yjrGOykfDUI/bH00cYC8=,tag:AgFF0Bb3YXZeUKb2BmA9Pg==,type:str]
|
||||||
|
kind: ENC[AES256_GCM,data:oBkqTrVH,iv:/M+hMx4ioTgtqjySJ0SvIv2W7huDyH1jAFCRXfHl4MQ=,tag:Qmq8JHdpdbpTA1WRrt8kuA==,type:str]
|
||||||
|
metadata:
|
||||||
|
name: ENC[AES256_GCM,data:MhdiC/arAhFbp2yzt4o=,iv:8pmcBcIj+iiVymud92ZIbMgEt9XCN7EFEYnL1ocwkWQ=,tag:T7/Dr24TtqACE7J171U/Rg==,type:str]
|
||||||
|
namespace: ENC[AES256_GCM,data:60vOnJKT,iv:t9Fapbuu9Ya311uzqZ86YjwEAR76PpOjxMDdGgfbxpA=,tag:6ERx/f670/SNOMikO+q/4w==,type:str]
|
||||||
|
type: ENC[AES256_GCM,data:i+s8ejKv,iv:LOqBlClSNxZY/RA50V0LNWD8a2XsHOI7bZSastpQ2E8=,tag:hlJ3TVaK6c4j/GSAK4EbqA==,type:str]
|
||||||
|
stringData:
|
||||||
|
key.txt: ENC[AES256_GCM,data:BYd7VuC7Tpu+fBfT2f+UwdmbzQnxDbAcapvNyoQR4qmcV/t4y7gjiD5Og5Tcpw3WhLLA3JBTuea7R/FqLwsHxqM1ZFsO17dUSZw=,iv:rodtfLRQUTyyt9P+7bhP6i/BEgZe5fePPDSYC1VHlq0=,tag:WGNFEStQo6CInbvNFbhrVw==,type:str]
|
||||||
|
sops:
|
||||||
|
age:
|
||||||
|
- recipient: age1s0gzgh8c00tgnkgxrqyz2nu0k56xvc9ev3jdenkmu90egux9xfmsxvvj43
|
||||||
|
enc: |
|
||||||
|
-----BEGIN AGE ENCRYPTED FILE-----
|
||||||
|
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBqTVFMS3hqVFpFYkJPYkdl
|
||||||
|
QTU5ZTNtL3NhbWhFRUt4N1ZmOHNUT2Z6SnhjCmFGYTdsVm9lWWJBMURQdExkQ3pD
|
||||||
|
eFZvYTdzaS9Eb0dURGNXaERVSm1jSUEKLS0tIGpJSjJqU2NDZXBNSmIxRWg5Nk1G
|
||||||
|
aFNPeGdCUUxuUHJPZWdkWU1QWW8yN2MKo5P8YpmEx1K6n2KmJ5ZinI8tHTt79U+x
|
||||||
|
QIPHIOsL0vyRRDwDrhxagd1MX4OEOZl590GvT6IiNY0lN4gCdjoNow==
|
||||||
|
-----END AGE ENCRYPTED FILE-----
|
||||||
|
lastmodified: "2026-04-19T22:34:54Z"
|
||||||
|
mac: ENC[AES256_GCM,data:5Ya2agLt9jHqylYh72cN9SNWpinNkSnbfAoUYXtPI+lp69qxYIq3SelE8vulWcDoOZIDxEepttVpIo+pkyQbxKwMms/iHLyEC1EIFg9MVIaP5KIdrr93p/aExMkFyPcDLiqC0XcCMuBhNTaZvQ5IE+wDs3JthUIa5F1ZL+3eTt4=,iv:iQLvWgAegOMYas/nxD3k3lXZ7wOjMGXYq/fuiin1+zU=,tag:F/YLP8oDDlGMisz0XLCJDA==,type:str]
|
||||||
|
unencrypted_suffix: _unencrypted
|
||||||
|
version: 3.12.2
|
||||||
|
---
|
||||||
|
apiVersion: ENC[AES256_GCM,data:THQ=,iv:kX/yYct8NmlujHHZ2Ui29wcGsjHojnHvYzx24i6CGxA=,tag:XtQInMnByeiit852ZAom7Q==,type:str]
|
||||||
|
kind: ENC[AES256_GCM,data:4NDGjFRb,iv:ImM1RSLM7Sa0J/RNPOeSmBUdDbxg32yIImurjgAIocM=,tag:5HLeek7XNSHDZ9ZlZsbahQ==,type:str]
|
||||||
|
metadata:
|
||||||
|
name: ENC[AES256_GCM,data:EotC086GrXiwxc2a,iv:xC5j6+Wokph7O5few7Kkzxwg8PW9eCE56QynyJftdUE=,tag:MvHqWXnwj3cVoie3VbTf/Q==,type:str]
|
||||||
|
namespace: ENC[AES256_GCM,data:Vo+Jc74Q,iv:Xfl7xjj8obV62L5U7IcK9XhY81aOvjWpQVu4XveMU/E=,tag:FDL3yxeO9DtVvHJY6LpWGA==,type:str]
|
||||||
|
type: ENC[AES256_GCM,data:U6aSqKrG,iv:iDBCN4GNTF01+c1sURCRDMXyY+WZ8IYYEYCQx3AX2As=,tag:QzwWCRXZWzncLo668Ei9RQ==,type:str]
|
||||||
|
stringData:
|
||||||
|
auth: ENC[AES256_GCM,data:IoYCciqcZIahHzyqIfs9dPtOU9//DU8ISSf/w5R2Og==,iv:1xqmXww4P+C/auZ6IjTISChTfhDEC76fYPi7beNl7Pc=,tag:c5ze7wDGfCxp2xiACbRcQg==,type:str]
|
||||||
|
sops:
|
||||||
|
age:
|
||||||
|
- recipient: age1s0gzgh8c00tgnkgxrqyz2nu0k56xvc9ev3jdenkmu90egux9xfmsxvvj43
|
||||||
|
enc: |
|
||||||
|
-----BEGIN AGE ENCRYPTED FILE-----
|
||||||
|
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBqTVFMS3hqVFpFYkJPYkdl
|
||||||
|
QTU5ZTNtL3NhbWhFRUt4N1ZmOHNUT2Z6SnhjCmFGYTdsVm9lWWJBMURQdExkQ3pD
|
||||||
|
eFZvYTdzaS9Eb0dURGNXaERVSm1jSUEKLS0tIGpJSjJqU2NDZXBNSmIxRWg5Nk1G
|
||||||
|
... (145 lines truncated)
|
||||||
Reference in New Issue
Block a user