diff --git a/README.md b/README.md new file mode 100644 index 0000000..cc84589 --- /dev/null +++ b/README.md @@ -0,0 +1,27 @@ +# argocd + +GitOps source for the cluster Argo CD installation. This app is self-managed by +Argo CD and intentionally uses a conservative sync policy. + +## Current deployment + +- Bootstrap: `enabled: true`, applied from `main` +- Argo application: `argocd-production` +- Target namespace: `argocd` +- Render path: `manifest/overlays/production` +- Repo URL used by Argo CD: `http://gitea-ha-http.apps:3000/olb42/argocd.git` +- Config management plugin: `ksops` + +## Runtime + +The base installs upstream Argo CD `v3.3.6` from the official install manifest. +The production overlay adds the Traefik route for `argocd.olb42.com`, KSOPS CMP +configuration, repo credentials, notifications, Redis credentials, and patches +for Argo CD config, RBAC, command parameters, repo-server behavior, and bundled +Redis disablement. + +## Sync policy + +Automated sync is disabled for the Argo CD application itself. Prune and +self-heal are also disabled so a bad self-management change cannot remove the +control plane that would be needed to repair it. diff --git a/manifest/overlays/production/argo-rollouts/kustomization.yaml b/manifest/overlays/production/argo-rollouts/kustomization.yaml new file mode 100644 index 0000000..d9b45c6 --- /dev/null +++ b/manifest/overlays/production/argo-rollouts/kustomization.yaml @@ -0,0 +1,8 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +namespace: argo-rollouts + +resources: + - namespace.yaml + - https://github.com/argoproj/argo-rollouts/releases/download/v1.9.0/install.yaml diff --git a/manifest/overlays/production/argo-rollouts/namespace.yaml b/manifest/overlays/production/argo-rollouts/namespace.yaml new file mode 100644 index 0000000..67214dc --- /dev/null +++ b/manifest/overlays/production/argo-rollouts/namespace.yaml @@ -0,0 +1,4 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: argo-rollouts diff --git a/manifest/overlays/production/argocd-image-updater/kustomization.yaml b/manifest/overlays/production/argocd-image-updater/kustomization.yaml new file mode 100644 index 0000000..c05e663 --- /dev/null +++ b/manifest/overlays/production/argocd-image-updater/kustomization.yaml @@ -0,0 +1,7 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +namespace: argocd + +resources: + - https://raw.githubusercontent.com/argoproj-labs/argocd-image-updater/v1.2.0/config/install.yaml diff --git a/manifest/overlays/production/kustomization.yaml b/manifest/overlays/production/kustomization.yaml index 25b69f4..d93003d 100644 --- a/manifest/overlays/production/kustomization.yaml +++ b/manifest/overlays/production/kustomization.yaml @@ -1,10 +1,10 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization -namespace: argocd - resources: - ../../base + - argo-rollouts + - argocd-image-updater - argocd-cmp-cm.yaml - ingressroute.yaml - argocd-gitea-token.sealed.secret.yaml diff --git a/manifest/overlays/production/repo-server-patch.yaml b/manifest/overlays/production/repo-server-patch.yaml index 9eab332..b92c425 100644 --- a/manifest/overlays/production/repo-server-patch.yaml +++ b/manifest/overlays/production/repo-server-patch.yaml @@ -27,6 +27,26 @@ spec: - mountPath: /var/run/argocd name: var-files containers: + - name: argocd-lovely-plugin + image: ghcr.io/crumbhole/lovely:1.2.4 + command: + - /var/run/argocd/argocd-cmp-server + securityContext: + allowPrivilegeEscalation: false + capabilities: + drop: + - ALL + runAsNonRoot: true + runAsUser: 999 + seccompProfile: + type: RuntimeDefault + volumeMounts: + - mountPath: /var/run/argocd + name: var-files + - mountPath: /home/argocd/cmp-server/plugins + name: plugins + - mountPath: /tmp + name: lovely-tmp - name: ksops image: viaductoss/ksops:v4.3.2 command: @@ -59,3 +79,5 @@ spec: secretName: argocd-age-key - name: cmp-tmp emptyDir: {} + - name: lovely-tmp + emptyDir: {}