add lovely argocd plugin, argo-rollout, and argocd-image-updater
Validate manifests / validate (push) Successful in 7s

This commit is contained in:
2026-05-11 11:31:05 +01:00
parent 9af2fe900d
commit e610f6df86
6 changed files with 70 additions and 2 deletions
+27
View File
@@ -0,0 +1,27 @@
# argocd
GitOps source for the cluster Argo CD installation. This app is self-managed by
Argo CD and intentionally uses a conservative sync policy.
## Current deployment
- Bootstrap: `enabled: true`, applied from `main`
- Argo application: `argocd-production`
- Target namespace: `argocd`
- Render path: `manifest/overlays/production`
- Repo URL used by Argo CD: `http://gitea-ha-http.apps:3000/olb42/argocd.git`
- Config management plugin: `ksops`
## Runtime
The base installs upstream Argo CD `v3.3.6` from the official install manifest.
The production overlay adds the Traefik route for `argocd.olb42.com`, KSOPS CMP
configuration, repo credentials, notifications, Redis credentials, and patches
for Argo CD config, RBAC, command parameters, repo-server behavior, and bundled
Redis disablement.
## Sync policy
Automated sync is disabled for the Argo CD application itself. Prune and
self-heal are also disabled so a bad self-management change cannot remove the
control plane that would be needed to repair it.
@@ -0,0 +1,8 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: argo-rollouts
resources:
- namespace.yaml
- https://github.com/argoproj/argo-rollouts/releases/download/v1.9.0/install.yaml
@@ -0,0 +1,4 @@
apiVersion: v1
kind: Namespace
metadata:
name: argo-rollouts
@@ -0,0 +1,7 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: argocd
resources:
- https://raw.githubusercontent.com/argoproj-labs/argocd-image-updater/v1.2.0/config/install.yaml
@@ -1,10 +1,10 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: argocd
resources:
- ../../base
- argo-rollouts
- argocd-image-updater
- argocd-cmp-cm.yaml
- ingressroute.yaml
- argocd-gitea-token.sealed.secret.yaml
@@ -27,6 +27,26 @@ spec:
- mountPath: /var/run/argocd
name: var-files
containers:
- name: argocd-lovely-plugin
image: ghcr.io/crumbhole/lovely:1.2.4
command:
- /var/run/argocd/argocd-cmp-server
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
runAsNonRoot: true
runAsUser: 999
seccompProfile:
type: RuntimeDefault
volumeMounts:
- mountPath: /var/run/argocd
name: var-files
- mountPath: /home/argocd/cmp-server/plugins
name: plugins
- mountPath: /tmp
name: lovely-tmp
- name: ksops
image: viaductoss/ksops:v4.3.2
command:
@@ -59,3 +79,5 @@ spec:
secretName: argocd-age-key
- name: cmp-tmp
emptyDir: {}
- name: lovely-tmp
emptyDir: {}