add lovely argocd plugin, argo-rollout, and argocd-image-updater
Validate manifests / validate (push) Successful in 7s
Validate manifests / validate (push) Successful in 7s
This commit is contained in:
@@ -0,0 +1,27 @@
|
||||
# argocd
|
||||
|
||||
GitOps source for the cluster Argo CD installation. This app is self-managed by
|
||||
Argo CD and intentionally uses a conservative sync policy.
|
||||
|
||||
## Current deployment
|
||||
|
||||
- Bootstrap: `enabled: true`, applied from `main`
|
||||
- Argo application: `argocd-production`
|
||||
- Target namespace: `argocd`
|
||||
- Render path: `manifest/overlays/production`
|
||||
- Repo URL used by Argo CD: `http://gitea-ha-http.apps:3000/olb42/argocd.git`
|
||||
- Config management plugin: `ksops`
|
||||
|
||||
## Runtime
|
||||
|
||||
The base installs upstream Argo CD `v3.3.6` from the official install manifest.
|
||||
The production overlay adds the Traefik route for `argocd.olb42.com`, KSOPS CMP
|
||||
configuration, repo credentials, notifications, Redis credentials, and patches
|
||||
for Argo CD config, RBAC, command parameters, repo-server behavior, and bundled
|
||||
Redis disablement.
|
||||
|
||||
## Sync policy
|
||||
|
||||
Automated sync is disabled for the Argo CD application itself. Prune and
|
||||
self-heal are also disabled so a bad self-management change cannot remove the
|
||||
control plane that would be needed to repair it.
|
||||
@@ -0,0 +1,8 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
namespace: argo-rollouts
|
||||
|
||||
resources:
|
||||
- namespace.yaml
|
||||
- https://github.com/argoproj/argo-rollouts/releases/download/v1.9.0/install.yaml
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: argo-rollouts
|
||||
@@ -0,0 +1,7 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
namespace: argocd
|
||||
|
||||
resources:
|
||||
- https://raw.githubusercontent.com/argoproj-labs/argocd-image-updater/v1.2.0/config/install.yaml
|
||||
@@ -1,10 +1,10 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
namespace: argocd
|
||||
|
||||
resources:
|
||||
- ../../base
|
||||
- argo-rollouts
|
||||
- argocd-image-updater
|
||||
- argocd-cmp-cm.yaml
|
||||
- ingressroute.yaml
|
||||
- argocd-gitea-token.sealed.secret.yaml
|
||||
|
||||
@@ -27,6 +27,26 @@ spec:
|
||||
- mountPath: /var/run/argocd
|
||||
name: var-files
|
||||
containers:
|
||||
- name: argocd-lovely-plugin
|
||||
image: ghcr.io/crumbhole/lovely:1.2.4
|
||||
command:
|
||||
- /var/run/argocd/argocd-cmp-server
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
runAsNonRoot: true
|
||||
runAsUser: 999
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
volumeMounts:
|
||||
- mountPath: /var/run/argocd
|
||||
name: var-files
|
||||
- mountPath: /home/argocd/cmp-server/plugins
|
||||
name: plugins
|
||||
- mountPath: /tmp
|
||||
name: lovely-tmp
|
||||
- name: ksops
|
||||
image: viaductoss/ksops:v4.3.2
|
||||
command:
|
||||
@@ -59,3 +79,5 @@ spec:
|
||||
secretName: argocd-age-key
|
||||
- name: cmp-tmp
|
||||
emptyDir: {}
|
||||
- name: lovely-tmp
|
||||
emptyDir: {}
|
||||
|
||||
Reference in New Issue
Block a user