Files
argocd/manifest/overlays/production/repo-server-patch.yaml
T
olb042 40eb3b842c
Validate manifests / validate (push) Failing after 4s
feat: initial ArgoCD GitOps self-management setup
- Base references upstream ArgoCD v3.3.6 install.yaml
- Production overlay applies all cluster customizations:
  - KSOPS CMP sidecar on argocd-repo-server
  - Custom ConfigMaps (argocd-cm, argocd-cmd-params-cm, argocd-rbac-cm, argocd-notifications-cm)
  - Redis migrated to shared-redis.data:6379
  - Traefik IngressRoute for argocd.olb42.com
  - SOPS-encrypted secrets (age key, redis auth, gitea tokens, repo-creds)
- Bootstrap Application with prune:false for safe self-management
2026-04-19 23:36:09 +01:00

62 lines
1.8 KiB
YAML

apiVersion: apps/v1
kind: Deployment
metadata:
name: argocd-repo-server
namespace: argocd
spec:
template:
spec:
initContainers:
- name: copyutil
image: quay.io/argoproj/argocd:v3.3.6
command:
- sh
- -c
args:
- /bin/cp --update=none /usr/local/bin/argocd /var/run/argocd/argocd && /bin/ln -s /var/run/argocd/argocd /var/run/argocd/argocd-cmp-server
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
volumeMounts:
- mountPath: /var/run/argocd
name: var-files
containers:
- name: ksops
image: viaductoss/ksops:v4.3.2
command:
- /var/run/argocd/argocd-cmp-server
env:
- name: SOPS_AGE_KEY_FILE
value: /age/key.txt
securityContext:
runAsNonRoot: true
runAsUser: 999
volumeMounts:
- mountPath: /var/run/argocd
name: var-files
- mountPath: /home/argocd/cmp-server/plugins
name: plugins
- mountPath: /home/argocd/cmp-server/config/plugin.yaml
name: argocd-cmp-cm
subPath: ksops.yaml
- mountPath: /age
name: age-key
readOnly: true
- mountPath: /tmp
name: cmp-tmp
volumes:
- name: argocd-cmp-cm
configMap:
name: argocd-cmp-cm
- name: age-key
secret:
secretName: argocd-age-key
- name: cmp-tmp
emptyDir: {}