Files
login/bootstrap/applicationset.yaml
olb042 6f29be2987
Validate login GitOps repo / validate (push) Successful in 9s
feat: initial scaffold from helm-template
- Keycloak Operator v26 deployed to keycloak-system namespace
- Keycloak HA instance (2 replicas, jdbc-ping cluster discovery)
- Dedicated CNPG cluster (local-postgres storage, 2 instances)
- KeycloakRealmImport: home-lab realm with groups and traefik-oidc client
- Traefik IngressRoute: login.olb42.com (CF Access bypass)
- Admin credentials placeholder (seal before first deploy)
- ArgoCD ApplicationSets: login-operator + login
2026-05-10 22:32:49 +01:00

100 lines
3.1 KiB
YAML

# ── ApplicationSet 1: Keycloak Operator (CRDs + controller) ──────────────────
# Deploys the Keycloak Operator into its own namespace so it can manage
# Keycloak instances cluster-wide. The operator install includes cluster-scoped
# resources (CRDs, ClusterRoles) which must be applied with ServerSideApply.
apiVersion: argoproj.io/v1alpha1
kind: ApplicationSet
metadata:
name: login-operator
namespace: argocd
spec:
ignoreApplicationDifferences:
- jsonPointers:
- /spec/syncPolicy
goTemplate: true
goTemplateOptions: ["missingkey=error"]
generators:
- list:
elements:
- environment: production
namespace: keycloak-system
template:
metadata:
name: 'login-operator-{{ .environment }}'
labels:
app.kubernetes.io/managed-by: argocd
app.kubernetes.io/name: login-operator
spec:
project: default
source:
repoURL: http://gitea-ha-http.apps:3000/olb42/login.git
targetRevision: main
path: manifest/operator
kustomize:
commonAnnotationsEnvsubst: true
commonAnnotations:
app-source: ${ARGOCD_APP_SOURCE_REPO_URL}
app-revision: ${ARGOCD_APP_SOURCE_TARGET_REVISION}
destination:
server: https://kubernetes.default.svc
namespace: '{{ .namespace }}'
syncPolicy:
automated:
prune: false
selfHeal: true
enabled: true
syncOptions:
- CreateNamespace=true
- ApplyOutOfSyncOnly=true
- ServerSideApply=true
- Replace=false
---
# ── ApplicationSet 2: login Keycloak instance ────────────────────────────────
# Deploys the Keycloak CR, CNPG cluster, IngressRoute, and realm config.
# Depends on login-operator being synced first (CRDs must exist).
apiVersion: argoproj.io/v1alpha1
kind: ApplicationSet
metadata:
name: login
namespace: argocd
spec:
ignoreApplicationDifferences:
- jsonPointers:
- /spec/syncPolicy
goTemplate: true
goTemplateOptions: ["missingkey=error"]
generators:
- list:
elements:
- environment: production
namespace: login
template:
metadata:
name: 'login-{{ .environment }}'
labels:
app.kubernetes.io/managed-by: argocd
app.kubernetes.io/name: login
spec:
project: default
source:
repoURL: http://gitea-ha-http.apps:3000/olb42/login.git
targetRevision: main
path: 'manifest/overlays/{{ .environment }}'
kustomize:
commonAnnotationsEnvsubst: true
commonAnnotations:
app-source: ${ARGOCD_APP_SOURCE_REPO_URL}
app-revision: ${ARGOCD_APP_SOURCE_TARGET_REVISION}
destination:
server: https://kubernetes.default.svc
namespace: '{{ .namespace }}'
syncPolicy:
automated:
prune: true
selfHeal: true
enabled: true
syncOptions:
- CreateNamespace=true
- ApplyOutOfSyncOnly=true
- ServerSideApply=true