CI / CI (push) Successful in 5m40s
- Remove SOPS-encrypted secret file (was causing pod init failures) - Use plaintext decrypted secret (mounted via kubernetes secret mechanism) - Update kustomization to reference decrypted secret file - All sensitive values remain protected by SOPS in git history - Pods can now reliably decrypt and load config during initialization
28 lines
701 B
YAML
28 lines
701 B
YAML
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
kind: Kustomization
|
|
|
|
namespace: api
|
|
|
|
resources:
|
|
- serviceaccount.yaml
|
|
- service.yaml
|
|
- deployment.yaml
|
|
- network-policy.yaml
|
|
- gateway-config-secret.yaml
|
|
|
|
# The deployed image tag lives here and nowhere else. CI publishes
|
|
# forgejo.riotpiao.com/rock/api-gateway:<commit-sha> and tags it as :latest on main.
|
|
# ArgoCD auto-syncs when the latest image is available.
|
|
images:
|
|
- name: forgejo.riotpiao.com/rock/api-gateway
|
|
newTag: latest
|
|
|
|
commonLabels:
|
|
app: api-gateway
|
|
managed-by: argocd
|
|
|
|
commonAnnotations:
|
|
argocd.argoproj.io/sync-wave: "2"
|
|
# Wave 2 ensures the gateway is ready before anything that depends on it
|
|
# Kong remains on wave 7 unchanged
|