fix: vendor Tekton release.yaml for proper ArgoCD management

ROOT CAUSE:
- tektoncd/pipeline config/ dir uses ko:// image refs (build-time placeholders)
- ArgoCD synced the raw dev manifests → InvalidImageName on all pods
- tektoncd/operator requires its own CRDs and controller (too heavy)
- Tekton has no official Helm chart

FIX:
- Vendor the pre-built release.yaml (v0.68.0) into k8s/infra/tekton/
- Point ArgoCD Application at our own repo (forgejo)
- Release contains real container images (ghcr.io/tektoncd/pipeline/*)
- Remove external tektoncd repo from AppProject (not needed)

TO UPGRADE TEKTON:
  1. Download new release from github.com/tektoncd/pipeline/releases
  2. Replace k8s/infra/tekton/release.yaml
  3. Commit — ArgoCD syncs automatically
This commit is contained in:
2026-09-13 15:10:39 +09:00
parent b06ee310b5
commit 7a5d0a83d5
6 changed files with 3595 additions and 107 deletions
+14 -9
View File
@@ -1,3 +1,12 @@
# Tekton Pipelines v0.68.0
#
# Install method: vendored release.yaml in k8s/infra/tekton/
# downloaded from https://storage.googleapis.com/tekton-releases/pipeline/previous/v0.68.0/release.yaml
#
# To upgrade:
# 1. Download new release.yaml from https://github.com/tektoncd/pipeline/releases
# 2. Replace k8s/infra/tekton/release.yaml
# 3. Commit and push — ArgoCD syncs automatically
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
@@ -11,13 +20,9 @@ spec:
project: homelab
source:
# tektoncd/operator is the official Kubernetes Operator for Tekton
# It manages the lifecycle of Tekton Pipelines installation
# Source: https://github.com/tektoncd/operator
repoURL: https://github.com/tektoncd/operator.git
repoURL: https://forgejo.riotpiao.com/riotpiao-poimen/homelab.git
targetRevision: main
# The operator's config directory contains the latest release manifests
path: config/install
path: k8s/infra/tekton
destination:
server: https://kubernetes.default.svc
@@ -29,8 +34,7 @@ spec:
selfHeal: true
syncOptions:
- CreateNamespace=true
- Validate=false
- RespectIgnoreDifferences=true
- ServerSideApply=true
retry:
limit: 5
backoff:
@@ -39,12 +43,13 @@ spec:
maxDuration: 3m
ignoreDifferences:
# Ignore webhook certificate changes (managed by cert-manager)
- group: admissionregistration.k8s.io
kind: ValidatingWebhookConfiguration
jsonPointers:
- /webhooks/0/clientConfig/caBundle
- /webhooks
- group: admissionregistration.k8s.io
kind: MutatingWebhookConfiguration
jsonPointers:
- /webhooks/0/clientConfig/caBundle
- /webhooks
-2
View File
@@ -45,8 +45,6 @@ spec:
- https://stakater.github.io/stakater-charts
# ArgoCD ecosystem charts
- https://argoproj.github.io/argo-helm
# Tekton Pipelines (CNCF CI/CD) — uses tektoncd/operator
- https://github.com/tektoncd/operator.git
destinations:
- server: https://kubernetes.default.svc
namespace: "*"
-45
View File
@@ -1,45 +0,0 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: tekton-pipelines
namespace: argocd
labels:
app.kubernetes.io/name: tekton-pipelines
app.kubernetes.io/part-of: homelab-infra
spec:
project: default
source:
repoURL: https://github.com/tektoncd/pipeline.git
targetRevision: main
path: config/release
destination:
server: https://kubernetes.default.svc
namespace: tekton-pipelines
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true
- Validate=false
- RespectIgnoreDifferences=true
retry:
limit: 5
backoff:
duration: 5s
factor: 2
maxDuration: 3m
ignoreDifferences:
# Ignore webhook certificate changes
- group: admissionregistration.k8s.io
kind: ValidatingWebhookConfiguration
jsonPointers:
- /webhooks/0/clientConfig/caBundle
- group: admissionregistration.k8s.io
kind: MutatingWebhookConfiguration
jsonPointers:
- /webhooks/0/clientConfig/caBundle
-40
View File
@@ -1,40 +0,0 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
metadata:
name: tekton-pipelines
# Tekton release includes CRDs, RBAC, controllers, webhook
# We use a remote base to stay on the latest stable release
bases:
- https://storage.googleapis.com/tekton-releases/pipeline/latest/release.yaml?ref=main
# Add our local namespace override
resources:
- namespace.yaml
# Common labels for all resources
commonLabels:
app: tekton
component: pipelines
managed-by: argocd
# Don't transform namespace - let the release define its own
# namespace: tekton-pipelines
patches:
# Ensure webhook is properly configured for validation
- target:
kind: ValidatingWebhookConfiguration
name: validation.webhook.pipeline.tekton.dev
patch: |-
- op: replace
path: /webhooks/0/failurePolicy
value: Fail
# Ensure mutation webhook is properly configured
- target:
kind: MutatingWebhookConfiguration
name: webhook.pipeline.tekton.dev
patch: |-
- op: replace
path: /webhooks/0/failurePolicy
value: Fail
-7
View File
@@ -1,7 +0,0 @@
apiVersion: v1
kind: Namespace
metadata:
name: tekton-pipelines
labels:
name: tekton-pipelines
managed-by: argocd
File diff suppressed because it is too large Load Diff