diff --git a/k8s/argocd/apps/06-ci-cd.yaml b/k8s/argocd/apps/06-ci-cd.yaml new file mode 100644 index 0000000..4bc9182 --- /dev/null +++ b/k8s/argocd/apps/06-ci-cd.yaml @@ -0,0 +1,46 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application +metadata: + name: tekton-pipelines + namespace: argocd + labels: + app.kubernetes.io/name: tekton-pipelines + app.kubernetes.io/part-of: homelab-infra + wave: "06" +spec: + project: homelab + + source: + repoURL: https://github.com/tektoncd/pipeline.git + targetRevision: main + path: config/release + + destination: + server: https://kubernetes.default.svc + namespace: tekton-pipelines + + syncPolicy: + automated: + prune: true + selfHeal: true + syncOptions: + - CreateNamespace=true + - Validate=false + - RespectIgnoreDifferences=true + retry: + limit: 5 + backoff: + duration: 5s + factor: 2 + maxDuration: 3m + + ignoreDifferences: + # Ignore webhook certificate changes (managed by cert-manager) + - group: admissionregistration.k8s.io + kind: ValidatingWebhookConfiguration + jsonPointers: + - /webhooks/0/clientConfig/caBundle + - group: admissionregistration.k8s.io + kind: MutatingWebhookConfiguration + jsonPointers: + - /webhooks/0/clientConfig/caBundle diff --git a/k8s/argocd/projects/homelab-project.yaml b/k8s/argocd/projects/homelab-project.yaml index c99fa5f..82d2faa 100644 --- a/k8s/argocd/projects/homelab-project.yaml +++ b/k8s/argocd/projects/homelab-project.yaml @@ -45,6 +45,8 @@ spec: - https://stakater.github.io/stakater-charts # ArgoCD ecosystem charts - https://argoproj.github.io/argo-helm + # Tekton Pipelines (CNCF CI/CD) + - https://github.com/tektoncd/pipeline.git destinations: - server: https://kubernetes.default.svc namespace: "*" diff --git a/k8s/infra/tekton/kustomization.yaml b/k8s/infra/tekton/kustomization.yaml new file mode 100644 index 0000000..539c62f --- /dev/null +++ b/k8s/infra/tekton/kustomization.yaml @@ -0,0 +1,40 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +metadata: + name: tekton-pipelines + +# Tekton release includes CRDs, RBAC, controllers, webhook +# We use a remote base to stay on the latest stable release +bases: +- https://storage.googleapis.com/tekton-releases/pipeline/latest/release.yaml?ref=main + +# Add our local namespace override +resources: +- namespace.yaml + +# Common labels for all resources +commonLabels: + app: tekton + component: pipelines + managed-by: argocd + +# Don't transform namespace - let the release define its own +# namespace: tekton-pipelines + +patches: + # Ensure webhook is properly configured for validation + - target: + kind: ValidatingWebhookConfiguration + name: validation.webhook.pipeline.tekton.dev + patch: |- + - op: replace + path: /webhooks/0/failurePolicy + value: Fail + # Ensure mutation webhook is properly configured + - target: + kind: MutatingWebhookConfiguration + name: webhook.pipeline.tekton.dev + patch: |- + - op: replace + path: /webhooks/0/failurePolicy + value: Fail diff --git a/k8s/infra/tekton/namespace.yaml b/k8s/infra/tekton/namespace.yaml new file mode 100644 index 0000000..39dc2bf --- /dev/null +++ b/k8s/infra/tekton/namespace.yaml @@ -0,0 +1,7 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: tekton-pipelines + labels: + name: tekton-pipelines + managed-by: argocd