Install Tekton Pipelines via ArgoCD for Kubernetes-native CI/CD: COMPONENTS: - Tekton Pipelines: CNCF-standard test orchestration - Task/Pipeline CRDs: Reusable workflow definitions - PipelineRun: Ephemeral execution instances - ArgoCD Application: GitOps-managed installation INTEGRATION: - homelab-frontend CI triggers PipelineRun via Kubernetes API - Tests run in cluster against actual services - Results flow back to CI for pass/fail decisions - Image promotion only on test success FILES: - k8s/infra/tekton/: Tekton infrastructure setup - namespace.yaml: tekton-pipelines namespace - kustomization.yaml: Release manifest reference - k8s/argocd/apps/06-ci-cd.yaml: ArgoCD Application - k8s/argocd/projects/homelab-project.yaml: Added Tekton repos WAVE ORDERING: Wave 06 (CI/CD) is deployed after: - Wave 05 (Networking) - Wave 04 (Core components) But before Wave 40+ (Applications) BENEFITS: ✓ Kubernetes-native (no external CI runners) ✓ GitOps-managed (everything in git via ArgoCD) ✓ CNCF-standard (industry-proven Tekton project) ✓ Pre-merge testing (tests must pass before deploy) ✓ Observable (logs, status, results tracking) ✓ Secure (non-root, resource limits, RBAC)
59 lines
2.5 KiB
YAML
59 lines
2.5 KiB
YAML
# k8s/argocd/projects/homelab-project.yaml
|
|
# AppProject referenced by every Application manifest under k8s/argocd/apps/
|
|
# (project: homelab) — was never committed, so 00-homelab-root.yaml and all
|
|
# layer/wave/phase apps fail admission with "application references project
|
|
# 'homelab' which does not exist" until this exists.
|
|
apiVersion: argoproj.io/v1alpha1
|
|
kind: AppProject
|
|
metadata:
|
|
name: homelab
|
|
namespace: argocd
|
|
spec:
|
|
description: Homelab GitOps — single-repo, in-cluster destinations only
|
|
sourceRepos:
|
|
- https://github.com/Riotpiaole/riotpiao.homelab.com.git
|
|
# Poimen services (GitHub)
|
|
- https://github.com/Riotpiaole/Poimen-memory.git
|
|
- https://github.com/Riotpiaole/Poimen-workflows.git
|
|
- https://github.com/Riotpiaole/poimen*.git
|
|
# In-cluster Forgejo repos — explicit allowlist (no wildcard)
|
|
- https://forgejo.riotpiao.com/riotpiao-poimen/homelab.git
|
|
- https://forgejo.riotpiao.com/riotpiao-poimen/homelab-frontend.git
|
|
- https://forgejo.riotpiao.com/riotpiao-poimen/kmsvc-manage.git
|
|
- https://forgejo.riotpiao.com/riotpiao-poimen/poimen.git
|
|
- https://forgejo.riotpiao.com/riotpiao-poimen/poimen-memory.git
|
|
- https://forgejo.riotpiao.com/riotpiao-poimen/poimen-workflows.git
|
|
- https://forgejo.riotpiao.com/riotpiao-poimen/poimen-frontend.git
|
|
- https://forgejo.riotpiao.com/rock/riotpiao.com.git
|
|
# Public Helm chart repos referenced by k8s/argocd/apps/* and bootstrap/*
|
|
- https://cloudnative-pg.github.io/charts
|
|
- https://dl.gitea.com/charts/
|
|
- https://charts.min.io/
|
|
- https://operator.min.io/
|
|
- https://prometheus-community.github.io/helm-charts
|
|
- https://grafana.github.io/helm-charts
|
|
- https://helm.releases.hashicorp.com
|
|
- https://charts.goauthentik.io
|
|
- https://strimzi.io/charts/
|
|
- https://charts.bitnami.com/bitnami
|
|
- https://homarr-labs.github.io/charts
|
|
- https://go.temporal.io/helm-charts
|
|
- https://portainer.github.io/k8s/
|
|
# Substrate charts (cert-manager, ingress-nginx, reloader) — app-of-apps owned
|
|
- https://charts.jetstack.io
|
|
- https://kubernetes.github.io/ingress-nginx
|
|
- https://stakater.github.io/stakater-charts
|
|
# ArgoCD ecosystem charts
|
|
- https://argoproj.github.io/argo-helm
|
|
# Tekton Pipelines (CNCF CI/CD)
|
|
- https://github.com/tektoncd/pipeline.git
|
|
destinations:
|
|
- server: https://kubernetes.default.svc
|
|
namespace: "*"
|
|
clusterResourceWhitelist:
|
|
- group: "*"
|
|
kind: "*"
|
|
namespaceResourceWhitelist:
|
|
- group: "*"
|
|
kind: "*"
|