Files
homelab/CONSOLIDATION-RESULTS.md
T

189 lines
4.9 KiB
Markdown
Raw Normal View History

# ArgoCD Application Consolidation - Implementation Results
## Summary
**Before:** 39 Applications
**After:** 35 Applications
**Removed:** 4 Applications (-10.3%)
## Implemented Merges
### ✅ 1. ingress-config ← wildcard-cert + homelab-ingress
**Before:**
- `wildcard-cert` (wave 1): k8s/bootstrap/ingress/riotpiao-com-cert.yaml
- `homelab-ingress` (wave 2): k8s/bootstrap/ingress/ingress.yaml
**After:**
- `ingress-config` (wave 1): k8s/bootstrap/ingress/ (kustomization)
**Changes:**
- Updated `k8s/bootstrap/ingress/kustomization.yaml` to include both files
- Merged both Applications into single `ingress-config` in `00-substrate.yaml`
- Certificate created before Ingresses (wave 1)
---
### ✅ 2. homarr ← homarr + homarr-patches
**Before:**
- `homarr` (wave 8): Helm chart + values
- `homarr-patches` (wave 9): k8s/applications/homarr/ (PostSync hook)
**After:**
- `homarr` (wave 8): Multi-source (Helm + values + PostSync patches)
**Changes:**
- Added third source to homarr Application
- fix-probes-job.yaml already has PostSync hook annotation
- Removed homarr-patches Application from `60-applications.yaml`
---
### ✅ 3. temporal ← temporal + temporal-db-secret-sync
**Before:**
- `temporal-db-secret-sync` (wave 7): k8s/applications/temporal/db-secret-sync/
- `temporal` (wave 8): Helm chart + values
**After:**
- `temporal` (wave 8): Multi-source (Helm + values + PostSync db-secret-sync)
**Changes:**
- Added third source to temporal Application
- copy-job.yaml already has PostSync hook annotation
- Removed temporal-db-secret-sync Application from `60-applications.yaml`
---
### ✅ 4. Removed Duplicate: ingress-nginx
**Before:**
- `ingress-nginx-bootstrap` (bootstrap): Working, has LoadBalancer IP
- `ingress-nginx` (ArgoCD): Duplicate, LoadBalancer pending
**After:**
- `ingress-nginx-bootstrap` (bootstrap): Kept
**Changes:**
- Removed ingress-nginx Application from `00-substrate.yaml`
- Bootstrap version breaks circular dependency (ArgoCD → Forgejo → Ingress)
- Eliminated duplicate DaemonSet
---
## Skipped Consolidations
### ⏭️ cert-manager + cert-manager-issuers
**Decision:** KEEP SEPARATE
**Reasoning:**
- cert-manager (wave 0) installs CRDs
- cert-manager-issuers (wave 1) creates Issuers using those CRDs
- Wave separation ensures CRDs exist before Issuers
- Merging risks race condition (Issuer created before CRD ready)
- This is intentional separation for safety
---
## Files Modified
1. `k8s/bootstrap/ingress/kustomization.yaml` - Added resources list
2. `k8s/argocd/apps/00-substrate.yaml` - Merged wildcard-cert + homelab-ingress, removed ingress-nginx
3. `k8s/argocd/apps/60-applications.yaml` - Merged homarr + temporal Applications
---
## Benefits Achieved
### ✅ Easier Management
- 4 fewer Application CRs to track
- Related resources grouped together
- Clearer ownership model
### ✅ Better Sync Behavior
- PostSync hooks ensure proper ordering
- No separate Applications for patches/hooks
- Single Application manages entire stack
### ✅ Cleaner Structure
- Multi-source Applications are standard pattern
- Each logical service = one Application
- Hooks embedded where they belong
---
## Next Steps (Optional Phase 2)
### Potential Future Consolidations:
1. **SQS Platform** (5 → 2 Applications)
- Keep `strimzi-operator` separate
- Merge: kmsvc-redis + kafka-cluster + queue-crd + management-service
2. **IAM** (3 → 2 Applications)
- Keep `vault` separate
- Merge: authentik + iam-jobs
3. **Monitoring** (3 → 2 Applications)
- Keep `prometheus-crds` separate (wave 0)
- Merge: prometheus + blackbox-exporter
**Recommendation:** Evaluate after Forgejo push and observe current consolidations in action.
---
## Validation Plan
After pushing to Forgejo:
```bash
# Check Applications synced successfully
kubectl get applications -n argocd
# Verify consolidated Applications are healthy
kubectl get application ingress-config -n argocd
kubectl get application homarr -n argocd
kubectl get application temporal -n argocd
# Check ingress-nginx duplicate removed
kubectl get application ingress-nginx -n argocd # Should be gone
# Verify resources deployed correctly
kubectl get certificate -n ingress-nginx riotpiao-com-tls
kubectl get ingress -A
kubectl get job -n dashboard homarr-fix-probes
kubectl get job -n temporal temporal-db-secret-sync
```
---
## Rollback Procedure
If issues arise, revert specific commits:
```bash
# Identify commit
git log --oneline | grep consolidation
# Revert specific merge
git revert <commit-hash>
# Or restore old Applications from git history
git show <commit>:k8s/argocd/apps/00-substrate.yaml > temp.yaml
kubectl apply -f temp.yaml
```
---
## Conclusion
Successfully consolidated 4 Applications while maintaining:
- ✅ Proper sync wave ordering
- ✅ Hook execution timing
- ✅ Resource namespace separation
- ✅ GitOps best practices
**Status:** Ready to commit and push to Forgejo for validation.