189 lines
4.9 KiB
Markdown
189 lines
4.9 KiB
Markdown
# ArgoCD Application Consolidation - Implementation Results
|
|||
|
|
|
||
|
|
## Summary
|
||
|
|
|
||
|
|
**Before:** 39 Applications
|
||
|
|
**After:** 35 Applications
|
||
|
|
**Removed:** 4 Applications (-10.3%)
|
||
|
|
|
||
|
|
## Implemented Merges
|
||
|
|
|
||
|
|
### ✅ 1. ingress-config ← wildcard-cert + homelab-ingress
|
||
|
|
|
||
|
|
**Before:**
|
||
|
|
- `wildcard-cert` (wave 1): k8s/bootstrap/ingress/riotpiao-com-cert.yaml
|
||
|
|
- `homelab-ingress` (wave 2): k8s/bootstrap/ingress/ingress.yaml
|
||
|
|
|
||
|
|
**After:**
|
||
|
|
- `ingress-config` (wave 1): k8s/bootstrap/ingress/ (kustomization)
|
||
|
|
|
||
|
|
**Changes:**
|
||
|
|
- Updated `k8s/bootstrap/ingress/kustomization.yaml` to include both files
|
||
|
|
- Merged both Applications into single `ingress-config` in `00-substrate.yaml`
|
||
|
|
- Certificate created before Ingresses (wave 1)
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
### ✅ 2. homarr ← homarr + homarr-patches
|
||
|
|
|
||
|
|
**Before:**
|
||
|
|
- `homarr` (wave 8): Helm chart + values
|
||
|
|
- `homarr-patches` (wave 9): k8s/applications/homarr/ (PostSync hook)
|
||
|
|
|
||
|
|
**After:**
|
||
|
|
- `homarr` (wave 8): Multi-source (Helm + values + PostSync patches)
|
||
|
|
|
||
|
|
**Changes:**
|
||
|
|
- Added third source to homarr Application
|
||
|
|
- fix-probes-job.yaml already has PostSync hook annotation
|
||
|
|
- Removed homarr-patches Application from `60-applications.yaml`
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
### ✅ 3. temporal ← temporal + temporal-db-secret-sync
|
||
|
|
|
||
|
|
**Before:**
|
||
|
|
- `temporal-db-secret-sync` (wave 7): k8s/applications/temporal/db-secret-sync/
|
||
|
|
- `temporal` (wave 8): Helm chart + values
|
||
|
|
|
||
|
|
**After:**
|
||
|
|
- `temporal` (wave 8): Multi-source (Helm + values + PostSync db-secret-sync)
|
||
|
|
|
||
|
|
**Changes:**
|
||
|
|
- Added third source to temporal Application
|
||
|
|
- copy-job.yaml already has PostSync hook annotation
|
||
|
|
- Removed temporal-db-secret-sync Application from `60-applications.yaml`
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
### ✅ 4. Removed Duplicate: ingress-nginx
|
||
|
|
|
||
|
|
**Before:**
|
||
|
|
- `ingress-nginx-bootstrap` (bootstrap): Working, has LoadBalancer IP
|
||
|
|
- `ingress-nginx` (ArgoCD): Duplicate, LoadBalancer pending
|
||
|
|
|
||
|
|
**After:**
|
||
|
|
- `ingress-nginx-bootstrap` (bootstrap): Kept
|
||
|
|
|
||
|
|
**Changes:**
|
||
|
|
- Removed ingress-nginx Application from `00-substrate.yaml`
|
||
|
|
- Bootstrap version breaks circular dependency (ArgoCD → Forgejo → Ingress)
|
||
|
|
- Eliminated duplicate DaemonSet
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## Skipped Consolidations
|
||
|
|
|
||
|
|
### ⏭️ cert-manager + cert-manager-issuers
|
||
|
|
|
||
|
|
**Decision:** KEEP SEPARATE
|
||
|
|
|
||
|
|
**Reasoning:**
|
||
|
|
- cert-manager (wave 0) installs CRDs
|
||
|
|
- cert-manager-issuers (wave 1) creates Issuers using those CRDs
|
||
|
|
- Wave separation ensures CRDs exist before Issuers
|
||
|
|
- Merging risks race condition (Issuer created before CRD ready)
|
||
|
|
- This is intentional separation for safety
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## Files Modified
|
||
|
|
|
||
|
|
1. `k8s/bootstrap/ingress/kustomization.yaml` - Added resources list
|
||
|
|
2. `k8s/argocd/apps/00-substrate.yaml` - Merged wildcard-cert + homelab-ingress, removed ingress-nginx
|
||
|
|
3. `k8s/argocd/apps/60-applications.yaml` - Merged homarr + temporal Applications
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## Benefits Achieved
|
||
|
|
|
||
|
|
### ✅ Easier Management
|
||
|
|
- 4 fewer Application CRs to track
|
||
|
|
- Related resources grouped together
|
||
|
|
- Clearer ownership model
|
||
|
|
|
||
|
|
### ✅ Better Sync Behavior
|
||
|
|
- PostSync hooks ensure proper ordering
|
||
|
|
- No separate Applications for patches/hooks
|
||
|
|
- Single Application manages entire stack
|
||
|
|
|
||
|
|
### ✅ Cleaner Structure
|
||
|
|
- Multi-source Applications are standard pattern
|
||
|
|
- Each logical service = one Application
|
||
|
|
- Hooks embedded where they belong
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## Next Steps (Optional Phase 2)
|
||
|
|
|
||
|
|
### Potential Future Consolidations:
|
||
|
|
|
||
|
|
1. **SQS Platform** (5 → 2 Applications)
|
||
|
|
- Keep `strimzi-operator` separate
|
||
|
|
- Merge: kmsvc-redis + kafka-cluster + queue-crd + management-service
|
||
|
|
|
||
|
|
2. **IAM** (3 → 2 Applications)
|
||
|
|
- Keep `vault` separate
|
||
|
|
- Merge: authentik + iam-jobs
|
||
|
|
|
||
|
|
3. **Monitoring** (3 → 2 Applications)
|
||
|
|
- Keep `prometheus-crds` separate (wave 0)
|
||
|
|
- Merge: prometheus + blackbox-exporter
|
||
|
|
|
||
|
|
**Recommendation:** Evaluate after Forgejo push and observe current consolidations in action.
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## Validation Plan
|
||
|
|
|
||
|
|
After pushing to Forgejo:
|
||
|
|
|
||
|
|
```bash
|
||
|
|
# Check Applications synced successfully
|
||
|
|
kubectl get applications -n argocd
|
||
|
|
|
||
|
|
# Verify consolidated Applications are healthy
|
||
|
|
kubectl get application ingress-config -n argocd
|
||
|
|
kubectl get application homarr -n argocd
|
||
|
|
kubectl get application temporal -n argocd
|
||
|
|
|
||
|
|
# Check ingress-nginx duplicate removed
|
||
|
|
kubectl get application ingress-nginx -n argocd # Should be gone
|
||
|
|
|
||
|
|
# Verify resources deployed correctly
|
||
|
|
kubectl get certificate -n ingress-nginx riotpiao-com-tls
|
||
|
|
kubectl get ingress -A
|
||
|
|
kubectl get job -n dashboard homarr-fix-probes
|
||
|
|
kubectl get job -n temporal temporal-db-secret-sync
|
||
|
|
```
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## Rollback Procedure
|
||
|
|
|
||
|
|
If issues arise, revert specific commits:
|
||
|
|
|
||
|
|
```bash
|
||
|
|
# Identify commit
|
||
|
|
git log --oneline | grep consolidation
|
||
|
|
|
||
|
|
# Revert specific merge
|
||
|
|
git revert <commit-hash>
|
||
|
|
|
||
|
|
# Or restore old Applications from git history
|
||
|
|
git show <commit>:k8s/argocd/apps/00-substrate.yaml > temp.yaml
|
||
|
|
kubectl apply -f temp.yaml
|
||
|
|
```
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## Conclusion
|
||
|
|
|
||
|
|
Successfully consolidated 4 Applications while maintaining:
|
||
|
|
- ✅ Proper sync wave ordering
|
||
|
|
- ✅ Hook execution timing
|
||
|
|
- ✅ Resource namespace separation
|
||
|
|
- ✅ GitOps best practices
|
||
|
|
|
||
|
|
**Status:** Ready to commit and push to Forgejo for validation.
|