k8s/ci-cd: add forgejo gitops and argocd deployment

- Forgejo git forge + OCI registry
- Argo CD pull-based GitOps
- Private CA TLS (self-signed 10-year cert)
- Machine credentials scoped to repositories
This commit is contained in:
Story Crater Bot
2026-07-11 19:17:34 -07:00
parent 63d7256b9e
commit 4ab596196e
14 changed files with 738 additions and 0 deletions
@@ -0,0 +1,31 @@
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: {{ .Release.Name }}-egress
namespace: {{ .Release.Namespace }}
spec:
podSelector:
matchLabels:
app: {{ .Release.Name }}
policyTypes: [Egress]
egress:
# Forgejo — same cicd namespace (git push, registry push/pull)
- to:
- podSelector: {}
# CoreDNS
- to:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: kube-system
ports:
- protocol: UDP
port: 53
- protocol: TCP
port: 53
# Internet (action deps, base images) — never LAN or pod network
- to:
- ipBlock:
cidr: 0.0.0.0/0
except:
- 192.168.1.0/24
- 10.244.0.0/16