k8s/ci-cd: add forgejo gitops and argocd deployment

- Forgejo git forge + OCI registry
- Argo CD pull-based GitOps
- Private CA TLS (self-signed 10-year cert)
- Machine credentials scoped to repositories
This commit is contained in:
Story Crater Bot
2026-08-18 15:08:00 -07:00
parent 0af06b1239
commit a3f261f548
14 changed files with 738 additions and 0 deletions
@@ -0,0 +1,40 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: api
namespace: api
spec:
replicas: 1
selector:
matchLabels:
app: api
template:
metadata:
labels:
app: api
spec:
containers:
- name: api
# CI bumps this tag on every push to main (ci.yml step "bump deploy repo")
image: forgejo.riotpiao.homelab.com/rock/api:latest
ports:
- containerPort: 8080
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: 500m
memory: 512Mi
readinessProbe:
httpGet:
path: /healthz
port: 8080
initialDelaySeconds: 5
periodSeconds: 10
livenessProbe:
httpGet:
path: /healthz
port: 8080
initialDelaySeconds: 15
periodSeconds: 30
@@ -0,0 +1,12 @@
apiVersion: v1
kind: Service
metadata:
name: api
namespace: api
spec:
selector:
app: api
ports:
- name: http
port: 80
targetPort: 8080
@@ -0,0 +1,22 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: api
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "10"
spec:
project: default
source:
repoURL: https://forgejo.forge.riotpiao.homelab.com/rock/deploy.git
targetRevision: main
path: api
destination:
server: https://kubernetes.default.svc
namespace: api
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true
@@ -0,0 +1,19 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: argocd
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "0"
spec:
project: default
source:
repoURL: https://forgejo.forge.riotpiao.homelab.com/rock/deploy.git
targetRevision: main
path: argocd
destination:
server: https://kubernetes.default.svc
namespace: argocd
# NO syncPolicy.automated — manual sync required.
# Argo CD managing itself auto-synced is a footgun: a misconfigured commit could
# take down the CD system before anyone can intervene. Approve manually.
@@ -0,0 +1,19 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: forge
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "0"
spec:
project: default
source:
repoURL: https://forgejo.forge.riotpiao.homelab.com/rock/deploy.git
targetRevision: main
path: forge
destination:
server: https://kubernetes.default.svc
namespace: forge
# NO syncPolicy.automated — manual sync required.
# Forgejo is what CI uses to push commits; auto-sync would let a bad CI commit
# break the very system CI depends on. Approve syncs manually in the Argo CD UI.