k8s/ci-cd: add forgejo gitops and argocd deployment

- Forgejo git forge + OCI registry
- Argo CD pull-based GitOps
- Private CA TLS (self-signed 10-year cert)
- Machine credentials scoped to repositories
This commit is contained in:
Story Crater Bot
2026-08-18 15:08:00 -07:00
parent 0af06b1239
commit a3f261f548
14 changed files with 738 additions and 0 deletions
@@ -0,0 +1,19 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: argocd
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "0"
spec:
project: default
source:
repoURL: https://forgejo.forge.riotpiao.homelab.com/rock/deploy.git
targetRevision: main
path: argocd
destination:
server: https://kubernetes.default.svc
namespace: argocd
# NO syncPolicy.automated — manual sync required.
# Argo CD managing itself auto-synced is a footgun: a misconfigured commit could
# take down the CD system before anyone can intervene. Approve manually.