feat(phase4): ArgoCD-driven Terraform apply via PostSync Hook Job

- Create Phase 4 ArgoCD Application (terraform-apply)
- PostSync Hook Job runs: terraform init && terraform apply -auto-approve
- ServiceAccount + ClusterRole for cluster-admin RBAC
- S3 credentials encrypted with SOPS (terraform-s3-secrets.enc.yaml)
- Pre-commit hook blocks local 'terraform apply' — all changes via git push
- True IaC: modify terraform/*.tf → git push → ArgoCD applies automatically
This commit is contained in:
Story Crater Bot
2026-07-15 16:39:27 -07:00
parent 842360288d
commit e71c7ad37e
5 changed files with 152 additions and 3 deletions
+26
View File
@@ -0,0 +1,26 @@
# Phase 4 — IaC (Terraform) — infrastructure-as-code via Hook Job
# ArgoCD-driven terraform apply. All changes via git push.
---
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: terraform-apply
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "4"
spec:
project: homelab
sources:
- repoURL: https://forgejo.riotpiao.homelab.com/riotpiao.com/homelab.git
targetRevision: main
path: k8s/hooks/phase4
destination:
server: https://kubernetes.default.svc
namespace: argocd
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true