Commit Graph
9 Commits
Author SHA1 Message Date
Story Crater Bot 27907387f6 docs: remove outdated docs describing the retired core/talos CLI workflow 2026-08-27 13:11:47 -07:00
Story Crater Bot 0fe3d25936 fix(ci): make the hardcoded-secret scan blocking and close the .gitignore/.sops.yaml gaps that let a plaintext deploy key through — also untracks tfplan binaries and skills-lock.json 2026-08-18 15:08:04 -07:00
Story Crater Bot 54bfb5ade6 feat(gitops): migrate domain to riotpiao.com, add CNPG + Forgejo HA on Redis/Postgres, wire ArgoCD apps — enables cluster rebuild after etcd wipe and unblocks the git-source chicken-egg via standalone Helm-source Applications 2026-08-18 15:08:02 -07:00
Story Crater Bot 491e88e493 feat(ci,iac): Consolidate Forgejo CI workflows and add Talos Terraform IaC
Consolidate three separate Forgejo Actions (argocd-sync, security-scan, validate-k8s) into single cluster-ci workflow for cleaner CI/CD pipeline with proper job sequencing and reduced auth overhead.

Add Terraform configuration for Talos cluster machine configs:
- Provider setup for Talos
- Centralized variables for CP and worker configs
- Template-based config generation for controlplane.yaml and worker-*.yaml
- Sensitive data separated in terraform.tfvars (gitignored)
- Local state tracking for infrastructure
2026-08-18 15:08:01 -07:00
Story Crater Bot e48580adb9 fix(ci): Forgejo Actions auth + kustomize cleanup in validate-k8s workflow 2026-08-18 15:08:01 -07:00
Story Crater Bot 563f720d09 refactor: retire Terraform, migrate to pure ArgoCD GitOps + CI validation 2026-08-18 15:08:01 -07:00
Story Crater Bot adbad3d97e fix(ci): use direct in-cluster Kubernetes auth for CI runner — drop kubeconfig file dependency 2026-08-18 15:08:01 -07:00
Story Crater Bot df9d9845c0 fix(ci): correct core-cli auth + S3 backend config for CI runner (iterate) 2026-08-18 15:08:01 -07:00
Story Crater Bot f16f439feb feat: Terraform CI via Forgejo Actions + MinIO S3 state backend
- ArgoCD manages MinIO (phase 0), Terraform manages infrastructure
- Runner workflow: pulls state from S3, validates, plans, applies
- 34 resources imported to state, S3 backend operational
- Fixed AppProject repos, S3 endpoint deprecation, runner package manager
2026-08-18 15:08:01 -07:00