apiVersion: argoproj.io/v1alpha1 kind: Application metadata: name: forge namespace: argocd annotations: argocd.argoproj.io/sync-wave: "0" spec: project: default source: repoURL: https://forgejo.forge.riotpiao.com/rock/deploy.git targetRevision: main path: forge destination: server: https://kubernetes.default.svc namespace: forge # NO syncPolicy.automated — manual sync required. # Forgejo is what CI uses to push commits; auto-sync would let a bad CI commit # break the very system CI depends on. Approve syncs manually in the Argo CD UI.