162 lines
3.7 KiB
YAML
162 lines
3.7 KiB
YAML
# ArgoCD Helm Values — Bootstrap Mode (SOPS plugin added post-bootstrap)
|
|
# Chart: https://github.com/argoproj/argo-helm
|
|
|
|
global:
|
|
domain: argocd.riotpiao.com
|
|
|
|
# Server configuration
|
|
server:
|
|
ingress:
|
|
enabled: true
|
|
ingressClassName: nginx
|
|
annotations:
|
|
cert-manager.io/cluster-issuer: letsencrypt-prod
|
|
nginx.ingress.kubernetes.io/ssl-passthrough: "true"
|
|
nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
|
|
hosts:
|
|
- argocd.riotpiao.com
|
|
tls:
|
|
- secretName: argocd-server-tls
|
|
hosts:
|
|
- argocd.riotpiao.com
|
|
|
|
# Allow insecure mode (terminate TLS at ingress)
|
|
extraArgs:
|
|
- --insecure
|
|
|
|
resources:
|
|
requests:
|
|
cpu: 100m
|
|
memory: 256Mi
|
|
limits:
|
|
cpu: 500m
|
|
memory: 1Gi
|
|
|
|
# Tolerations for control-plane
|
|
tolerations:
|
|
- key: node-role.kubernetes.io/control-plane
|
|
operator: Exists
|
|
effect: NoSchedule
|
|
|
|
# Repo server configuration
|
|
repoServer:
|
|
resources:
|
|
requests:
|
|
cpu: 100m
|
|
memory: 256Mi
|
|
limits:
|
|
cpu: 1000m
|
|
memory: 1Gi
|
|
|
|
# Tolerations for control-plane
|
|
tolerations:
|
|
- key: node-role.kubernetes.io/control-plane
|
|
operator: Exists
|
|
effect: NoSchedule
|
|
|
|
# Fetch sops binary into shared emptyDir (runs as root; main containers can't write /usr/local/bin)
|
|
initContainers:
|
|
- name: install-sops
|
|
image: alpine:3.20
|
|
command: [sh, -c]
|
|
args:
|
|
- |
|
|
wget -qO /sops-bin/sops https://github.com/getsops/sops/releases/download/v3.9.3/sops-v3.9.3.linux.amd64
|
|
chmod +x /sops-bin/sops
|
|
volumeMounts:
|
|
- mountPath: /sops-bin
|
|
name: sops-bin
|
|
|
|
# SOPS CMP sidecar (decrypts *.enc.yaml via argocd-cmp-cm ConfigMap plugin)
|
|
extraContainers:
|
|
- name: sops-secrets-v1
|
|
command: [/var/run/argocd/argocd-cmp-server]
|
|
image: quay.io/argoproj/argocd:v3.4.5
|
|
env:
|
|
- name: SOPS_AGE_KEY_FILE
|
|
value: /sops-age/key.txt
|
|
- name: PATH
|
|
value: /sops-bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
|
|
volumeMounts:
|
|
- mountPath: /var/run/argocd
|
|
name: var-files
|
|
- mountPath: /home/argocd/cmp-server/plugins
|
|
name: plugins
|
|
- mountPath: /tmp
|
|
name: cmp-tmp
|
|
- mountPath: /home/argocd/cmp-server/config/plugin.yaml
|
|
subPath: sops-secrets-v1.0.yaml
|
|
name: argocd-cmp-cm
|
|
- mountPath: /sops-age
|
|
name: sops-age
|
|
readOnly: true
|
|
- mountPath: /sops-bin
|
|
name: sops-bin
|
|
readOnly: true
|
|
securityContext:
|
|
runAsNonRoot: true
|
|
runAsUser: 999
|
|
|
|
volumes:
|
|
- name: sops-bin
|
|
emptyDir: {}
|
|
- name: cmp-tmp
|
|
emptyDir: {}
|
|
- name: argocd-cmp-cm
|
|
configMap:
|
|
name: argocd-cmp-cm
|
|
- name: sops-age
|
|
secret:
|
|
secretName: sops-age
|
|
|
|
# Controller configuration
|
|
controller:
|
|
resources:
|
|
requests:
|
|
cpu: 200m
|
|
memory: 512Mi
|
|
limits:
|
|
cpu: 1000m
|
|
memory: 2Gi
|
|
|
|
# Tolerations for control-plane
|
|
tolerations:
|
|
- key: node-role.kubernetes.io/control-plane
|
|
operator: Exists
|
|
effect: NoSchedule
|
|
|
|
# Application controller configuration
|
|
applicationSet:
|
|
enabled: true
|
|
|
|
# Notifications (optional, for Slack/Discord alerts)
|
|
notifications:
|
|
enabled: false
|
|
|
|
# Redis for caching
|
|
redis:
|
|
enabled: true
|
|
resources:
|
|
requests:
|
|
cpu: 50m
|
|
memory: 64Mi
|
|
limits:
|
|
cpu: 200m
|
|
memory: 256Mi
|
|
|
|
# ArgoCD configuration
|
|
configs:
|
|
# Default project allows all repos
|
|
cm:
|
|
admin.enabled: "true"
|
|
application.instanceLabelKey: argocd.argoproj.io/instance
|
|
|
|
params:
|
|
server.insecure: true
|
|
|
|
# RBAC (allow admin full access)
|
|
rbac:
|
|
policy.default: role:readonly
|
|
policy.csv: |
|
|
g, admin, role:admin
|