Files
homelab/k8s/argocd/apps/00-substrate.yaml
T
rock 2038253d48 feat(security): add Kyverno for image scanning and Pod security policies
- Install Kyverno policy engine for admission control
- Add ClusterPolicies:
  * Disallow 'latest' tags (require explicit versions)
  * Restrict to trusted registries (docker.io, ghcr.io, quay.io, etc.)
  * Require non-root containers
  * Drop all Linux capabilities by default
  * Require securityContext on all containers
  * Require read-only root filesystem (audit only)
  * Require resource requests/limits (prevent starvation)
- All policies in audit mode initially (failurePolicy: ignore)
- Ready to graduate to enforce after testing
- Fixes: missing image scanning from security audit
2026-08-31 11:43:04 -07:00

213 lines
5.9 KiB
YAML

# Wave 0/1 — cluster substrate: cert-manager, ingress-nginx, reloader, and the
# Let's Encrypt issuers + wildcard cert. Previously installed by Terraform; now
# owned by app-of-apps (Pure GitOps). Controllers at wave 0; the ClusterIssuers
# and wildcard Certificate at wave 1 so cert-manager CRDs exist first.
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: cert-manager
namespace: argocd
finalizers:
- resources-finalizer.argocd.argoproj.io
annotations:
argocd.argoproj.io/sync-wave: "0"
spec:
project: homelab
revisionHistoryLimit: 3
sources:
- repoURL: https://charts.jetstack.io
chart: cert-manager
targetRevision: "v1.21.0"
helm:
valueFiles:
- $values/k8s/bootstrap/cert-manager/cert-manager-values.yaml
- repoURL: https://forgejo.riotpiao.com/rock/homelab.git
targetRevision: main
ref: values
destination:
server: https://kubernetes.default.svc
namespace: cert-manager
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true
- ServerSideApply=true
# ingress-nginx removed: duplicate of ingress-nginx-bootstrap
# The bootstrap version (k8s/bootstrap-local/06-ingress-nginx.yaml) is kept
# to break the circular dependency (ArgoCD needs Forgejo domain access)
---
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: reloader
namespace: argocd
finalizers:
- resources-finalizer.argocd.argoproj.io
annotations:
argocd.argoproj.io/sync-wave: "0"
spec:
project: homelab
revisionHistoryLimit: 3
source:
repoURL: https://stakater.github.io/stakater-charts
chart: reloader
targetRevision: "2.2.14"
helm:
values: |
reloader:
# Watch every workload — no per-Deployment reloader annotation needed
# (several charts, e.g. homarr, don't expose Deployment-level
# annotations). reloadOnCreate rolls a workload when a Secret/ConfigMap
# it references is first CREATED, not only updated — so ksops-delivered
# secrets landing after a pod started auto-restart it.
autoReloadAll: true
reloadOnCreate: true
deployment:
tolerations:
- key: node-role.kubernetes.io/control-plane
operator: Exists
effect: NoSchedule
destination:
server: https://kubernetes.default.svc
namespace: reloader
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true
---
# Wave 1 — LE ClusterIssuers + wildcard cert (needs cert-manager CRDs from wave 0).
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: cert-manager-issuers
namespace: argocd
finalizers:
- resources-finalizer.argocd.argoproj.io
annotations:
argocd.argoproj.io/sync-wave: "1"
spec:
project: homelab
revisionHistoryLimit: 3
source:
repoURL: https://forgejo.riotpiao.com/rock/homelab.git
targetRevision: main
# A real kustomization.yaml (resources: the 3 issuer/CA files) renders these
# deterministically. The previous directory.include with bare filenames
# rendered EMPTY — ArgoCD's include glob never matched — so this app silently
# tracked 0 resources; its ConfigMaps/Issuers only existed from bootstrap
# kubectl apply, and an automated prune wiped them.
path: k8s/bootstrap/cert-manager
destination:
server: https://kubernetes.default.svc
namespace: cert-manager
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true
---
# Consolidated: wildcard-cert + homelab-ingress → ingress-config
# Manages both the wildcard TLS certificate and all Ingress rules.
# Certificate must exist before Ingresses (wave 1), but both are in same directory.
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: ingress-config
namespace: argocd
finalizers:
- resources-finalizer.argocd.argoproj.io
annotations:
argocd.argoproj.io/sync-wave: "1"
spec:
project: homelab
revisionHistoryLimit: 3
source:
repoURL: https://forgejo.riotpiao.com/rock/homelab.git
targetRevision: main
path: k8s/bootstrap/ingress
destination:
server: https://kubernetes.default.svc
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true
---
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: cluster-maintenance
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "0"
spec:
project: homelab
source:
repoURL: https://forgejo.riotpiao.com/rock/homelab.git
targetRevision: main
path: k8s/infra/cluster-maintenance
destination:
server: https://kubernetes.default.svc
namespace: kube-system
syncPolicy:
automated:
prune: true
selfHeal: true
---
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: kyverno
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "0"
spec:
project: homelab
source:
repoURL: https://kyverno.github.io/kyverno/
chart: kyverno
targetRevision: "1.14.0"
helm:
valueFiles:
- $values/k8s/bootstrap/kyverno/kyverno-values.yaml
sources:
- repoURL: https://forgejo.riotpiao.com/rock/homelab.git
targetRevision: main
ref: values
destination:
server: https://kubernetes.default.svc
namespace: kyverno
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true
---
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: kyverno-policies
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "0"
spec:
project: homelab
source:
repoURL: https://forgejo.riotpiao.com/rock/homelab.git
targetRevision: main
path: k8s/bootstrap/kyverno
destination:
server: https://kubernetes.default.svc
namespace: kyverno
syncPolicy:
automated:
prune: true
selfHeal: true