252 lines
7.8 KiB
YAML
252 lines
7.8 KiB
YAML
# Wave 1 — MinIO (operator + tenant), Longhorn policy, Prometheus stack.
|
|
# Helm charts pull from public repos; values come from the git repo via a
|
|
# second "ref: values" source (ArgoCD multi-source pattern).
|
|
apiVersion: argoproj.io/v1alpha1
|
|
kind: Application
|
|
metadata:
|
|
name: minio-operator
|
|
namespace: argocd
|
|
annotations:
|
|
argocd.argoproj.io/sync-wave: "1"
|
|
spec:
|
|
project: homelab
|
|
sources:
|
|
- repoURL: https://operator.min.io/
|
|
chart: operator
|
|
targetRevision: "5.0.18"
|
|
helm:
|
|
valueFiles:
|
|
- $values/k8s/infra/minio/minio-operator-values.yaml
|
|
- repoURL: https://forgejo.riotpiao.com/rock/homelab.git
|
|
targetRevision: main
|
|
ref: values
|
|
destination:
|
|
server: https://kubernetes.default.svc
|
|
namespace: storage
|
|
syncPolicy:
|
|
automated:
|
|
prune: true
|
|
selfHeal: true
|
|
syncOptions:
|
|
- CreateNamespace=true
|
|
---
|
|
# Tenant + buckets + replication are raw CRs (MinIO Tenant CRD from operator).
|
|
apiVersion: argoproj.io/v1alpha1
|
|
kind: Application
|
|
metadata:
|
|
name: minio-tenant
|
|
namespace: argocd
|
|
annotations:
|
|
argocd.argoproj.io/sync-wave: "1"
|
|
spec:
|
|
project: homelab
|
|
source:
|
|
repoURL: https://forgejo.riotpiao.com/rock/homelab.git
|
|
targetRevision: main
|
|
path: k8s/infra/minio
|
|
destination:
|
|
server: https://kubernetes.default.svc
|
|
namespace: storage
|
|
syncPolicy:
|
|
automated:
|
|
prune: true
|
|
selfHeal: true
|
|
syncOptions:
|
|
- CreateNamespace=true
|
|
---
|
|
# Longhorn itself is substrate (bootstrap-installed); this app manages only its
|
|
# ServiceMonitor / policy manifests.
|
|
apiVersion: argoproj.io/v1alpha1
|
|
kind: Application
|
|
metadata:
|
|
name: longhorn-config
|
|
namespace: argocd
|
|
annotations:
|
|
argocd.argoproj.io/sync-wave: "1"
|
|
spec:
|
|
project: homelab
|
|
source:
|
|
repoURL: https://forgejo.riotpiao.com/rock/homelab.git
|
|
targetRevision: main
|
|
path: k8s/infra/longhorn
|
|
destination:
|
|
server: https://kubernetes.default.svc
|
|
namespace: longhorn-system
|
|
# Longhorn writes disk state back into its own Node CRs — the disk key it
|
|
# generates, storageReserved, diskType, evictionRequested. Git declares only
|
|
# allowScheduling; without this the controller's writes read as drift forever.
|
|
ignoreDifferences:
|
|
- group: longhorn.io
|
|
kind: Node
|
|
jsonPointers:
|
|
- /spec/disks
|
|
syncPolicy:
|
|
automated:
|
|
prune: true
|
|
selfHeal: true
|
|
---
|
|
apiVersion: argoproj.io/v1alpha1
|
|
kind: Application
|
|
metadata:
|
|
name: prometheus
|
|
namespace: argocd
|
|
annotations:
|
|
argocd.argoproj.io/sync-wave: "1"
|
|
spec:
|
|
project: homelab
|
|
sources:
|
|
- repoURL: https://prometheus-community.github.io/helm-charts
|
|
chart: kube-prometheus-stack
|
|
targetRevision: "*"
|
|
helm:
|
|
skipCrds: true
|
|
valueFiles:
|
|
- $values/k8s/infra/monitoring/prometheus-values.yaml
|
|
- repoURL: https://forgejo.riotpiao.com/rock/homelab.git
|
|
targetRevision: main
|
|
ref: values
|
|
destination:
|
|
server: https://kubernetes.default.svc
|
|
namespace: monitoring
|
|
syncPolicy:
|
|
managedNamespaceMetadata:
|
|
# node-exporter needs hostNetwork/hostPID/hostPath/hostPort; blocked by
|
|
# default baseline PSS (DaemonSet created 0 pods, Prometheus STS stuck).
|
|
labels:
|
|
pod-security.kubernetes.io/enforce: privileged
|
|
automated:
|
|
prune: true
|
|
selfHeal: true
|
|
syncOptions:
|
|
- CreateNamespace=true
|
|
# ServerSideApply removed — it conflicts with managedNamespaceMetadata's
|
|
# forced namespace apply ("--force cannot be used with --server-side").
|
|
# helm.skipCrds: true above stops ArgoCD from ever managing the CRDs
|
|
# through this Application (previously it kept re-patching them via
|
|
# client-side apply and hitting etcd's 262144-byte annotation limit on
|
|
# kubectl.kubernetes.io/last-applied-configuration, permanently failing
|
|
# sync). CRDs are applied once via the separate prometheus-crds
|
|
# Application below, which uses ServerSideApply=true (no namespace-
|
|
# metadata conflict since CRDs are cluster-scoped).
|
|
---
|
|
# CRDs only, extracted to plain YAML (`helm show crds kube-prometheus-stack`)
|
|
# and committed to git under k8s/infra/monitoring/crds/, applied via Server-
|
|
# Side Apply to avoid the etcd 262144-byte last-applied-configuration
|
|
# annotation limit that client-side apply hits on these very large CRDs
|
|
# (prometheuses, alertmanagers, scrapeconfigs, etc). A plain git path source
|
|
# (not a remote Helm source) is used deliberately so ArgoCD applies exactly
|
|
# these 8 CRD manifests and nothing else — no ambiguity about what "CRDs only"
|
|
# means from a Helm chart. Split out from the main `prometheus` Application
|
|
# (helm.skipCrds: true there) because ServerSideApply conflicts with that
|
|
# app's managedNamespaceMetadata.
|
|
# NOTE: bump k8s/infra/monitoring/crds/kube-prometheus-stack-crds.yaml
|
|
# whenever the kube-prometheus-stack chart version changes materially
|
|
# (`helm show crds prometheus-community/kube-prometheus-stack > ...`).
|
|
apiVersion: argoproj.io/v1alpha1
|
|
kind: Application
|
|
metadata:
|
|
name: prometheus-crds
|
|
namespace: argocd
|
|
annotations:
|
|
argocd.argoproj.io/sync-wave: "0"
|
|
spec:
|
|
project: homelab
|
|
source:
|
|
repoURL: https://forgejo.riotpiao.com/rock/homelab.git
|
|
targetRevision: main
|
|
path: k8s/infra/monitoring/crds
|
|
destination:
|
|
server: https://kubernetes.default.svc
|
|
namespace: monitoring
|
|
syncPolicy:
|
|
automated:
|
|
prune: true
|
|
selfHeal: true
|
|
syncOptions:
|
|
- CreateNamespace=true
|
|
- ServerSideApply=true
|
|
---
|
|
# Cluster monitoring config: custom PrometheusRules (per-app namespaces),
|
|
# ServiceMonitors (monitoring ns), and Grafana dashboard ConfigMaps (logging ns,
|
|
# grafana sidecar-discovered). Single source = k8s/infra/monitoring (one
|
|
# kustomization, no namespace transformer so per-app rule namespaces are kept).
|
|
# Wave 2: after prometheus-operator CRDs (wave 0) + stack (wave 1) and grafana
|
|
# (wave 2, logging). ServerSideApply avoids the etcd last-applied annotation
|
|
# limit on the large dashboard ConfigMap JSON.
|
|
apiVersion: argoproj.io/v1alpha1
|
|
kind: Application
|
|
metadata:
|
|
name: monitoring-config
|
|
namespace: argocd
|
|
annotations:
|
|
argocd.argoproj.io/sync-wave: "2"
|
|
spec:
|
|
project: homelab
|
|
source:
|
|
repoURL: https://forgejo.riotpiao.com/rock/homelab.git
|
|
targetRevision: main
|
|
path: k8s/infra/monitoring
|
|
destination:
|
|
server: https://kubernetes.default.svc
|
|
namespace: monitoring
|
|
syncPolicy:
|
|
automated:
|
|
prune: true
|
|
selfHeal: true
|
|
syncOptions:
|
|
- CreateNamespace=true
|
|
- ServerSideApply=true
|
|
---
|
|
apiVersion: argoproj.io/v1alpha1
|
|
kind: Application
|
|
metadata:
|
|
name: blackbox-exporter
|
|
namespace: argocd
|
|
annotations:
|
|
argocd.argoproj.io/sync-wave: "1"
|
|
spec:
|
|
project: homelab
|
|
sources:
|
|
- repoURL: https://prometheus-community.github.io/helm-charts
|
|
chart: prometheus-blackbox-exporter
|
|
targetRevision: "~11"
|
|
helm:
|
|
valueFiles:
|
|
- $values/k8s/infra/monitoring/blackbox-exporter-values.yaml
|
|
- repoURL: https://forgejo.riotpiao.com/rock/homelab.git
|
|
targetRevision: main
|
|
ref: values
|
|
destination:
|
|
server: https://kubernetes.default.svc
|
|
namespace: monitoring
|
|
syncPolicy:
|
|
automated:
|
|
prune: true
|
|
selfHeal: true
|
|
---
|
|
# Distributed tracing: Tempo + OpenTelemetry Collector.
|
|
# Receives traces from instrumented services, stores in local volume (72h retention).
|
|
# Grafana datasource auto-configured, service graph + latency dashboards included.
|
|
apiVersion: argoproj.io/v1alpha1
|
|
kind: Application
|
|
metadata:
|
|
name: tracing
|
|
namespace: argocd
|
|
annotations:
|
|
argocd.argoproj.io/sync-wave: "1"
|
|
spec:
|
|
project: homelab
|
|
source:
|
|
repoURL: https://forgejo.riotpiao.com/rock/homelab.git
|
|
targetRevision: main
|
|
path: k8s/infra/tracing
|
|
destination:
|
|
server: https://kubernetes.default.svc
|
|
namespace: tracing
|
|
syncPolicy:
|
|
automated:
|
|
prune: true
|
|
selfHeal: true
|
|
syncOptions:
|
|
- CreateNamespace=true
|