diff --git a/k8s/argocd/poimen-workflows.yaml b/k8s/argocd/poimen-workflows.yaml new file mode 100644 index 0000000..a86bfcb --- /dev/null +++ b/k8s/argocd/poimen-workflows.yaml @@ -0,0 +1,29 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application +metadata: + name: poimen-workflows + namespace: argocd + labels: + app.kubernetes.io/name: poimen-workflows + app.kubernetes.io/component: orchestrator +spec: + project: poimen + source: + repoURL: https://forgejo.riotpiao.com/rock/poimen-workflows.git + targetRevision: main + path: k8s + plugin: + name: kustomize + destination: + server: https://kubernetes.default.svc + namespace: poimen + syncPolicy: + automated: + prune: true + selfHeal: true + retry: + limit: 5 + backoff: + duration: 5s + factor: 2 + maxDuration: 3m diff --git a/k8s/argocd/root.yaml b/k8s/argocd/root.yaml index 21c7595..3b6ee07 100644 --- a/k8s/argocd/root.yaml +++ b/k8s/argocd/root.yaml @@ -4,8 +4,11 @@ metadata: name: poimen namespace: argocd spec: + # Explicit allowlist, not the 'rock/*' wildcard -- only repos with an actual + # Application under this project belong here. Add a line here when (and only + # when) a new Application is registered. sourceRepos: - - 'https://forgejo.riotpiao.com/rock/*' + - 'https://forgejo.riotpiao.com/rock/poimen-workflows.git' destinations: - namespace: 'poimen' server: https://kubernetes.default.svc