Declare Argo CD Core v3.5.3 on railiance01 and its resource bounds
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Has been cancelled

Pinned core-install.yaml (sha256 1a87025d...c448) with a kustomize
resources patch for the four workloads. The unpatched pin diffs clean
against live; the resources patch is declared only, and its apply waits
on the founder in RAIL-EN-WP-0002-T02. SCOPE.md no longer says ArgoCD is
absent from railiance01.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
This commit is contained in:
tegwick 2026-09-21 18:41:24 +02:00
parent f91a5298cb
commit 70295b6b2b
8 changed files with 284 additions and 13 deletions

View file

@ -0,0 +1,4 @@
# Pinned upstream manifest for Argo CD Core on railiance01.
ARGOCD_VERSION := v3.5.3
ARGOCD_MANIFEST_URL := https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.3/manifests/core-install.yaml
ARGOCD_MANIFEST_SHA256 := 1a87025d8eb2eae621653fd312fb9ca51df1b4b3b6992a030e3a9ef38e45c448

View file

@ -0,0 +1,82 @@
# Argo CD Core on railiance01 — declared state
Owner: `railiance-enablement` (S4). ArgoCD is an S4 concern per
railiance-infra (RAIL-HO-WP-0004 service inventory). Settled as
ArchitectureBlueprint §5.6 option 1, **adopt properly** (founder,
`GOVERN @ estate`, 2026-09-21).
| Item | Value |
|---|---|
| Distribution | upstream Argo CD **Core** (headless: no API server, UI or Dex) |
| Version | `v3.5.3` |
| Manifest | `core-install.yaml` at tag `v3.5.3` (URL in `PIN`) |
| sha256 | `1a87025d8eb2eae621653fd312fb9ca51df1b4b3b6992a030e3a9ef38e45c448` |
| Images | `quay.io/argoproj/argocd:v3.5.3`, `public.ecr.aws/docker/library/redis:8.2.3-alpine` |
| Namespace | `argocd` (created 2026-09-21T13:55:29Z) |
| Objects | 34, server-side applied, field manager `kubectl` |
| Applications / AppProjects | none (nothing adopted) |
| Listeners | no LoadBalancer or NodePort Service (ADR-0008) |
The live install was a direct `ADMINISTER @ realm:kubernetes/railiance01`,
`activation=APPROVED` by the founder, performed by the custodian session on
2026-09-21 (record: `the-custodian/docs/kubernetes-change-gate-decision.md`).
This directory is its declared state. Evidence: `target-audited` for the
install itself; this repository adds `external-audited` evidence from here on.
## Files
- `PIN` — pinned manifest URL, version, sha256 (included by the Makefile).
- `kustomization.yaml` — pinned upstream plus `resources.yaml`.
- `resources.yaml` — requests and limits for the four workloads.
**Declared, not yet applied** (RAIL-EN-WP-0002-T02).
- `upstream/` — fetched manifest, gitignored; `make argocd-fetch` verifies it.
## Read-only commands
```bash
make argocd-fetch # download + sha256 check
make argocd-render # render declared state locally
make argocd-diff # server-side diff against railiance01 (read-only)
```
## Install (as performed 2026-09-21, pinned upstream, no resources patch)
```bash
make argocd-fetch
ssh railiance01 'kubectl create namespace argocd'
ssh railiance01 'kubectl apply --server-side --dry-run=server -n argocd -f -' \
< deploy/argocd/railiance01/upstream/core-install.yaml
ssh railiance01 'kubectl apply --server-side -n argocd -f -' \
< deploy/argocd/railiance01/upstream/core-install.yaml
```
## Apply the declared state (includes resources) — needs founder go-ahead
```bash
make argocd-diff # expect: only resources on the 4 workloads
kubectl kustomize deploy/argocd/railiance01 \
| ssh railiance01 'kubectl apply --server-side -n argocd -f -'
ssh railiance01 'kubectl -n argocd rollout status sts/argocd-application-controller deploy/argocd-repo-server deploy/argocd-applicationset-controller deploy/argocd-redis'
```
## Rollback
Resources only (return to upstream BestEffort):
```bash
ssh railiance01 'kubectl apply --server-side -n argocd -f -' \
< deploy/argocd/railiance01/upstream/core-install.yaml
```
Whole install (nothing else depends on it while there are 0 Applications):
```bash
ssh railiance01 'kubectl delete namespace argocd'
ssh railiance01 'kubectl delete crd applications.argoproj.io applicationsets.argoproj.io appprojects.argoproj.io'
```
The upstream core manifest also creates one ClusterRole and one
ClusterRoleBinding (`argocd-application-controller`). For a clean cluster,
delete everything it declares first:
`ssh railiance01 'kubectl delete -n argocd -f -' < deploy/argocd/railiance01/upstream/core-install.yaml`,
then the namespace.

View file

@ -0,0 +1,10 @@
# Declared state of Argo CD Core on railiance01 (namespace argocd).
# Upstream manifest is fetched and sha256-verified by `make argocd-fetch`
# into upstream/ (gitignored); see PIN and README.md. Like upstream, the
# render carries no namespace: apply it with `-n argocd`.
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- upstream/core-install.yaml
patches:
- path: resources.yaml

View file

@ -0,0 +1,68 @@
# Requests and limits for the four Argo CD Core workloads. Upstream core sets
# none, so the live pods are BestEffort. Idle use on 2026-09-21 (kubectl top,
# 0 Applications): controller 2m/23Mi, applicationset 1m/19Mi,
# repo-server 1m/19Mi, redis 5m/4Mi. Requests sit above idle to leave room for
# phase B adoption; memory limits bound the pods; CPU limits are generous.
# Total added requests: 95m CPU, 480Mi memory (init containers do not add).
# NOT YET APPLIED: see RAIL-EN-WP-0002-T02.
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: argocd-application-controller
spec:
template:
spec:
containers:
- name: argocd-application-controller
resources:
requests: {cpu: 50m, memory: 256Mi}
limits: {cpu: 1000m, memory: 1Gi}
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: argocd-repo-server
spec:
template:
spec:
initContainers:
- name: copyutil
resources:
requests: {cpu: 10m, memory: 32Mi}
limits: {cpu: 100m, memory: 64Mi}
containers:
- name: argocd-repo-server
resources:
requests: {cpu: 25m, memory: 128Mi}
limits: {cpu: 1000m, memory: 1Gi}
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: argocd-applicationset-controller
spec:
template:
spec:
containers:
- name: argocd-applicationset-controller
resources:
requests: {cpu: 10m, memory: 64Mi}
limits: {cpu: 250m, memory: 256Mi}
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: argocd-redis
spec:
template:
spec:
initContainers:
- name: secret-init
resources:
requests: {cpu: 10m, memory: 32Mi}
limits: {cpu: 100m, memory: 64Mi}
containers:
- name: redis
resources:
requests: {cpu: 10m, memory: 32Mi}
limits: {cpu: 200m, memory: 128Mi}