--- id: RAIL-EN-WP-0002 type: workplan title: "Declare Argo CD Core on railiance01 and bound its resources" domain: financials repo: railiance-enablement status: finished flavor: implementation owner: codex topic_slug: railiance created: "2026-09-21" updated: "2026-09-24" related: - ArchitectureBlueprint-5.6 - RPF-WP-0043 state_hub_workstream_id: "4230fe0e-127a-511f-8c5c-9cd883c23e5f" --- # RAIL-EN-WP-0002 — Argo CD Core on railiance01: declared state Argo CD Core v3.5.3 was installed on railiance01 on 2026-09-21 as a direct `ADMINISTER @ realm:kubernetes/railiance01`, `activation=APPROVED` by the founder, performed by the custodian session (`the-custodian/docs/kubernetes-change-gate-decision.md`). ArgoCD is an S4 concern (railiance-infra RAIL-HO-WP-0004 inventory), so its declared state lives here: `deploy/argocd/railiance01/`. ## T01 — Declare the install ```task id: RAIL-EN-WP-0002-T01 status: done priority: high state_hub_task_id: "0debb9c0-1567-5f22-820d-34ba62e1ddfb" ``` Pin manifest URL and sha256 (`PIN`), kustomization, install and rollback commands (`README.md`), read-only `make argocd-fetch|render|diff`. **Outcome (2026-09-21):** fetched manifest sha256 matches the pin (`1a87025d…c448`, 34 objects). Read-only `kubectl diff --server-side -n argocd` of the unpatched pinned manifest against railiance01: **no diff**. So the declared base matches live exactly. ## T02 — Apply resource requests and limits (live change, awaits founder) ```task id: RAIL-EN-WP-0002-T02 status: done priority: high state_hub_task_id: "8846994d-24cf-58e4-83ea-c8b23610bf22" ``` Upstream core sets no resources, so all four pods are BestEffort (verified 2026-09-21). `resources.yaml` declares: | Workload | Request cpu/mem | Limit cpu/mem | Idle use 2026-09-21 | |---|---|---|---| | application-controller (sts) | 50m / 256Mi | 1 / 1Gi | 2m / 23Mi | | repo-server (+ copyutil init 10m/32Mi, 100m/64Mi) | 25m / 128Mi | 1 / 1Gi | 1m / 19Mi | | applicationset-controller | 10m / 64Mi | 250m / 256Mi | 1m / 19Mi | | redis (+ secret-init init 10m/32Mi, 100m/64Mi) | 10m / 32Mi | 200m / 128Mi | 5m / 4Mi | Added requests: 95m CPU, 480Mi memory. Node requests before: 3320m (83%) CPU, 8856Mi (55%) memory, so this fits. Pods become Burstable. Idle use is with 0 Applications; revisit after phase B adoption. **Applied 2026-09-21** (founder go-ahead; custodian session, `ADMINISTER @ realm:kubernetes/railiance01`, `activation=APPROVED`): `argocd-diff` showed resources-only; 680m CPU free and 0 Pending beforehand; 34 objects server-side applied; all four rollouts complete; all four pods Burstable, Ready, 0 restarts; 0 Pending after. This was a **live change** (rolls all four pods). On the founder's go-ahead, mode `ADMINISTER @ realm:kubernetes/railiance01`, `activation=APPROVED`: ```bash make argocd-diff # expect only resources on the 4 workloads kubectl kustomize deploy/argocd/railiance01 \ | ssh railiance01 'kubectl apply --server-side -n argocd -f -' ssh railiance01 'kubectl -n argocd rollout status sts/argocd-application-controller deploy/argocd-repo-server deploy/argocd-applicationset-controller deploy/argocd-redis' ``` Rollback (back to upstream BestEffort): ```bash ssh railiance01 'kubectl apply --server-side -n argocd -f -' \ < deploy/argocd/railiance01/upstream/core-install.yaml ``` **Done when:** all four pods Ready with qosClass Burstable and `make argocd-diff` is empty. ## Not in this workplan Phase B is `RPF-WP-0044` in railiance-platform. Phase C (retire coulombcore's ArgoCD) stays with that later plan. Both need their own founder go-ahead. Once phase B exists, ArgoCD's own manifest should move under GitOps too. Both tasks here are done. The install is declared, and the resource bounds were applied on 2026-09-21.