Declare railiance01 ArgoCD bootstrap on its own path, automated sync off (RPF-WP-0044-T01).

Founder's Option A: argocd/railiance01/bootstrap (3 AppProjects, root with no
automated block, tenants whitelist + postgresql.cnpg.io/Cluster), root path
argocd/railiance01/applications (README placeholder, renders zero children),
pinned child drafts in argocd/railiance01/drafts (issue-core repointed to
rapp-issue-core manifests), rapp-issue-core repository template; issue-core
template marked obsolete. argocd/bootstrap and argocd/applications untouched
(coulombcore). Nothing applied.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
This commit is contained in:
codex 2026-09-21 19:04:15 +02:00
parent 538a3087fe
commit c3ebd6dddc
12 changed files with 322 additions and 0 deletions

View file

@ -0,0 +1,22 @@
apiVersion: argoproj.io/v1alpha1
kind: AppProject
metadata:
name: railiance-bootstrap
namespace: argocd
labels:
app.kubernetes.io/part-of: railiance-gitops
railiance-platform/component: gitops
spec:
description: Platform-owned ArgoCD bootstrap project for Railiance app-of-apps.
sourceRepos:
- https://forgejo.coulomb.social/coulomb/railiance-platform.git
destinations:
- server: https://kubernetes.default.svc
namespace: argocd
clusterResourceWhitelist: []
namespaceResourceWhitelist:
- group: argoproj.io
kind: Application
orphanedResources:
warn: true

View file

@ -0,0 +1,56 @@
apiVersion: argoproj.io/v1alpha1
kind: AppProject
metadata:
name: railiance-tenants
namespace: argocd
labels:
app.kubernetes.io/part-of: railiance-gitops
railiance-platform/component: gitops
spec:
description: Guardrails for Railiance tenant applications deployed by ArgoCD.
sourceRepos:
- https://forgejo.coulomb.social/coulomb/*.git
# Emergency rollback only (T12 Option A through 2026-08-07)
- https://gitea.coulomb.social/coulomb/*.git
destinations:
- server: https://kubernetes.default.svc
namespace: "*"
clusterResourceWhitelist:
- group: ""
kind: Namespace
namespaceResourceWhitelist:
- group: ""
kind: ConfigMap
- group: ""
kind: PersistentVolumeClaim
- group: ""
kind: Secret
- group: ""
kind: Service
- group: ""
kind: ServiceAccount
- group: apps
kind: Deployment
- group: apps
kind: StatefulSet
- group: autoscaling
kind: HorizontalPodAutoscaler
- group: batch
kind: CronJob
- group: batch
kind: Job
- group: external-secrets.io
kind: ExternalSecret
- group: postgresql.cnpg.io
kind: Cluster
- group: networking.k8s.io
kind: Ingress
- group: networking.k8s.io
kind: NetworkPolicy
- group: traefik.io
kind: IngressRoute
- group: traefik.io
kind: Middleware
orphanedResources:
warn: true

View file

@ -0,0 +1,48 @@
apiVersion: argoproj.io/v1alpha1
kind: AppProject
metadata:
name: railiance-platform-addons
namespace: argocd
labels:
app.kubernetes.io/part-of: railiance-gitops
railiance-platform/component: gitops
spec:
description: Platform-owned cluster add-ons required by tenant workloads.
sourceRepos:
- https://forgejo.coulomb.social/coulomb/railiance-platform.git
- https://charts.external-secrets.io
destinations:
- server: https://kubernetes.default.svc
namespace: "*"
clusterResourceWhitelist:
- group: ""
kind: Namespace
- group: apiextensions.k8s.io
kind: CustomResourceDefinition
- group: admissionregistration.k8s.io
kind: MutatingWebhookConfiguration
- group: admissionregistration.k8s.io
kind: ValidatingWebhookConfiguration
- group: rbac.authorization.k8s.io
kind: ClusterRole
- group: rbac.authorization.k8s.io
kind: ClusterRoleBinding
- group: external-secrets.io
kind: ClusterSecretStore
namespaceResourceWhitelist:
- group: ""
kind: ConfigMap
- group: ""
kind: Secret
- group: ""
kind: Service
- group: ""
kind: ServiceAccount
- group: apps
kind: Deployment
- group: rbac.authorization.k8s.io
kind: Role
- group: rbac.authorization.k8s.io
kind: RoleBinding
orphanedResources:
warn: true

View file

@ -0,0 +1,27 @@
# railiance01 root app (RPF-WP-0044, founder's Option A, 2026-09-21).
# No `automated` block: the root syncs only when synced by hand, with the
# revision pinned in the sync operation. T07 restores automated sync after
# T03-T06 are proven. coulombcore keeps argocd/bootstrap -> argocd/applications
# until phase C; nothing here is read by coulombcore.
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: railiance-apps-root
namespace: argocd
labels:
app.kubernetes.io/part-of: railiance-gitops
railiance-platform/component: gitops
spec:
project: railiance-bootstrap
source:
repoURL: https://forgejo.coulomb.social/coulomb/railiance-platform.git
targetRevision: main
path: argocd/railiance01/applications
destination:
server: https://kubernetes.default.svc
namespace: argocd
syncPolicy:
syncOptions:
- CreateNamespace=false
- ApplyOutOfSyncOnly=true
- PruneLast=true

View file

@ -0,0 +1,11 @@
# railiance01 ArgoCD bootstrap, applied by hand (RPF-WP-0044-T02).
# Separate from argocd/bootstrap/, which is coulombcore's and stays unchanged
# until phase C. Do not point `make argocd-bootstrap-deploy` at the old path on
# railiance01: its root declares automated prune + self-heal.
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- 00-railiance-bootstrap-project.yaml
- 01-railiance-tenants-project.yaml
- 02-railiance-platform-addons-project.yaml
- 10-railiance-apps-root.application.yaml