Declare scoped activity-core ArgoCD adoption
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
parent
c9bf8c90c9
commit
f3f2b82d0c
4 changed files with 97 additions and 0 deletions
|
|
@ -0,0 +1,23 @@
|
|||
# ACTIVITY-WP-0041 / RPF-WP-0048: founder-authorized adoption, 2026-09-27.
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: Application
|
||||
metadata:
|
||||
name: activity-core
|
||||
namespace: argocd
|
||||
labels:
|
||||
app.kubernetes.io/part-of: railiance-gitops
|
||||
spec:
|
||||
project: activity-core
|
||||
source:
|
||||
repoURL: https://forgejo.coulomb.social/coulomb/activity-core.git
|
||||
targetRevision: c12a8fbcfbd0624e195a0183f8b7ca5ce2bc07d5
|
||||
path: k8s/gitops
|
||||
destination:
|
||||
server: https://kubernetes.default.svc
|
||||
namespace: activity-core
|
||||
syncPolicy:
|
||||
syncOptions:
|
||||
- CreateNamespace=false
|
||||
- ApplyOutOfSyncOnly=true
|
||||
- PruneLast=true
|
||||
- FailOnSharedResource=true
|
||||
23
argocd/railiance01/bootstrap/03-activity-core-project.yaml
Normal file
23
argocd/railiance01/bootstrap/03-activity-core-project.yaml
Normal file
|
|
@ -0,0 +1,23 @@
|
|||
# ACTIVITY-WP-0041 / RPF-WP-0048: explicit namespace and resource scope.
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: AppProject
|
||||
metadata:
|
||||
name: activity-core
|
||||
namespace: argocd
|
||||
spec:
|
||||
description: Activity-core application runtime; excludes jobs, custody and infrastructure.
|
||||
sourceRepos:
|
||||
- https://forgejo.coulomb.social/coulomb/activity-core.git
|
||||
destinations:
|
||||
- server: https://kubernetes.default.svc
|
||||
namespace: activity-core
|
||||
clusterResourceWhitelist: []
|
||||
namespaceResourceWhitelist:
|
||||
- group: ""
|
||||
kind: ConfigMap
|
||||
- group: ""
|
||||
kind: Service
|
||||
- group: apps
|
||||
kind: Deployment
|
||||
orphanedResources:
|
||||
warn: false
|
||||
|
|
@ -8,4 +8,5 @@ resources:
|
|||
- 00-railiance-bootstrap-project.yaml
|
||||
- 01-railiance-tenants-project.yaml
|
||||
- 02-railiance-platform-addons-project.yaml
|
||||
- 03-activity-core-project.yaml
|
||||
- 10-railiance-apps-root.application.yaml
|
||||
|
|
|
|||
50
workplans/RPF-WP-0048-activity-core-gitops-adoption.md
Normal file
50
workplans/RPF-WP-0048-activity-core-gitops-adoption.md
Normal file
|
|
@ -0,0 +1,50 @@
|
|||
---
|
||||
id: RPF-WP-0048
|
||||
type: workplan
|
||||
title: "Adopt activity-core application runtime into railiance01 GitOps"
|
||||
domain: financials
|
||||
repo: railiance-platform
|
||||
status: active
|
||||
owner: codex
|
||||
topic_slug: railiance
|
||||
created: "2026-09-27"
|
||||
updated: "2026-09-27"
|
||||
---
|
||||
|
||||
User authorized implementation of ACTIVITY-WP-0041 on 2026-09-27, after the
|
||||
frontend-patterns reporting exception. This explicitly authorizes this adoption;
|
||||
it does not widen the earlier one-time exception to unrelated workloads.
|
||||
Authority: CONSTRUCT @ activity-core and railiance-platform;
|
||||
ADMINISTER @ realm:kubernetes/railiance01 for the scoped bootstrap;
|
||||
activation=APPROVED. Existing 24-hour observation requirement remains in force.
|
||||
|
||||
## Bootstrap a namespace-scoped project and adopt nine runtime resources
|
||||
|
||||
```task
|
||||
id: RPF-WP-0048-T01
|
||||
status: progress
|
||||
priority: high
|
||||
```
|
||||
|
||||
New project permits only activity-core source, activity-core destination, and
|
||||
ConfigMap/Service/Deployment kinds. No secrets, Jobs, databases, queues, Temporal,
|
||||
llm-connect, edge relay, storage or cluster-scoped resources enter this Application.
|
||||
Application source is activity-core k8s/gitops at a pinned reviewed commit; no
|
||||
finalizer, automated sync or pruning initially. Root sync must name this child
|
||||
only; unrelated pending applications must not be changed. Verify ArgoCD's diff,
|
||||
health, resource inventory, schedules and original deployment generations.
|
||||
|
||||
## Observe adoption and enforce bounded promotion readiness
|
||||
|
||||
```task
|
||||
id: RPF-WP-0048-T02
|
||||
status: wait
|
||||
priority: high
|
||||
```
|
||||
|
||||
Keep automated sync off for at least 24 hours after successful adoption. Record
|
||||
start and earliest eligibility in evidence. ACTIVITY-WP-0041 owns image publication,
|
||||
source validation and the promotion/rollback guard. Root-wide automation is outside
|
||||
this workplan. No unattended merge credential or release executor is assumed just
|
||||
because the Application exists. Confirm the scoped identity and checks before
|
||||
activating bounded routine promotion. Destructive pruning remains disabled.
|
||||
Loading…
Add table
Add a link
Reference in a new issue