railiance-platform/argocd/applications
codex adb5a7249c Record the ArgoCD lane as the production change path and plan policy-nexus onboarding.
Founder decision 2026-09-21 (the-custodian/docs/kubernetes-change-gate-decision.md).
RPF-WP-0043 plans, and does not perform, the policy-nexus adoption; it waits on
the founder's go-ahead. Records that this repository cannot show ArgoCD
reconciling on railiance01.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 14:36:08 +02:00
..
external-secrets.application.yaml Add ESO OpenBao GitOps add-ons 2026-06-25 20:08:36 +02:00
issue-core.application.yaml Point issue-core ArgoCD Application at Forgejo Git source 2026-07-08 15:21:00 +02:00
openbao-secretstore.application.yaml Repoint ArgoCD GitOps to Forgejo (RAIL-HO-WP-0005 T11) 2026-07-08 15:35:28 +02:00
README.md Record the ArgoCD lane as the production change path and plan policy-nexus onboarding. 2026-09-21 14:36:08 +02:00
target-revenue.application.yaml Add ArgoCD Application for target-revenue Trust Service 2026-08-05 16:41:00 +02:00

Railiance ArgoCD Tenant Applications

This directory is synced by the railiance-apps-root ArgoCD Application.

Tenant teams author a thin ArgoCD Application manifest against the contract in docs/argocd-gitops.md. Platform review merges that manifest here after checking namespace, repository, sync policy, and secret-delivery shape.

Workload manifests stay in the owning tenant repo. The default source path for tenant workloads is:

k8s/railiance/

Since the founder's decision of 2026-09-21, this directory is the change path for production-approved workloads (see docs/argocd-gitops.md § Production Change Path). A merge here is a live production change. Adopting a workload that is already running (for example rapp-policy-nexus, RPF-WP-0043) needs the founder's go-ahead and a diff first. Do not add an Application for a running workload directly.

Do not commit Kubernetes Secret values, ArgoCD repository credentials, OpenBao tokens, deploy keys, or API keys here.