first commit
This commit is contained in:
@@ -0,0 +1,36 @@
|
||||
# ArgoCD GitOps bootstrap
|
||||
|
||||
ArgoCD is installed once into the local cluster; everything after that is
|
||||
declared through the root Application. The root uses the app-of-apps pattern:
|
||||
it watches `argocd/apps/`, and each child Application owns one platform or
|
||||
workload boundary.
|
||||
|
||||
## Bootstrap
|
||||
|
||||
1. Push this repository to GitHub and replace `REPLACE_WITH_GITHUB_OWNER` in
|
||||
the Application manifests with the repository owner.
|
||||
2. Create the local cluster from `local-quickstart/`.
|
||||
3. Run:
|
||||
|
||||
```bash
|
||||
kubectl create namespace argocd --dry-run=client -o yaml | kubectl apply -f -
|
||||
kubectl apply --server-side --force-conflicts -n argocd -f https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml
|
||||
kubectl -n argocd rollout status deployment/argocd-server --timeout=180s
|
||||
kubectl apply -f argocd/app-of-apps.yaml
|
||||
kubectl get applications -n argocd -w
|
||||
```
|
||||
|
||||
The first command is idempotent. The official install manifest is fetched at
|
||||
bootstrap time rather than vendored into this repository, keeping the repo
|
||||
reviewable and making the ArgoCD version choice visible in the command.
|
||||
|
||||
For local UI access:
|
||||
|
||||
```bash
|
||||
kubectl -n argocd port-forward svc/argocd-server 8081:443
|
||||
kubectl -n argocd get secret argocd-initial-admin-secret \
|
||||
-o jsonpath='{.data.password}' | base64 -d; echo
|
||||
```
|
||||
|
||||
The initial admin secret is for local bootstrap only. A later hardening phase
|
||||
should replace this with SSO/RBAC and remove the bootstrap credential.
|
||||
@@ -0,0 +1,24 @@
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: Application
|
||||
metadata:
|
||||
name: security-baseline-root
|
||||
namespace: argocd
|
||||
labels:
|
||||
app.kubernetes.io/part-of: kubernetes-security-baseline
|
||||
spec:
|
||||
project: default
|
||||
source:
|
||||
# Replace the owner after publishing this repository.
|
||||
repoURL: https://github.com/REPLACE_WITH_GITHUB_OWNER/kubernetes-security-baseline.git
|
||||
targetRevision: main
|
||||
path: argocd/apps
|
||||
destination:
|
||||
server: https://kubernetes.default.svc
|
||||
namespace: argocd
|
||||
syncPolicy:
|
||||
automated:
|
||||
prune: true
|
||||
selfHeal: true
|
||||
syncOptions:
|
||||
- CreateNamespace=true
|
||||
|
||||
@@ -0,0 +1,29 @@
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: Application
|
||||
metadata:
|
||||
name: falco
|
||||
namespace: argocd
|
||||
annotations:
|
||||
argocd.argoproj.io/sync-wave: "-1"
|
||||
spec:
|
||||
project: default
|
||||
sources:
|
||||
- repoURL: https://falcosecurity.github.io/charts
|
||||
chart: falco
|
||||
targetRevision: 4.21.1
|
||||
helm:
|
||||
valueFiles:
|
||||
- $values/falco/falco-values.yaml
|
||||
- repoURL: https://github.com/REPLACE_WITH_GITHUB_OWNER/kubernetes-security-baseline.git
|
||||
targetRevision: main
|
||||
ref: values
|
||||
destination:
|
||||
server: https://kubernetes.default.svc
|
||||
namespace: falco
|
||||
syncPolicy:
|
||||
automated:
|
||||
prune: true
|
||||
selfHeal: true
|
||||
syncOptions:
|
||||
- CreateNamespace=true
|
||||
|
||||
@@ -0,0 +1,23 @@
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: Application
|
||||
metadata:
|
||||
name: kyverno
|
||||
namespace: argocd
|
||||
annotations:
|
||||
argocd.argoproj.io/sync-wave: "-2"
|
||||
spec:
|
||||
project: default
|
||||
source:
|
||||
repoURL: https://kyverno.github.io/kyverno/
|
||||
chart: kyverno
|
||||
targetRevision: 3.3.7
|
||||
destination:
|
||||
server: https://kubernetes.default.svc
|
||||
namespace: kyverno
|
||||
syncPolicy:
|
||||
automated:
|
||||
prune: true
|
||||
selfHeal: true
|
||||
syncOptions:
|
||||
- CreateNamespace=true
|
||||
|
||||
@@ -0,0 +1,24 @@
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: Application
|
||||
metadata:
|
||||
name: security-policies
|
||||
namespace: argocd
|
||||
annotations:
|
||||
# Policies wait for Kyverno's CRDs/controller to exist.
|
||||
argocd.argoproj.io/sync-wave: "0"
|
||||
spec:
|
||||
project: default
|
||||
source:
|
||||
repoURL: https://github.com/REPLACE_WITH_GITHUB_OWNER/kubernetes-security-baseline.git
|
||||
targetRevision: main
|
||||
path: policies/kyverno
|
||||
destination:
|
||||
server: https://kubernetes.default.svc
|
||||
namespace: security-baseline
|
||||
syncPolicy:
|
||||
automated:
|
||||
prune: true
|
||||
selfHeal: true
|
||||
syncOptions:
|
||||
- CreateNamespace=true
|
||||
|
||||
@@ -0,0 +1,23 @@
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: Application
|
||||
metadata:
|
||||
name: security-test-workloads
|
||||
namespace: argocd
|
||||
annotations:
|
||||
argocd.argoproj.io/sync-wave: "1"
|
||||
spec:
|
||||
project: default
|
||||
source:
|
||||
repoURL: https://github.com/REPLACE_WITH_GITHUB_OWNER/kubernetes-security-baseline.git
|
||||
targetRevision: main
|
||||
path: test-workloads
|
||||
destination:
|
||||
server: https://kubernetes.default.svc
|
||||
namespace: security-baseline
|
||||
syncPolicy:
|
||||
automated:
|
||||
prune: true
|
||||
selfHeal: true
|
||||
syncOptions:
|
||||
- CreateNamespace=true
|
||||
|
||||
Reference in New Issue
Block a user