first commit

This commit is contained in:
2026-08-09 19:52:19 -04:00
commit f12fb4d7a1
25 changed files with 597 additions and 0 deletions
+36
View File
@@ -0,0 +1,36 @@
# ArgoCD GitOps bootstrap
ArgoCD is installed once into the local cluster; everything after that is
declared through the root Application. The root uses the app-of-apps pattern:
it watches `argocd/apps/`, and each child Application owns one platform or
workload boundary.
## Bootstrap
1. Push this repository to GitHub and replace `REPLACE_WITH_GITHUB_OWNER` in
the Application manifests with the repository owner.
2. Create the local cluster from `local-quickstart/`.
3. Run:
```bash
kubectl create namespace argocd --dry-run=client -o yaml | kubectl apply -f -
kubectl apply --server-side --force-conflicts -n argocd -f https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml
kubectl -n argocd rollout status deployment/argocd-server --timeout=180s
kubectl apply -f argocd/app-of-apps.yaml
kubectl get applications -n argocd -w
```
The first command is idempotent. The official install manifest is fetched at
bootstrap time rather than vendored into this repository, keeping the repo
reviewable and making the ArgoCD version choice visible in the command.
For local UI access:
```bash
kubectl -n argocd port-forward svc/argocd-server 8081:443
kubectl -n argocd get secret argocd-initial-admin-secret \
-o jsonpath='{.data.password}' | base64 -d; echo
```
The initial admin secret is for local bootstrap only. A later hardening phase
should replace this with SSO/RBAC and remove the bootstrap credential.
+24
View File
@@ -0,0 +1,24 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: security-baseline-root
namespace: argocd
labels:
app.kubernetes.io/part-of: kubernetes-security-baseline
spec:
project: default
source:
# Replace the owner after publishing this repository.
repoURL: https://github.com/REPLACE_WITH_GITHUB_OWNER/kubernetes-security-baseline.git
targetRevision: main
path: argocd/apps
destination:
server: https://kubernetes.default.svc
namespace: argocd
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true
+29
View File
@@ -0,0 +1,29 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: falco
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "-1"
spec:
project: default
sources:
- repoURL: https://falcosecurity.github.io/charts
chart: falco
targetRevision: 4.21.1
helm:
valueFiles:
- $values/falco/falco-values.yaml
- repoURL: https://github.com/REPLACE_WITH_GITHUB_OWNER/kubernetes-security-baseline.git
targetRevision: main
ref: values
destination:
server: https://kubernetes.default.svc
namespace: falco
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true
+23
View File
@@ -0,0 +1,23 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: kyverno
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "-2"
spec:
project: default
source:
repoURL: https://kyverno.github.io/kyverno/
chart: kyverno
targetRevision: 3.3.7
destination:
server: https://kubernetes.default.svc
namespace: kyverno
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true
+24
View File
@@ -0,0 +1,24 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: security-policies
namespace: argocd
annotations:
# Policies wait for Kyverno's CRDs/controller to exist.
argocd.argoproj.io/sync-wave: "0"
spec:
project: default
source:
repoURL: https://github.com/REPLACE_WITH_GITHUB_OWNER/kubernetes-security-baseline.git
targetRevision: main
path: policies/kyverno
destination:
server: https://kubernetes.default.svc
namespace: security-baseline
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true
+23
View File
@@ -0,0 +1,23 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: security-test-workloads
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "1"
spec:
project: default
source:
repoURL: https://github.com/REPLACE_WITH_GITHUB_OWNER/kubernetes-security-baseline.git
targetRevision: main
path: test-workloads
destination:
server: https://kubernetes.default.svc
namespace: security-baseline
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true