# ArgoCD GitOps bootstrap ArgoCD is installed once into the local cluster; everything after that is declared through the root Application. The root uses the app-of-apps pattern: it watches `argocd/apps/`, and each child Application owns one platform or workload boundary. ## Bootstrap 1. Push this repository to GitHub and replace `REPLACE_WITH_GITHUB_OWNER` in the Application manifests with the repository owner. 2. Create the local cluster from `local-quickstart/`. 3. Run: ```bash kubectl create namespace argocd --dry-run=client -o yaml | kubectl apply -f - kubectl apply --server-side --force-conflicts -n argocd -f https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml kubectl -n argocd rollout status deployment/argocd-server --timeout=180s kubectl apply -f argocd/app-of-apps.yaml kubectl get applications -n argocd -w ``` The first command is idempotent. The official install manifest is fetched at bootstrap time rather than vendored into this repository, keeping the repo reviewable and making the ArgoCD version choice visible in the command. For local UI access: ```bash kubectl -n argocd port-forward svc/argocd-server 8081:443 kubectl -n argocd get secret argocd-initial-admin-secret \ -o jsonpath='{.data.password}' | base64 -d; echo ``` The initial admin secret is for local bootstrap only. A later hardening phase should replace this with SSO/RBAC and remove the bootstrap credential.