refactor(gitops): establish platform ownership boundaries

This commit is contained in:
donghyeon-ka
2026-07-26 01:34:29 +09:00
parent 293ee6fc97
commit a6f6c663e0
121 changed files with 2801 additions and 1204 deletions
@@ -0,0 +1,8 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- platform-addons.yaml
- platform-services.yaml
- systems.yaml
- workloads.yaml
@@ -0,0 +1,50 @@
apiVersion: argoproj.io/v1alpha1
kind: AppProject
metadata:
name: platform-addons
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "-10"
argocd.argoproj.io/sync-options: Prune=confirm,Delete=confirm
finalizers:
- resources-finalizer.argocd.argoproj.io
spec:
description: Cluster-scoped controllers installed from approved Helm repositories
sourceRepos:
- https://bitnami.github.io/sealed-secrets
- https://helm.releases.hashicorp.com
destinations:
- namespace: kube-system
server: https://kubernetes.default.svc
- namespace: vault
server: https://kubernetes.default.svc
clusterResourceWhitelist:
- group: ""
kind: Namespace
- group: apiextensions.k8s.io
kind: CustomResourceDefinition
- group: rbac.authorization.k8s.io
kind: ClusterRole
- group: rbac.authorization.k8s.io
kind: ClusterRoleBinding
- group: admissionregistration.k8s.io
kind: MutatingWebhookConfiguration
namespaceResourceWhitelist:
- group: ""
kind: ConfigMap
- group: ""
kind: Secret
- group: ""
kind: Service
- group: ""
kind: ServiceAccount
- group: apps
kind: Deployment
- group: policy
kind: PodDisruptionBudget
- group: rbac.authorization.k8s.io
kind: Role
- group: rbac.authorization.k8s.io
kind: RoleBinding
orphanedResources:
warn: true
@@ -0,0 +1,37 @@
apiVersion: argoproj.io/v1alpha1
kind: AppProject
metadata:
name: platform-services
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "-10"
argocd.argoproj.io/sync-options: Prune=confirm,Delete=confirm
finalizers:
- resources-finalizer.argocd.argoproj.io
spec:
description: Shared services owned by this standalone reference platform
sourceRepos:
- https://git.learn.hyeonworks.com/donghyeon.kang/project-gitops
destinations:
- namespace: vault
server: https://kubernetes.default.svc
clusterResourceWhitelist:
- group: ""
kind: Namespace
- group: rbac.authorization.k8s.io
kind: ClusterRoleBinding
namespaceResourceWhitelist:
- group: ""
kind: ConfigMap
- group: ""
kind: PersistentVolumeClaim
- group: ""
kind: Service
- group: ""
kind: ServiceAccount
- group: apps
kind: Deployment
- group: networking.k8s.io
kind: NetworkPolicy
orphanedResources:
warn: true
@@ -0,0 +1,39 @@
apiVersion: argoproj.io/v1alpha1
kind: AppProject
metadata:
name: systems
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "-10"
argocd.argoproj.io/sync-options: Prune=confirm,Delete=confirm
finalizers:
- resources-finalizer.argocd.argoproj.io
spec:
description: Backing systems dedicated to an example product boundary
sourceRepos:
- https://git.learn.hyeonworks.com/donghyeon.kang/project-gitops
destinations:
- namespace: auth-system-dev
server: https://kubernetes.default.svc
clusterResourceWhitelist:
- group: ""
kind: Namespace
namespaceResourceWhitelist:
- group: ""
kind: ConfigMap
- group: ""
kind: Service
- group: ""
kind: ServiceAccount
- group: apps
kind: Deployment
- group: apps
kind: StatefulSet
- group: batch
kind: Job
- group: networking.k8s.io
kind: Ingress
- group: networking.k8s.io
kind: NetworkPolicy
orphanedResources:
warn: true
@@ -0,0 +1,41 @@
apiVersion: argoproj.io/v1alpha1
kind: AppProject
metadata:
name: workloads
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "-10"
argocd.argoproj.io/sync-options: Prune=confirm,Delete=confirm
finalizers:
- resources-finalizer.argocd.argoproj.io
spec:
description: First-party application workloads
sourceRepos:
- https://git.learn.hyeonworks.com/donghyeon.kang/project-gitops
destinations:
- namespace: auth-dev
server: https://kubernetes.default.svc
- namespace: api-dev
server: https://kubernetes.default.svc
clusterResourceWhitelist:
- group: ""
kind: Namespace
namespaceResourceWhitelist:
- group: ""
kind: ConfigMap
- group: ""
kind: Service
- group: ""
kind: ServiceAccount
- group: bitnami.com
kind: SealedSecret
- group: apps
kind: Deployment
- group: batch
kind: Job
- group: networking.k8s.io
kind: Ingress
- group: networking.k8s.io
kind: NetworkPolicy
orphanedResources:
warn: true