Files
project-gitops/CHANGELOG.md
T
2026-08-28 17:24:26 +09:00

73 lines
4.1 KiB
Markdown

# Changelog
## 2026-07-26
- Adopted the `k8s-template` lifecycle layout: bootstrap under
`bootstrap/gitops`, Terraform under `infrastructure`, all Kubernetes desired
state under `gitops`, automation under `scripts`, and ADRs under
`docs/decisions`.
- Made `gitops/clusters/dev-k3s` the root Application source while preserving
permission-scoped ApplicationSets and their staged `autoSync` gates.
- Co-located reusable Terraform modules in `infrastructure/components`,
backend examples with each live root, and Vault ACLs with their owning
Terraform state.
- Added the template catalogs, `_template` directories, examples, security
checks, and common validation ahead of project-specific validation.
- Clarified that this repository is an independent GitOps reference lab, not a
shared production platform or an application source monorepo.
- Reclassified Kubernetes ownership as `platform`, `systems` and `workloads`;
moved the Project Auth PostgreSQL/Keycloak boundary to
`systems/auth-system`.
- Replaced generic cluster `manifests` with ownership-aligned
`clusters/dev-k3s/overlays`.
- Moved the Argo control-plane inventory to
`platform/control-plane/argocd` and separated permission-scoped AppProjects
for addons, shared services, systems and workloads.
- Added a bootstrap-only `gitops-control-plane` AppProject so the root no
longer reconciles through Argo CD's unrestricted `default` project.
- Replaced repeated child Application definitions with strict
list-generated ApplicationSets and explicit `autoSync` bootstrap gates.
- Renamed the Project Auth backing-system namespace to `auth-system-dev` and
aligned service DNS, NetworkPolicy and ConfigMap ownership.
- Changed Vault KV ownership from legacy `dev/platform` paths to
`dev/systems/auth-system` and `dev/workloads/auth-server` paths.
- Split the broad `vault-core` ownership into `vault-foundation` and
`vault-workloads`, retaining `vault-database` as a third isolated state.
- Documented delegated Terraform identities, stage-by-stage bootstrap and
non-destructive state/path migration procedures.
- Kept GHCR as the image artifact boundary and made immutable digests the
promotion target; existing short commit tags remain until a registry-verified
promotion PR replaces them.
- Performed repository-only refactoring and static validation; no Kubernetes,
Vault, Argo CD, registry or remote Terraform backend was mutated.
## 2026-07-25
- Established the internal Gitea repository as the single GitOps source.
- Replaced staged Argo roots with one bootstrap seed and one cluster-owned
root Application.
- Reorganized the repository around `clusters/dev-k3s`, environment-neutral
`platform`/`workloads` bases and separate `iac/terraform`.
- Corrected the Sealed Secrets Helm repository and added controller resources
and key renewal configuration.
- Removed incomplete production skeletons; production remains unsupported.
- Changed application promotion to a Gitea pull request carrying an immutable
OCI digest and removed direct writes to `main`.
- Pinned Vault, PostgreSQL, Keycloak, Vault Injector and Sealed Secrets images
to verified multi-architecture digests.
- Removed routine `kubectl apply`, port-forward orchestration and reusable
Vault operator-token scripts.
- Added a guarded, dev-only Vault init/unseal/root-revoke entrypoint.
- Fixed auth migration and Keycloak sync Job lifecycle and ordering.
- Removed selective sync from Applications containing Sync hooks.
- Enabled ConfigMap hash rollouts and projected Vault authentication tokens.
- Removed the same-cluster Transit Vault and its credential rotation cycle.
- Consolidated Terraform into `vault-core` and `vault-database` remote states
with write-only/ephemeral credential inputs.
- Removed tracked Terraform providers and backend metadata.
- Moved machine-consumed Vault policies out of runbooks and narrowed routine
automation permissions.
- Recorded Gateway API first and deferred Istio ambient adoption criteria.
- Reduced shell entrypoints from 18 files/1,205 lines to 3 files/300 lines.
- Split current documentation from archived historical material.