cluster-bootstrap only brings up the minimal layer (argocd, metallb,
envoy-gateway, storage). App/platform services now live in a separate
cluster-platform repo, applied after this one finishes.
Prior test only checked PVC reaches Bound. Add a pod that writes a
file, then a second pod re-mounting the same PVC to confirm data
survives pod delete/recreate (proves NFS-backed, not emptyDir).
nfs-subdir-external-provisioner chart v4.0.18 has no extraObjects
values key - it was silently ignored, so nfs-retain never actually
existed. Only nfs-delete (native storageClass.* key) is real.
Updated README expected output to match.
Drop .env/envsubst/bake-hash-into-values.yaml flow entirely. Chart's
configs.secret block is removed for good, so the rendered manifest
never declares admin.password/admin.passwordMtime. Password hash is
set once directly on the live argocd-secret via kubectl patch, and
survives every self-heal sync since ArgoCD never owns those fields.
- remove server.httproute from argocd values.yaml: helm install failed
since Gateway API CRDs (installed by envoy-gateway, wave 2) don't
exist yet; HTTPRoute is already applied manually in Phase 6
- add bootstrap-app.yaml as the Git-committed root/seed Application,
replacing ad-hoc UI creation (GitOps anti-pattern: apps not stored
in Git can't be recreated)