refactor: one self-contained folder per platform service

Each platform/apps/<service>/ now holds its own application.yaml
(multi-source: chart + values + raw-manifest extras), values.yaml, and
any extra manifests (HTTPRoute, RBAC, ClusterSecretStore) together,
replacing the split apps/*.yaml + manifests/*/ + separate *-config
Application pattern.

Root platform-app.yaml now recurses platform/apps/*/application.yaml
only. Extras get a resource-level sync-wave (1) so they still land
after their service's Helm chart within the same Application sync.

Also adds an HTTPRoute for vault (vault.fireflylab.local) - exposed
same as every other service here, accepted as LAN-only exposure.
This commit is contained in:
2026-07-29 23:56:50 +07:00
parent a1cff1dfb9
commit 7a665bdf9d
30 changed files with 133 additions and 169 deletions
+34
View File
@@ -0,0 +1,34 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: vault
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "0"
spec:
project: default
sources:
- repoURL: https://helm.releases.hashicorp.com
chart: vault
targetRevision: "0.30.0" # TODO: verify latest via `helm search repo hashicorp/vault --versions`
helm:
valueFiles:
- $values/platform/apps/vault/values.yaml
- repoURL: https://gitea.fireflylab.cc/duynguyen/cluster-platform.git
targetRevision: main
ref: values
- repoURL: https://gitea.fireflylab.cc/duynguyen/cluster-platform.git
targetRevision: main
path: platform/apps/vault
directory:
exclude: "{application.yaml,values.yaml}"
destination:
server: https://kubernetes.default.svc
namespace: vault
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true
- SkipDryRunOnMissingResource=true
+22
View File
@@ -0,0 +1,22 @@
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: vault
namespace: vault
annotations:
argocd.argoproj.io/sync-wave: "1"
spec:
parentRefs:
- name: envoy-gateway
namespace: envoy-gateway-system
hostnames:
- "vault.fireflylab.local"
rules:
- matches:
- path:
type: PathPrefix
value: /
backendRefs:
# verify with: kubectl get svc -n vault (UI served on same port as API when ui.enabled)
- name: vault
port: 8200
+15
View File
@@ -0,0 +1,15 @@
server:
dataStorage:
enabled: true
storageClass: nfs-delete
size: 10Gi
standalone:
enabled: true
ha:
enabled: false
ui:
enabled: true
injector:
enabled: true