Compare commits

...

2 commits

Author SHA1 Message Date
4be877e419
update argo files
Signed-off-by: gwg313 <gwg313@pm.me>
2026-05-23 22:12:10 -04:00
d3da92bbb8
add cicd exclude to resource limits
Signed-off-by: gwg313 <gwg313@pm.me>
2026-05-23 22:09:35 -04:00
9 changed files with 8 additions and 14 deletions

View file

@ -1,5 +1,7 @@
harbor: harbor:
externalURL: https://registry.gwg313.xyz externalURL: https://registry.gwg313.xyz
updateStrategy:
type: Recreate
nginx: nginx:
replicas: 0 replicas: 0
@ -21,8 +23,6 @@ harbor:
memory: 128Mi memory: 128Mi
core: core:
updateStrategy:
type: Recreate
resources: resources:
requests: requests:
cpu: 100m cpu: 100m
@ -32,8 +32,6 @@ harbor:
memory: 512Mi memory: 512Mi
jobservice: jobservice:
updateStrategy:
type: Recreate
resources: resources:
requests: requests:
cpu: 100m cpu: 100m

View file

@ -4,3 +4,4 @@ kind: Kustomization
resources: resources:
- https://storage.googleapis.com/tekton-releases/pipeline/latest/release.yaml - https://storage.googleapis.com/tekton-releases/pipeline/latest/release.yaml
- https://storage.googleapis.com/tekton-releases/dashboard/latest/release.yaml - https://storage.googleapis.com/tekton-releases/dashboard/latest/release.yaml
- https://raw.githubusercontent.com/openshift-pipelines/pipelines-as-code/stable/release.k8s.yaml

View file

@ -20,5 +20,3 @@ spec:
selfHeal: true selfHeal: true
syncOptions: syncOptions:
- CreateNamespace=true - CreateNamespace=true
- ServerSideApply=true
- SkipDryRunOnMissingResource=true

View file

@ -20,4 +20,3 @@ spec:
selfHeal: true selfHeal: true
syncOptions: syncOptions:
- CreateNamespace=true - CreateNamespace=true
- ServerSideApply=true

View file

@ -18,8 +18,3 @@ spec:
automated: automated:
prune: true prune: true
selfHeal: true selfHeal: true
syncOptions:
- CreateNamespace=false
- ServerSideApply=true
- Replace=true # <-- Policies have immutable fields so this helps deal with updates
- Force=true

View file

@ -20,5 +20,4 @@ spec:
selfHeal: true selfHeal: true
syncOptions: syncOptions:
- CreateNamespace=true - CreateNamespace=true
- ServerSideApply=true
- SkipDryRunOnMissingResource=true - SkipDryRunOnMissingResource=true

View file

@ -20,4 +20,3 @@ spec:
selfHeal: true selfHeal: true
syncOptions: syncOptions:
- CreateNamespace=true - CreateNamespace=true
- ServerSideApply=true

View file

@ -5,6 +5,8 @@ metadata:
annotations: annotations:
policies.kyverno.io/title: Inject Namespace Baseline CNP policies.kyverno.io/title: Inject Namespace Baseline CNP
policies.kyverno.io/description: Automatically provisions a local default-deny + DNS egress CNP inside new application namespaces. policies.kyverno.io/description: Automatically provisions a local default-deny + DNS egress CNP inside new application namespaces.
argocd.argoproj.io/sync-options: Force=true,Replace=true
spec: spec:
background: true background: true
rules: rules:
@ -32,6 +34,7 @@ spec:
- monitoring - monitoring
- tekton-pipelines-resolvers - tekton-pipelines-resolvers
- tekton-pipelines - tekton-pipelines
- pipelines-as-code
generate: generate:
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy

View file

@ -36,6 +36,8 @@ spec:
- monitoring - monitoring
- tekton-pipelines-resolvers - tekton-pipelines-resolvers
- tekton-pipelines - tekton-pipelines
- pipelines-as-code
- cicd
validate: validate:
message: "Resource discipline violation: Containers must declare cpu/memory requests and limits." message: "Resource discipline violation: Containers must declare cpu/memory requests and limits."
pattern: pattern: