mirror of
https://github.com/gwg313/homelab-gitops.git
synced 2026-06-05 21:01:02 +00:00
Compare commits
2 commits
5ad6f392eb
...
4be877e419
| Author | SHA1 | Date | |
|---|---|---|---|
| 4be877e419 | |||
| d3da92bbb8 |
9 changed files with 8 additions and 14 deletions
|
|
@ -1,5 +1,7 @@
|
|||
harbor:
|
||||
externalURL: https://registry.gwg313.xyz
|
||||
updateStrategy:
|
||||
type: Recreate
|
||||
|
||||
nginx:
|
||||
replicas: 0
|
||||
|
|
@ -21,8 +23,6 @@ harbor:
|
|||
memory: 128Mi
|
||||
|
||||
core:
|
||||
updateStrategy:
|
||||
type: Recreate
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
|
|
@ -32,8 +32,6 @@ harbor:
|
|||
memory: 512Mi
|
||||
|
||||
jobservice:
|
||||
updateStrategy:
|
||||
type: Recreate
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
|
|
|
|||
|
|
@ -4,3 +4,4 @@ kind: Kustomization
|
|||
resources:
|
||||
- https://storage.googleapis.com/tekton-releases/pipeline/latest/release.yaml
|
||||
- https://storage.googleapis.com/tekton-releases/dashboard/latest/release.yaml
|
||||
- https://raw.githubusercontent.com/openshift-pipelines/pipelines-as-code/stable/release.k8s.yaml
|
||||
|
|
|
|||
|
|
@ -20,5 +20,3 @@ spec:
|
|||
selfHeal: true
|
||||
syncOptions:
|
||||
- CreateNamespace=true
|
||||
- ServerSideApply=true
|
||||
- SkipDryRunOnMissingResource=true
|
||||
|
|
|
|||
|
|
@ -20,4 +20,3 @@ spec:
|
|||
selfHeal: true
|
||||
syncOptions:
|
||||
- CreateNamespace=true
|
||||
- ServerSideApply=true
|
||||
|
|
|
|||
|
|
@ -18,8 +18,3 @@ spec:
|
|||
automated:
|
||||
prune: true
|
||||
selfHeal: true
|
||||
syncOptions:
|
||||
- CreateNamespace=false
|
||||
- ServerSideApply=true
|
||||
- Replace=true # <-- Policies have immutable fields so this helps deal with updates
|
||||
- Force=true
|
||||
|
|
|
|||
|
|
@ -20,5 +20,4 @@ spec:
|
|||
selfHeal: true
|
||||
syncOptions:
|
||||
- CreateNamespace=true
|
||||
- ServerSideApply=true
|
||||
- SkipDryRunOnMissingResource=true
|
||||
|
|
|
|||
|
|
@ -20,4 +20,3 @@ spec:
|
|||
selfHeal: true
|
||||
syncOptions:
|
||||
- CreateNamespace=true
|
||||
- ServerSideApply=true
|
||||
|
|
|
|||
|
|
@ -5,6 +5,8 @@ metadata:
|
|||
annotations:
|
||||
policies.kyverno.io/title: Inject Namespace Baseline CNP
|
||||
policies.kyverno.io/description: Automatically provisions a local default-deny + DNS egress CNP inside new application namespaces.
|
||||
argocd.argoproj.io/sync-options: Force=true,Replace=true
|
||||
|
||||
spec:
|
||||
background: true
|
||||
rules:
|
||||
|
|
@ -32,6 +34,7 @@ spec:
|
|||
- monitoring
|
||||
- tekton-pipelines-resolvers
|
||||
- tekton-pipelines
|
||||
- pipelines-as-code
|
||||
generate:
|
||||
apiVersion: cilium.io/v2
|
||||
kind: CiliumNetworkPolicy
|
||||
|
|
|
|||
|
|
@ -36,6 +36,8 @@ spec:
|
|||
- monitoring
|
||||
- tekton-pipelines-resolvers
|
||||
- tekton-pipelines
|
||||
- pipelines-as-code
|
||||
- cicd
|
||||
validate:
|
||||
message: "Resource discipline violation: Containers must declare cpu/memory requests and limits."
|
||||
pattern:
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue