- appset: goTemplate, filename-based app names, .path.path IS the directory, exclude apps/root from the glob (v3.5 git files-generator schema) - remove empty Secret stubs: with prune:true they would overwrite live secret values (openwebui, paperless, vaultwarden-admin-token, password) - secrets stay cluster-managed, not in git
42 lines
1.2 KiB
YAML
42 lines
1.2 KiB
YAML
apiVersion: argoproj.io/v1alpha1
|
|
kind: ApplicationSet
|
|
metadata:
|
|
name: haven-apps
|
|
namespace: argocd
|
|
spec:
|
|
goTemplate: true
|
|
goTemplateOptions: ["missingkey=error"]
|
|
generators:
|
|
- git:
|
|
repoURL: https://git.ivanch.me/ivanch/haven-ops.git
|
|
revision: main
|
|
files:
|
|
# one Application per <app>.yaml under apps/<ns>/
|
|
- path: "apps/*/*.yaml"
|
|
# never generate apps for the bootstrap/root manifests themselves
|
|
- path: "apps/root/*.yaml"
|
|
exclude: true
|
|
template:
|
|
metadata:
|
|
# apps/default/notepad.yaml -> Application "notepad"
|
|
name: '{{ .path.filename | trimSuffix ".yaml" }}'
|
|
namespace: argocd
|
|
finalizers:
|
|
- resources-finalizer.argocd.argoproj.io
|
|
spec:
|
|
project: default
|
|
source:
|
|
repoURL: https://git.ivanch.me/ivanch/haven-ops.git
|
|
targetRevision: main
|
|
# in the git files generator .path.path IS the containing directory
|
|
path: '{{ .path.path }}'
|
|
directory:
|
|
include: '{{ .path.filename }}'
|
|
destination:
|
|
server: https://kubernetes.default.svc
|
|
namespace: '{{ index .path.segments 1 }}'
|
|
syncPolicy:
|
|
automated:
|
|
prune: true
|
|
selfHeal: true
|