49 lines
2.4 KiB
Markdown
49 lines
2.4 KiB
Markdown
# ArgoCD Applications (tracked copies)
|
|
|
|
Personal ArgoCD instance at `argocd.realvuxbaro.me`, on the same k3s cluster
|
|
that serves `realvuxbaro.me` — not the team's shared ArgoCD
|
|
(`argocd.vinmec.tech`), which this project does not use or have access to.
|
|
An earlier version of this directory described a plan to use the team's
|
|
instance (`docs-legacy/adr/0002-argocd-gitops.md`); that was never started,
|
|
and the owner deployed this personal instance instead because the team's
|
|
on-prem infra was heavier than needed for a single-operator project.
|
|
|
|
## Why these files exist
|
|
|
|
Until 2026-08-18, `medical-chatbot-app` and `medical-chatbot-data` existed
|
|
only as live objects inside ArgoCD — created once via the API during the
|
|
2026-08-17 cutover, never captured as a manifest. Losing the ArgoCD instance
|
|
would have meant losing the Application *definitions* too, even though the
|
|
Helm values they render (`values-production.yaml`,
|
|
`values-production-data.yaml`) were already tracked. These two files close
|
|
that gap: they are the disaster-recovery source for the Application objects
|
|
themselves.
|
|
|
|
## What's tracked vs. what isn't
|
|
|
|
`project`, `source` (repo/path/revision/valueFiles), `destination`, and
|
|
`syncPolicy` are tracked — verified byte-for-byte against the live objects on
|
|
2026-08-18. `medical-chatbot-app.yaml` deliberately omits the live
|
|
Application's inline `spec.source.helm.values`: it currently carries the
|
|
CI-rewritten image tags and, as a known gap, a plaintext Grafana admin
|
|
password that belongs in a Kubernetes Secret instead (needs cluster write
|
|
access this repo's automation doesn't have — not yet done). See the comment
|
|
at the top of that file before ever applying it.
|
|
|
|
## Files
|
|
|
|
- `applications/medical-chatbot-app.yaml` — ai-service, web, observability.
|
|
Serves both `realvuxbaro.me` and `readytochat.realvuxbaro.me`.
|
|
- `applications/medical-chatbot-data.yaml` — PostgreSQL + Qdrant, split into
|
|
its own Application so an app-side sync or prune can never touch the
|
|
PersistentVolumeClaims.
|
|
|
|
## Known gaps
|
|
|
|
- `project: default` on both — no RBAC/project scoping.
|
|
- Image tags move through `.github/scripts/sync_practice_argocd.py` and
|
|
`rollback-k3s.yml` mutating the live Application directly via the ArgoCD
|
|
API, not through a Git commit — a real GitOps setup would use an image
|
|
updater that writes the tag back to Git. Not yet built.
|
|
- The Grafana admin password gap above.
|