ArgoCD Applications (tracked copies)
Personal ArgoCD instance at argocd.realvuxbaro.me, on the same k3s cluster
that serves realvuxbaro.me — not the team's shared ArgoCD
(argocd.vinmec.tech), which this project does not use or have access to.
An earlier version of this directory described a plan to use the team's
instance (docs-legacy/adr/0002-argocd-gitops.md); that was never started,
and the owner deployed this personal instance instead because the team's
on-prem infra was heavier than needed for a single-operator project.
Why these files exist
Until 2026-08-18, medical-chatbot-app and medical-chatbot-data existed
only as live objects inside ArgoCD — created once via the API during the
2026-08-17 cutover, never captured as a manifest. Losing the ArgoCD instance
would have meant losing the Application definitions too, even though the
Helm values they render (values-production.yaml,
values-production-data.yaml) were already tracked. These two files close
that gap: they are the disaster-recovery source for the Application objects
themselves.
What's tracked vs. what isn't
project, source (repo/path/revision/valueFiles), destination, and
syncPolicy are tracked — verified byte-for-byte against the live objects on
2026-08-18. medical-chatbot-app.yaml deliberately omits the live
Application's inline spec.source.helm.values: it currently carries the
CI-rewritten image tags and, as a known gap, a plaintext Grafana admin
password that belongs in a Kubernetes Secret instead (needs cluster write
access this repo's automation doesn't have — not yet done). See the comment
at the top of that file before ever applying it.
Files
applications/medical-chatbot-app.yaml— ai-service, web, observability. Serves bothrealvuxbaro.meandreadytochat.realvuxbaro.me.applications/medical-chatbot-data.yaml— PostgreSQL + Qdrant, split into its own Application so an app-side sync or prune can never touch the PersistentVolumeClaims.
Known gaps
project: defaulton both — no RBAC/project scoping.- Image tags move through
.github/scripts/sync_practice_argocd.pyandrollback-k3s.ymlmutating the live Application directly via the ArgoCD API, not through a Git commit — a real GitOps setup would use an image updater that writes the tag back to Git. Not yet built. - The Grafana admin password gap above.