T7: Root wiring + pilot apps (integration) #9
Labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
lab/iac#9
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Parent
Spec: catalog-driven app bootstrapping and capability groups (#2)
What to build
The integration slice where everything meets: all five roots read the same catalog and plan together for the pilot apps (privatebin, syncthing), with the platform-operator note in the docs. The Argo CD root (T9, iac single-repo: live
argocd_projectper app via theargoproj-labs/argocdprovider, role->group bindings) superseded the earlier flux-clusters manifests approach. Greentofu validate+tofu planend-to-end.Acceptance criteria
apps/catalog.yamland plan togetherplatform-operatoractor vs app principalstofu validate+tofu plangreen for all five roots on the pilot catalogtask validate-argocd-rbacgreen for the pilot apps (ADR-0007 matrix)Blocked by
T8: k8s-apiserver OIDC flags (#11) runs parallel in flux-clusters — not a blocker.
T10: tofu-controller sync for provider roots (#25) runs after — the roots must plan green here first.