added repo
This commit is contained in:
@@ -0,0 +1,239 @@
|
||||
argo-cd:
|
||||
global:
|
||||
image:
|
||||
tag: "v2.13.8"
|
||||
additionalLabels:
|
||||
bu: infra
|
||||
team: devops
|
||||
podLabels:
|
||||
bu: infra
|
||||
team: devops
|
||||
nodeSelector:
|
||||
dedicated: devops
|
||||
tolerations:
|
||||
- key: "dedicated"
|
||||
operator: "Equal"
|
||||
value: "devops"
|
||||
effect: "NoSchedule"
|
||||
dex:
|
||||
enabled: true
|
||||
resources:
|
||||
limits:
|
||||
cpu: 500m
|
||||
memory: 1Gi
|
||||
requests:
|
||||
cpu: 300m
|
||||
memory: 512Mi
|
||||
metrics:
|
||||
enabled: true
|
||||
podAnnotations:
|
||||
prometheus.io/scrape: true
|
||||
prometheus.io/path: /metrics
|
||||
prometheus.io/port: 5558
|
||||
controller:
|
||||
replicas: 2
|
||||
enableStatefulSet: true
|
||||
podAnnotations:
|
||||
prometheus.io/scrape: true
|
||||
prometheus.io/path: /metrics
|
||||
prometheus.io/port: 8082
|
||||
resources:
|
||||
limits:
|
||||
cpu: "7"
|
||||
memory: "12Gi"
|
||||
requests:
|
||||
cpu: "6"
|
||||
memory: "8Gi"
|
||||
env:
|
||||
- name: ARGOCD_CONTROLLER_REPLICAS
|
||||
value: '2'
|
||||
redis-ha:
|
||||
enabled: true
|
||||
repoServer:
|
||||
autoscaling:
|
||||
enabled: true
|
||||
maxReplicas: 15
|
||||
minReplicas: 3
|
||||
targetMemoryUtilizationPercentage: 70
|
||||
targetCPUUtilizationPercentage: 60
|
||||
metrics:
|
||||
enabled: true
|
||||
serviceMonitor:
|
||||
enabled: false
|
||||
interval: 60s
|
||||
podAnnotations:
|
||||
prometheus.io/scrape: true
|
||||
prometheus.io/path: /metrics
|
||||
prometheus.io/port: 8084
|
||||
resources:
|
||||
limits:
|
||||
cpu: 2500m
|
||||
memory: 4Gi
|
||||
requests:
|
||||
cpu: 1500m
|
||||
memory: 3Gi
|
||||
env:
|
||||
- name: ARGOCD_HELM_ALLOW_CONCURRENCY
|
||||
value: 'true'
|
||||
server:
|
||||
ingress:
|
||||
annotations.nginx.ingress.kubernetes.io/force-ssl-redirect: false
|
||||
annotations.nginx.ingress.kubernetes.io/rewrite-target: /
|
||||
annotations.nginx.ingress.kubernetes.io/ssl-redirect: false
|
||||
enabled: true
|
||||
hostname: "argocd-prd.meeshogcp.in"
|
||||
ingressClassName: nginx-internal
|
||||
replicas: 3
|
||||
autoscaling:
|
||||
enabled: true
|
||||
minReplicas: 3
|
||||
maxReplicas: 15
|
||||
targetMemoryUtilizationPercentage: 60
|
||||
targetCPUUtilizationPercentage: 60
|
||||
extraArgs:
|
||||
- --insecure
|
||||
podAnnotations:
|
||||
prometheus.io/scrape: true
|
||||
prometheus.io/path: /metrics
|
||||
prometheus.io/port: 8083
|
||||
resources:
|
||||
limits:
|
||||
cpu: 1500m
|
||||
memory: 4Gi
|
||||
requests:
|
||||
cpu: 1
|
||||
memory: 2Gi
|
||||
applicationSet:
|
||||
replicaCount: 2
|
||||
resources:
|
||||
limits:
|
||||
cpu: 500m
|
||||
memory: 1Gi
|
||||
requests:
|
||||
cpu: 300m
|
||||
memory: 512Mi
|
||||
notifications:
|
||||
resources:
|
||||
limits:
|
||||
cpu: 500m
|
||||
memory: 1Gi
|
||||
requests:
|
||||
cpu: 300m
|
||||
memory: 512Mi
|
||||
|
||||
configs:
|
||||
cm:
|
||||
resource.customizations: |
|
||||
keda.sh/ScaledObject:
|
||||
health.lua: |
|
||||
local hs = {}
|
||||
local healthy = false
|
||||
local degraded = false
|
||||
local suspended = false
|
||||
|
||||
if obj.status ~= nil then
|
||||
if obj.status.conditions ~= nil then
|
||||
for i, condition in ipairs(obj.status.conditions) do
|
||||
if condition.status == "False" and condition.type == "Ready" then
|
||||
degraded = true
|
||||
hs.message = condition.message
|
||||
end
|
||||
if condition.status == "True" and condition.type == "Ready" then
|
||||
healthy = true
|
||||
hs.message = condition.message
|
||||
end
|
||||
if condition.status == "True" and condition.type == "Paused" then
|
||||
suspended = true
|
||||
hs.message = condition.message
|
||||
end
|
||||
end
|
||||
end
|
||||
end
|
||||
|
||||
if degraded == true then
|
||||
hs.status = "Degraded"
|
||||
return hs
|
||||
elseif healthy == true then
|
||||
hs.status = "Healthy"
|
||||
if suspended == true then
|
||||
hs.message = "ScaledObject is paused as part of normal operations."
|
||||
else
|
||||
hs.message = "ScaledObject is active."
|
||||
end
|
||||
return hs
|
||||
end
|
||||
|
||||
hs.status = "Progressing"
|
||||
hs.message = "Creating ScaledObject or waiting for conditions."
|
||||
return hs
|
||||
url: https://argocd-prd.meeshogcp.in
|
||||
timeout.reconciliation: 3m
|
||||
timeout.reconciliation.jitter: 60s
|
||||
statusbadge.enabled: "true"
|
||||
help.chatUrl: "https://meesho.slack.com/archives/C021QNS6JLV"
|
||||
help.chatText: "Chat now!"
|
||||
dex.config: |
|
||||
logger:
|
||||
level: error
|
||||
format: json
|
||||
connectors:
|
||||
- type: github
|
||||
id: github
|
||||
name: GitHub
|
||||
loadAllGroups: true
|
||||
admin.enabled: "true"
|
||||
config:
|
||||
clientID: 7f82547c0e671780cda5
|
||||
clientSecret: $github-sso-secret:dex.github.clientSecret
|
||||
orgs:
|
||||
- name: Meesho
|
||||
params:
|
||||
controller.sharding.algorithm: round-robin
|
||||
controller.status.processors: '40'
|
||||
controller.operation.processors: '20'
|
||||
controller.repo.server.timeout.seconds: '60'
|
||||
rbac:
|
||||
policy.csv: |
|
||||
p, role:admins, *, *, */*, allow
|
||||
## Policy for Admin-NoDelete role
|
||||
p, role:admin-nodelete, *, get, *, allow
|
||||
p, role:admin-nodelete, *, create, *, allow
|
||||
p, role:admin-nodelete, *, update, *, allow
|
||||
p, role:admin-nodelete, *, update, devops/argocd-*, deny
|
||||
p, role:admin-nodelete, applications, override, *, allow
|
||||
p, role:admin-nodelete, applications, sync, *, allow
|
||||
p, role:admin-nodelete, applications, action/*, *, allow
|
||||
p, role:admin-nodelete, applications, delete/*/Pod/*/*, */*, allow
|
||||
g, Meesho:devops-new, role:admin-nodelete
|
||||
|
||||
p, role:superstore, applications, *, farmiso/*, allow
|
||||
|
||||
p, role:backend, applications, get, */*, allow
|
||||
p, role:backend, applications, update, */*, allow
|
||||
p, role:backend, applications, sync, */*, allow
|
||||
|
||||
g, Meesho:devops, role:admins
|
||||
g, Meesho:superstore, role:superstore
|
||||
g, Meesho:backend, role:backend
|
||||
p, role:intern, *, get, *, allow
|
||||
g, Meesho:devops-interns, role:intern
|
||||
|
||||
## Policy: sync access to aurva apps
|
||||
p, role:aurva-sync, applications, get, devops/aurva-dataplane-*, allow
|
||||
p, role:aurva-sync, applications, sync, devops/aurva-dataplane-*, allow
|
||||
p, role:aurva-sync, applications, action/apps/*/restart, devops/aurva-dataplane-*, allow
|
||||
g, keshav.pandya@meesho.com, role:aurva-sync
|
||||
|
||||
repositories:
|
||||
gcp-devops-admin:
|
||||
url: https://github.com/Meesho/gcp-devops-admin
|
||||
gcp-argocd-apps:
|
||||
url: https://github.com/Meesho/gcp-argocd-apps
|
||||
gcp-service-helmcharts:
|
||||
url: https://github.com/Meesho/gcp-service-helmcharts
|
||||
sre-argo-apps:
|
||||
url: https://github.com/Meesho/sre-argo-apps
|
||||
devops-infra-helm-charts:
|
||||
url: https://github.com/Meesho/devops-infra-helm-charts
|
||||
devops-infra-argo-config:
|
||||
url: https://github.com/Meesho/devops-infra-argo-config
|
||||
Reference in New Issue
Block a user