A new cluster directory rather than edits to k8s-admin-prd-ase1, so no
homelab value is ever reused for GCP by accident. Charts are the ones
already vendored here (gitea 12.7.0, argo-cd 7.7.23, cert-manager
v1.20.1); only the values are new. Verified with helm template.
What differs from the homelab, and why:
- gitea: storageClass standard-rwo, and Recreate for a different reason
than the homelab's LevelDB lock — three nodes and a ReadWriteOnce disk
mean a rolling update's new pod waits forever on Multi-Attach. The
admin password comes from a Secret created at bootstrap instead of the
chart's published default, which would otherwise be live on a public
IP. Registration is disabled and webhooks are limited to private
ranges, for the same reason.
- argocd: single ingress host (no Tailscale), and the homelab's Ingress
health override is dropped, since Contour writes real load balancer
status here. server and repoServer autoscale 1-3 on CPU; the chart
omits replicas when autoscaling is on, so the HPA and ArgoCD's own
self-management do not fight over the count. Memory is deliberately
not a scaling metric: Go does not return memory promptly, so a memory
target scales up and never back down.
- cert-manager: written fresh, not copied. The homelab file was never
adapted from the fleet — it pulls from a private Meesho registry and
pins pods to a node pool that does not exist here. The chart's own
values.yaml carries that registry too, so imageRegistry and
imageNamespace are overridden back to upstream's quay.io/jetstack.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LEsTefWWifp4ikvhHF5s6N