From 1832cbeb649225fb96602e3af921e4004555907b Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 21 Jul 2026 11:40:51 +0200 Subject: [PATCH 001/122] Added kube-prometheus-stack, alert manger, grafana custom dashboard --- infrastructure/overlay/dev/ingress.yaml | 1 + .../base/alertmanager/inhibit-rules.yaml | 0 .../base/alertmanager/receivers.yaml | 0 .../monitoring/base/alertmanager/routes.yaml | 0 .../base/alertmanager/templates/email.tmpl | 0 .../base/alertmanager/templates/slack.tmpl | 0 .../base/grafana/dashboardproviders.yaml | 0 .../grafana/dashboards/ingress-nginx.json | 0 .../base/grafana/dashboards/jvm.json | 0 .../base/grafana/dashboards/kubernetes.json | 0 .../base/grafana/dashboards/nodes.json | 0 .../base/grafana/dashboards/postgres.json | 0 .../base/grafana/dashboards/redis.json | 0 .../base/grafana/dashboards/springboot.json | 0 .../monitoring/base/grafana/datasources.yaml | 0 .../alertmanager/README.md} | 0 .../alertmanager/external-secret.yaml | 21 +++ .../external-secret.yaml | 26 ++++ .../grafana/dashboards/README.md | 17 ++ .../kube-prometheus-stack/helm-release.yaml | 65 ++++---- .../helm-repository.yaml | 8 + .../kube-prometheus-stack/kustomization.yaml | 16 ++ .../base/kube-prometheus-stack/values.yaml | 146 +++++++++++++++--- 23 files changed, 245 insertions(+), 55 deletions(-) delete mode 100644 platform/monitoring/base/alertmanager/inhibit-rules.yaml delete mode 100644 platform/monitoring/base/alertmanager/receivers.yaml delete mode 100644 platform/monitoring/base/alertmanager/routes.yaml delete mode 100644 platform/monitoring/base/alertmanager/templates/email.tmpl delete mode 100644 platform/monitoring/base/alertmanager/templates/slack.tmpl delete mode 100644 platform/monitoring/base/grafana/dashboardproviders.yaml delete mode 100644 platform/monitoring/base/grafana/dashboards/ingress-nginx.json delete mode 100644 platform/monitoring/base/grafana/dashboards/jvm.json delete mode 100644 platform/monitoring/base/grafana/dashboards/kubernetes.json delete mode 100644 platform/monitoring/base/grafana/dashboards/nodes.json delete mode 100644 platform/monitoring/base/grafana/dashboards/postgres.json delete mode 100644 platform/monitoring/base/grafana/dashboards/redis.json delete mode 100644 platform/monitoring/base/grafana/dashboards/springboot.json delete mode 100644 platform/monitoring/base/grafana/datasources.yaml rename platform/monitoring/base/{alertmanager/config.yaml => kube-prometheus-stack/alertmanager/README.md} (100%) create mode 100644 platform/monitoring/base/kube-prometheus-stack/alertmanager/external-secret.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/external-secret.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/README.md create mode 100644 platform/monitoring/base/kube-prometheus-stack/helm-repository.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/kustomization.yaml diff --git a/infrastructure/overlay/dev/ingress.yaml b/infrastructure/overlay/dev/ingress.yaml index 9979c41..e25b6cc 100644 --- a/infrastructure/overlay/dev/ingress.yaml +++ b/infrastructure/overlay/dev/ingress.yaml @@ -16,6 +16,7 @@ metadata: # Redirect HTTP to HTTPS alb.ingress.kubernetes.io/ssl-redirect: '443' + external-dns.alpha.kubernetes.io/hostname: api.dev.emmanuelogah.com spec: ingressClassName: alb diff --git a/platform/monitoring/base/alertmanager/inhibit-rules.yaml b/platform/monitoring/base/alertmanager/inhibit-rules.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/alertmanager/receivers.yaml b/platform/monitoring/base/alertmanager/receivers.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/alertmanager/routes.yaml b/platform/monitoring/base/alertmanager/routes.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/alertmanager/templates/email.tmpl b/platform/monitoring/base/alertmanager/templates/email.tmpl deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/alertmanager/templates/slack.tmpl b/platform/monitoring/base/alertmanager/templates/slack.tmpl deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/grafana/dashboardproviders.yaml b/platform/monitoring/base/grafana/dashboardproviders.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/grafana/dashboards/ingress-nginx.json b/platform/monitoring/base/grafana/dashboards/ingress-nginx.json deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/grafana/dashboards/jvm.json b/platform/monitoring/base/grafana/dashboards/jvm.json deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/grafana/dashboards/kubernetes.json b/platform/monitoring/base/grafana/dashboards/kubernetes.json deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/grafana/dashboards/nodes.json b/platform/monitoring/base/grafana/dashboards/nodes.json deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/grafana/dashboards/postgres.json b/platform/monitoring/base/grafana/dashboards/postgres.json deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/grafana/dashboards/redis.json b/platform/monitoring/base/grafana/dashboards/redis.json deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/grafana/dashboards/springboot.json b/platform/monitoring/base/grafana/dashboards/springboot.json deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/grafana/datasources.yaml b/platform/monitoring/base/grafana/datasources.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/alertmanager/config.yaml b/platform/monitoring/base/kube-prometheus-stack/alertmanager/README.md similarity index 100% rename from platform/monitoring/base/alertmanager/config.yaml rename to platform/monitoring/base/kube-prometheus-stack/alertmanager/README.md diff --git a/platform/monitoring/base/kube-prometheus-stack/alertmanager/external-secret.yaml b/platform/monitoring/base/kube-prometheus-stack/alertmanager/external-secret.yaml new file mode 100644 index 0000000..a82f14b --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/alertmanager/external-secret.yaml @@ -0,0 +1,21 @@ +apiVersion: external-secrets.io/v1 +kind: ExternalSecret +metadata: + name: alertmanager-notification-secret + namespace: dev + +spec: + refreshInterval: 1h + + secretStoreRef: + name: aws-secretsmanager + kind: ClusterSecretStore + + target: + name: alertmanager-notification-secret + + data: + - secretKey: slack-webhook + remoteRef: + key: alertmanager/notifications + property: slack-webhook \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/external-secret.yaml b/platform/monitoring/base/kube-prometheus-stack/external-secret.yaml new file mode 100644 index 0000000..ccf18bd --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/external-secret.yaml @@ -0,0 +1,26 @@ +apiVersion: external-secrets.io/v1 +kind: ExternalSecret +metadata: + name: grafana-admin + namespace: dev +spec: + refreshInterval: 1h + + secretStoreRef: + kind: ClusterSecretStore + name: aws-secretsmanager + + target: + name: grafana-admin + creationPolicy: Owner + + data: + - secretKey: admin-user + remoteRef: + key: grafana/admin + property: username + + - secretKey: admin-password + remoteRef: + key: grafana/admin + property: password \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/README.md b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/README.md new file mode 100644 index 0000000..1539e2c --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/README.md @@ -0,0 +1,17 @@ +# Grafana Dashboards + +This directory contains custom Grafana dashboards provisioned through +the kube-prometheus-stack Grafana sidecar. + +## Dashboards + +- kubernetes.json +- nodes.json +- ingress-nginx.json +- springboot.json +- jvm.json +- postgres.json +- redis.json + +Each dashboard is packaged into a ConfigMap by Kustomize and +automatically imported into Grafana. \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/helm-release.yaml b/platform/monitoring/base/kube-prometheus-stack/helm-release.yaml index 4d41496..bed1602 100644 --- a/platform/monitoring/base/kube-prometheus-stack/helm-release.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/helm-release.yaml @@ -1,38 +1,31 @@ -apiVersion: argoproj.io/v1alpha1 - -kind: Application - +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: - name: monitoring - + name: prometheus-stack + namespace: dev spec: - - project: default - - source: - - repoURL: https://prometheus-community.github.io/helm-charts - - chart: kube-prometheus-stack - - targetRevision: 72.6.0 - - helm: - - valueFiles: - - - values.yaml - - destination: - - server: https://kubernetes.default.svc - - namespace: monitoring - - syncPolicy: - - automated: - - prune: true - - selfHeal: true \ No newline at end of file + interval: 30m + + chart: + spec: + chart: kube-prometheus-stack + version: "72.6.0" + sourceRef: + kind: HelmRepository + name: prometheus-community + namespace: flux-system + + install: + createNamespace: true + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + remediateLastFailure: true + + valuesFrom: + - kind: ConfigMap + name: prometheus-stack-values + valuesKey: values.yaml \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/helm-repository.yaml b/platform/monitoring/base/kube-prometheus-stack/helm-repository.yaml new file mode 100644 index 0000000..7fb95d4 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/helm-repository.yaml @@ -0,0 +1,8 @@ +apiVersion: source.toolkit.fluxcd.io/v1 +kind: HelmRepository +metadata: + name: prometheus-community + namespace: flux-system +spec: + interval: 24h + url: https://prometheus-community.github.io/helm-charts \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml new file mode 100644 index 0000000..1ee5224 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml @@ -0,0 +1,16 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +namespace: dev + +resources: + - helm-repository.yaml + - helm-release.yaml + +configMapGenerator: + - name: prometheus-stack-values + files: + - values.yaml + +generatorOptions: + disableNameSuffixHash: true \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/values.yaml b/platform/monitoring/base/kube-prometheus-stack/values.yaml index ba6776b..f83157b 100644 --- a/platform/monitoring/base/kube-prometheus-stack/values.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/values.yaml @@ -1,51 +1,159 @@ grafana: + enabled: true - adminPassword: admin + admin: + existingSecret: grafana-admin + userKey: admin-user + passwordKey: admin-password - persistence: + service: + type: ClusterIP + persistence: enabled: true - + storageClassName: gp3 size: 20Gi - service: - - type: ClusterIP + defaultDashboardsEnabled: true + + sidecar: + dashboards: + enabled: true + searchNamespace: ALL + + datasources: + enabled: true + + dashboards: + default: + kubernetes-cluster: + gnetId: 15757 + revision: 42 + datasource: Prometheus + + node-exporter: + gnetId: 1860 + revision: 37 + datasource: Prometheus + + ingress-nginx: + gnetId: 9614 + revision: 1 + datasource: Prometheus + + spring-boot: + gnetId: 12900 + revision: 1 + datasource: Prometheus + + jvm: + gnetId: 4701 + revision: 10 + datasource: Prometheus + + postgres: + gnetId: 9628 + revision: 7 + datasource: Prometheus + + redis: + gnetId: 11835 + revision: 1 + datasource: Prometheus prometheus: - prometheusSpec: - retention: 30d - retentionSize: 30GB storageSpec: - volumeClaimTemplate: - spec: - storageClassName: gp3 - accessModes: + - ReadWriteOnce + resources: + requests: + storage: 50Gi - - ReadWriteOnce +alertmanager: + enabled: true + alertmanagerSpec: + retention: 120h + storage: + volumeClaimTemplate: + spec: + storageClassName: gp3 + accessModes: + - ReadWriteOnce resources: - requests: + storage: 10Gi - storage: 50Gi + # Use Kubernetes secret for credentials + secrets: + - alertmanager-notification-secret -alertmanager: - enabled: true + config: + global: + resolve_timeout: 5m -kubeStateMetrics: + route: + group_by: + - alertname + - namespace + + group_wait: 30s + group_interval: 5m + repeat_interval: 4h + + receiver: default-receiver + + routes: + - matchers: + - severity="critical" + receiver: slack-critical + receivers: + + - name: default-receiver + + - name: slack-critical + slack_configs: + - api_url_file: /etc/alertmanager/secrets/alertmanager-notification-secret/slack-webhook + channel: "#alerts" + send_resolved: true + title: >- + {{ .CommonAnnotations.summary }} + + - name: email-alerts + email_configs: + - to: platform-team@example.com + from: alertmanager@example.com + smarthost: smtp.example.com:587 + auth_username: alertmanager@example.com + auth_password_file: /etc/alertmanager/secrets/alertmanager-email-secret/password + + + inhibit_rules: + - source_matchers: + - severity="critical" + + target_matchers: + - severity="warning" + + equal: + - namespace + - alertname + + +kubeStateMetrics: enabled: true nodeExporter: + enabled: true +prometheusOperator: enabled: true \ No newline at end of file From 05a35880c73224fa1bef382c2a3b7c9006427ead Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 21 Jul 2026 12:52:52 +0200 Subject: [PATCH 002/122] Added exporter --- .../base/exporters/jmx-exporter.yaml | 0 .../base/exporters/postgres-exporter.yaml | 0 .../base/exporters/redis-exporter.yaml | 0 .../blackbox-exporter/helm-release.yaml | 30 +++++++++++++++++++ .../exporters/kustomization.yaml} | 0 .../exporters/network-policy.yaml | 20 +++++++++++++ .../postgres-exporter/helm-release.yaml | 28 +++++++++++++++++ .../redis-exporter/helm-release.yaml | 22 ++++++++++++++ .../base/kube-prometheus-stack/values.yaml | 6 ++++ .../base/servicemonitors/order.yaml | 24 +++++---------- 10 files changed, 113 insertions(+), 17 deletions(-) delete mode 100644 platform/monitoring/base/exporters/jmx-exporter.yaml delete mode 100644 platform/monitoring/base/exporters/postgres-exporter.yaml delete mode 100644 platform/monitoring/base/exporters/redis-exporter.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/exporters/blackbox-exporter/helm-release.yaml rename platform/monitoring/base/{exporters/blackbox-exporter.yaml => kube-prometheus-stack/exporters/kustomization.yaml} (100%) create mode 100644 platform/monitoring/base/kube-prometheus-stack/exporters/network-policy.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/exporters/postgres-exporter/helm-release.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/exporters/redis-exporter/helm-release.yaml diff --git a/platform/monitoring/base/exporters/jmx-exporter.yaml b/platform/monitoring/base/exporters/jmx-exporter.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/exporters/postgres-exporter.yaml b/platform/monitoring/base/exporters/postgres-exporter.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/exporters/redis-exporter.yaml b/platform/monitoring/base/exporters/redis-exporter.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/kube-prometheus-stack/exporters/blackbox-exporter/helm-release.yaml b/platform/monitoring/base/kube-prometheus-stack/exporters/blackbox-exporter/helm-release.yaml new file mode 100644 index 0000000..7061cf7 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/exporters/blackbox-exporter/helm-release.yaml @@ -0,0 +1,30 @@ +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease + +metadata: + name: blackbox-exporter + namespace: dev + +spec: + interval: 30m + + chart: + spec: + chart: prometheus-blackbox-exporter + version: "9.0.0" + sourceRef: + kind: HelmRepository + name: prometheus-community + namespace: flux-system + + values: + serviceMonitor: + enabled: true + + config: + modules: + http_2xx: + prober: http + timeout: 5s + http: + preferred_ip_protocol: ip4 \ No newline at end of file diff --git a/platform/monitoring/base/exporters/blackbox-exporter.yaml b/platform/monitoring/base/kube-prometheus-stack/exporters/kustomization.yaml similarity index 100% rename from platform/monitoring/base/exporters/blackbox-exporter.yaml rename to platform/monitoring/base/kube-prometheus-stack/exporters/kustomization.yaml diff --git a/platform/monitoring/base/kube-prometheus-stack/exporters/network-policy.yaml b/platform/monitoring/base/kube-prometheus-stack/exporters/network-policy.yaml new file mode 100644 index 0000000..108e8d5 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/exporters/network-policy.yaml @@ -0,0 +1,20 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-prometheus + namespace: dev + +spec: + podSelector: + matchLabels: + app.kubernetes.io/component: exporter + + ingress: + - from: + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: dev + + ports: + - port: 9100 \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/exporters/postgres-exporter/helm-release.yaml b/platform/monitoring/base/kube-prometheus-stack/exporters/postgres-exporter/helm-release.yaml new file mode 100644 index 0000000..b3318f4 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/exporters/postgres-exporter/helm-release.yaml @@ -0,0 +1,28 @@ +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease + +metadata: + name: postgres-exporter + namespace: dev + +spec: + interval: 30m + + chart: + spec: + chart: prometheus-postgres-exporter + version: "6.8.0" + sourceRef: + kind: HelmRepository + name: prometheus-community + namespace: flux-system + + values: + serviceMonitor: + enabled: true + + config: + datasource: + host: postgres.default.svc.cluster.local + port: "5432" + database: postgres \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/exporters/redis-exporter/helm-release.yaml b/platform/monitoring/base/kube-prometheus-stack/exporters/redis-exporter/helm-release.yaml new file mode 100644 index 0000000..a4a8d15 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/exporters/redis-exporter/helm-release.yaml @@ -0,0 +1,22 @@ +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease + +metadata: + name: redis-exporter + namespace: dev + +spec: + interval: 30m + + chart: + spec: + chart: prometheus-redis-exporter + version: "6.8.0" + sourceRef: + kind: HelmRepository + name: prometheus-community + namespace: flux-system + + values: + serviceMonitor: + enabled: true \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/values.yaml b/platform/monitoring/base/kube-prometheus-stack/values.yaml index f83157b..8e1b8df 100644 --- a/platform/monitoring/base/kube-prometheus-stack/values.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/values.yaml @@ -66,6 +66,12 @@ prometheus: retention: 30d retentionSize: 30GB + serviceMonitorSelector: + matchLabels: + prometheus: kube-prometheus + + serviceMonitorNamespaceSelector: {} + storageSpec: volumeClaimTemplate: spec: diff --git a/platform/monitoring/base/servicemonitors/order.yaml b/platform/monitoring/base/servicemonitors/order.yaml index 87412d7..ed92a33 100644 --- a/platform/monitoring/base/servicemonitors/order.yaml +++ b/platform/monitoring/base/servicemonitors/order.yaml @@ -1,29 +1,19 @@ apiVersion: monitoring.coreos.com/v1 - kind: ServiceMonitor metadata: - name: order-service + namespace: dev -spec: + labels: + prometheus: kube-prometheus +spec: selector: - matchLabels: - app: order-service - namespaceSelector: - - matchNames: - - - order - endpoints: - - - port: http - - path: /actuator/prometheus - - interval: 15s \ No newline at end of file + - port: http + path: /actuator/prometheus + interval: 30s \ No newline at end of file From c58d7106e73e93616b8e688e839de50744a28077 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 21 Jul 2026 14:02:43 +0200 Subject: [PATCH 003/122] added prometheus rule --- README.md | 8 ++ .../exporters/network-policy.yaml | 10 ++- .../kube-prometheus-stack/kustomization.yaml | 1 + .../prometheusrules/applications.yaml | 35 ++++++++ .../prometheusrules/databases.yaml | 84 ++++++++++++++++++ .../prometheusrules/ingress.yaml | 59 +++++++++++++ .../prometheusrules/kubernetes.yaml | 49 +++++++++++ .../prometheusrules/kustomization.yaml | 10 +++ .../prometheusrules/nodes.yaml | 54 ++++++++++++ .../prometheusrules/redis.yaml | 85 +++++++++++++++++++ .../base/kube-prometheus-stack/values.yaml | 6 ++ .../base/networkpolicy/allow-prometheus.yaml | 0 .../prometheusrules/application-latency.yaml | 0 .../base/prometheusrules/database-down.yaml | 3 - .../deployment-unavailable.yaml | 0 .../base/prometheusrules/disk-pressure.yaml | 0 .../base/prometheusrules/high-cpu.yaml | 29 ------- .../base/prometheusrules/high-memory.yaml | 52 ------------ .../base/prometheusrules/ingress-5xx.yaml | 0 .../base/prometheusrules/node-not-ready.yaml | 0 .../base/prometheusrules/pod-crashloop.yaml | 0 .../base/prometheusrules/pod-restarts.yaml | 21 ----- .../prometheusrules/postgres-connections.yaml | 0 .../base/prometheusrules/redis-down.yaml | 0 24 files changed, 400 insertions(+), 106 deletions(-) create mode 100644 platform/monitoring/base/kube-prometheus-stack/prometheusrules/applications.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/prometheusrules/databases.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/prometheusrules/ingress.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/prometheusrules/kubernetes.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/prometheusrules/kustomization.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/prometheusrules/nodes.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/prometheusrules/redis.yaml delete mode 100644 platform/monitoring/base/networkpolicy/allow-prometheus.yaml delete mode 100644 platform/monitoring/base/prometheusrules/application-latency.yaml delete mode 100644 platform/monitoring/base/prometheusrules/database-down.yaml delete mode 100644 platform/monitoring/base/prometheusrules/deployment-unavailable.yaml delete mode 100644 platform/monitoring/base/prometheusrules/disk-pressure.yaml delete mode 100644 platform/monitoring/base/prometheusrules/high-cpu.yaml delete mode 100644 platform/monitoring/base/prometheusrules/high-memory.yaml delete mode 100644 platform/monitoring/base/prometheusrules/ingress-5xx.yaml delete mode 100644 platform/monitoring/base/prometheusrules/node-not-ready.yaml delete mode 100644 platform/monitoring/base/prometheusrules/pod-crashloop.yaml delete mode 100644 platform/monitoring/base/prometheusrules/pod-restarts.yaml delete mode 100644 platform/monitoring/base/prometheusrules/postgres-connections.yaml delete mode 100644 platform/monitoring/base/prometheusrules/redis-down.yaml diff --git a/README.md b/README.md index 3cc01c3..8d1b7be 100644 --- a/README.md +++ b/README.md @@ -130,6 +130,14 @@ Kubernetes-argocd Repo │ │ ├── api-errors.yaml │ │ ├── latency.yaml │ │ ├── disk-space.yaml + │ │ ├── application-latency.yaml + │ │ ├── disk-pressure.yaml + │ │ ├── ingress-5xx.yaml + │ │ ├── node-not-ready.yaml + │ │ ├── pod-crashloop.yaml + │ │ ├── postgres-connections.yaml + │ │ ├── redis.yaml + │ │ ├── deployment-unavailable.yaml │ │ └── database-down.yaml │ │ ├── recording-rules/ │ │ │ ├── cluster.yaml diff --git a/platform/monitoring/base/kube-prometheus-stack/exporters/network-policy.yaml b/platform/monitoring/base/kube-prometheus-stack/exporters/network-policy.yaml index 108e8d5..55fcabf 100644 --- a/platform/monitoring/base/kube-prometheus-stack/exporters/network-policy.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/exporters/network-policy.yaml @@ -10,11 +10,19 @@ spec: matchLabels: app.kubernetes.io/component: exporter + policyTypes: + - Ingress + ingress: - from: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: dev + podSelector: + matchLabels: + app.kubernetes.io/name: prometheus + ports: - - port: 9100 \ No newline at end of file + - protocol: TCP + port: 9100 \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml index 1ee5224..e745b10 100644 --- a/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml @@ -6,6 +6,7 @@ namespace: dev resources: - helm-repository.yaml - helm-release.yaml + - prometheusrules/ configMapGenerator: - name: prometheus-stack-values diff --git a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/applications.yaml b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/applications.yaml new file mode 100644 index 0000000..b9cb62f --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/applications.yaml @@ -0,0 +1,35 @@ +apiVersion: monitoring.coreos.com/v1 +kind: PrometheusRule + +metadata: + name: application-alerts + namespace: dev + + labels: + prometheus: kube-prometheus + +spec: + groups: + + - name: application.rules + + rules: + + - alert: APIHighErrorRate + + expr: | + ( + sum(rate(http_server_requests_seconds_count{ + status=~"5.." + }[5m])) + / + sum(rate(http_server_requests_seconds_count[5m])) + ) > 0.05 + + for: 5m + + labels: + severity: critical + + annotations: + summary: API error rate above 5% \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/databases.yaml b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/databases.yaml new file mode 100644 index 0000000..6c9135d --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/databases.yaml @@ -0,0 +1,84 @@ +apiVersion: monitoring.coreos.com/v1 +kind: PrometheusRule + +metadata: + name: database-alerts + namespace: dev + + labels: + prometheus: kube-prometheus + +spec: + groups: + + - name: postgres.rules + + rules: + + - alert: PostgreSQLDown + + expr: | + pg_up == 0 + + for: 5m + + labels: + severity: critical + + annotations: + summary: PostgreSQL database is down + description: > + PostgreSQL exporter cannot connect to the database. + + + - alert: PostgreSQLTooManyConnections + + expr: | + ( + sum(pg_stat_database_numbackends) + / + sum(pg_settings_max_connections) + ) > 0.85 + + for: 10m + + labels: + severity: warning + + annotations: + summary: PostgreSQL connection usage above 85% + description: > + Database connection usage is approaching the configured limit. + + + - alert: PostgreSQLDeadlocks + + expr: | + rate(pg_stat_database_deadlocks_total[5m]) > 0 + + for: 5m + + labels: + severity: warning + + annotations: + summary: PostgreSQL deadlocks detected + description: > + PostgreSQL is reporting deadlocks. + + + - alert: PostgreSQLSlowQueries + + expr: | + rate(pg_stat_database_tup_returned[5m]) + / + rate(pg_stat_database_tup_fetched[5m]) + < 0.1 + + for: 15m + + labels: + severity: warning + + annotations: + summary: PostgreSQL query efficiency degraded \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/ingress.yaml b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/ingress.yaml new file mode 100644 index 0000000..e7c09fc --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/ingress.yaml @@ -0,0 +1,59 @@ +apiVersion: monitoring.coreos.com/v1 +kind: PrometheusRule + +metadata: + name: ingress-alerts + namespace: dev + + labels: + prometheus: kube-prometheus + +spec: + + groups: + + - name: ingress.rules + + rules: + + + - alert: ALBControllerErrors + + expr: | + rate( + aws_loadbalancer_controller_reconcile_errors_total[5m] + ) > 0 + + for: 10m + + labels: + severity: warning + + annotations: + summary: AWS Load Balancer Controller errors + description: > + ALB controller is reporting reconciliation errors. + + + - alert: HighHTTP5xxRate + + expr: | + ( + sum(rate( + http_server_requests_seconds_count{ + status=~"5.." + }[5m])) + / + sum(rate( + http_server_requests_seconds_count[5m])) + ) > 0.05 + + for: 5m + + labels: + severity: critical + + annotations: + summary: High HTTP 5xx error rate + description: > + More than 5% of HTTP requests are returning errors. \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/kubernetes.yaml b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/kubernetes.yaml new file mode 100644 index 0000000..94bca1c --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/kubernetes.yaml @@ -0,0 +1,49 @@ +apiVersion: monitoring.coreos.com/v1 +kind: PrometheusRule + +metadata: + name: kubernetes-alerts + namespace: dev + + labels: + prometheus: kube-prometheus + +spec: + groups: + + - name: kubernetes.rules + + rules: + + - alert: PodCrashLooping + + expr: | + increase(kube_pod_container_status_restarts_total[15m]) > 5 + + for: 10m + + labels: + severity: warning + + annotations: + summary: Pod is restarting repeatedly + description: | + Pod {{ $labels.namespace }}/{{ $labels.pod }} + has restarted more than 5 times in 15 minutes. + + + - alert: PodNotReady + + expr: | + kube_pod_status_ready{condition="false"} == 1 + + for: 15m + + labels: + severity: warning + + annotations: + summary: Pod is not ready + description: | + Pod {{ $labels.namespace }}/{{ $labels.pod }} + has been unavailable for 15 minutes. \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/kustomization.yaml new file mode 100644 index 0000000..480ec9f --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/kustomization.yaml @@ -0,0 +1,10 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - kubernetes.yaml + - nodes.yaml + - applications.yaml + - ingress.yaml + - databases.yaml + - redis.yaml \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/nodes.yaml b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/nodes.yaml new file mode 100644 index 0000000..23bb86b --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/nodes.yaml @@ -0,0 +1,54 @@ +apiVersion: monitoring.coreos.com/v1 +kind: PrometheusRule + +metadata: + name: node-alerts + namespace: dev + + labels: + prometheus: kube-prometheus + +spec: + groups: + + - name: node.rules + + rules: + + - alert: HighCPUUsage + + expr: | + 100 - + ( + avg by(instance) + (rate(node_cpu_seconds_total{mode="idle"}[5m])) + * 100 + ) + > 85 + + for: 10m + + labels: + severity: warning + + annotations: + summary: High CPU usage + description: | + Node {{ $labels.instance }} + CPU usage is above 85%. + + + - alert: DiskSpaceLow + + expr: | + node_filesystem_avail_bytes / + node_filesystem_size_bytes + < 0.10 + + for: 15m + + labels: + severity: warning + + annotations: + summary: Disk space below 10% \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/redis.yaml b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/redis.yaml new file mode 100644 index 0000000..a7a0374 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/redis.yaml @@ -0,0 +1,85 @@ +apiVersion: monitoring.coreos.com/v1 +kind: PrometheusRule + +metadata: + name: redis-alerts + namespace: dev + + labels: + prometheus: kube-prometheus + +spec: + groups: + + - name: redis.rules + + rules: + + + - alert: RedisDown + + expr: | + redis_up == 0 + + for: 5m + + labels: + severity: critical + + annotations: + summary: Redis is unavailable + description: > + Redis exporter cannot connect to Redis. + + + - alert: RedisHighMemoryUsage + + expr: | + ( + redis_memory_used_bytes + / + redis_memory_max_bytes + ) > 0.85 + + for: 10m + + labels: + severity: warning + + annotations: + summary: Redis memory usage above 85% + description: > + Redis memory utilization is approaching the configured limit. + + + - alert: RedisRejectedConnections + + expr: | + increase(redis_rejected_connections_total[5m]) > 0 + + for: 5m + + labels: + severity: warning + + annotations: + summary: Redis is rejecting connections + description: > + Redis has rejected client connections recently. + + + - alert: RedisHighLatency + + expr: | + redis_commands_duration_seconds_total + / + redis_commands_processed_total + > 0.1 + + for: 10m + + labels: + severity: warning + + annotations: + summary: Redis command latency is high \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/values.yaml b/platform/monitoring/base/kube-prometheus-stack/values.yaml index 8e1b8df..cd8dbef 100644 --- a/platform/monitoring/base/kube-prometheus-stack/values.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/values.yaml @@ -70,6 +70,12 @@ prometheus: matchLabels: prometheus: kube-prometheus + ruleSelector: + matchLabels: + prometheus: kube-prometheus + + ruleNamespaceSelector: {} + serviceMonitorNamespaceSelector: {} storageSpec: diff --git a/platform/monitoring/base/networkpolicy/allow-prometheus.yaml b/platform/monitoring/base/networkpolicy/allow-prometheus.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/prometheusrules/application-latency.yaml b/platform/monitoring/base/prometheusrules/application-latency.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/prometheusrules/database-down.yaml b/platform/monitoring/base/prometheusrules/database-down.yaml deleted file mode 100644 index 3469e69..0000000 --- a/platform/monitoring/base/prometheusrules/database-down.yaml +++ /dev/null @@ -1,3 +0,0 @@ -alert: PostgresDown - -expr: pg_up == 0 \ No newline at end of file diff --git a/platform/monitoring/base/prometheusrules/deployment-unavailable.yaml b/platform/monitoring/base/prometheusrules/deployment-unavailable.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/prometheusrules/disk-pressure.yaml b/platform/monitoring/base/prometheusrules/disk-pressure.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/prometheusrules/high-cpu.yaml b/platform/monitoring/base/prometheusrules/high-cpu.yaml deleted file mode 100644 index b1667b0..0000000 --- a/platform/monitoring/base/prometheusrules/high-cpu.yaml +++ /dev/null @@ -1,29 +0,0 @@ -apiVersion: monitoring.coreos.com/v1 - -kind: PrometheusRule - -metadata: - - name: high-cpu - -spec: - - groups: - - - name: cpu - - rules: - - - alert: HighCPU - - expr: rate(container_cpu_usage_seconds_total[5m]) > 0.8 - - for: 5m - - labels: - - severity: warning - - annotations: - - summary: CPU usage is high \ No newline at end of file diff --git a/platform/monitoring/base/prometheusrules/high-memory.yaml b/platform/monitoring/base/prometheusrules/high-memory.yaml deleted file mode 100644 index 329b945..0000000 --- a/platform/monitoring/base/prometheusrules/high-memory.yaml +++ /dev/null @@ -1,52 +0,0 @@ -apiVersion: monitoring.coreos.com/v1 -kind: PrometheusRule - -metadata: - name: high-memory - namespace: monitoring - -spec: - groups: - - name: memory.rules - - rules: - - - alert: HighMemoryUsage - - expr: | - ( - container_memory_working_set_bytes{container!="",pod!=""} - / - container_spec_memory_limit_bytes{container!="",pod!=""} - ) > 0.90 - - for: 5m - - labels: - severity: warning - - annotations: - summary: "Container memory usage is high" - description: > - Container {{ $labels.container }} in pod {{ $labels.pod }} - is using more than 90% of its memory limit for over 5 minutes. - - - alert: CriticalMemoryUsage - - expr: | - ( - container_memory_working_set_bytes{container!="",pod!=""} - / - container_spec_memory_limit_bytes{container!="",pod!=""} - ) > 0.98 - - for: 2m - - labels: - severity: critical - - annotations: - summary: "Container is about to run out of memory" - description: > - Container {{ $labels.container }} in pod {{ $labels.pod }} - is consuming more than 98% of its memory limit. \ No newline at end of file diff --git a/platform/monitoring/base/prometheusrules/ingress-5xx.yaml b/platform/monitoring/base/prometheusrules/ingress-5xx.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/prometheusrules/node-not-ready.yaml b/platform/monitoring/base/prometheusrules/node-not-ready.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/prometheusrules/pod-crashloop.yaml b/platform/monitoring/base/prometheusrules/pod-crashloop.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/prometheusrules/pod-restarts.yaml b/platform/monitoring/base/prometheusrules/pod-restarts.yaml deleted file mode 100644 index 1ac8403..0000000 --- a/platform/monitoring/base/prometheusrules/pod-restarts.yaml +++ /dev/null @@ -1,21 +0,0 @@ -apiVersion: monitoring.coreos.com/v1 - -kind: PrometheusRule - -metadata: - - name: pod-restarts - -spec: - - groups: - - - name: pod - - rules: - - - alert: PodRestarting - - expr: increase(kube_pod_container_status_restarts_total[10m]) > 3 - - for: 5m \ No newline at end of file diff --git a/platform/monitoring/base/prometheusrules/postgres-connections.yaml b/platform/monitoring/base/prometheusrules/postgres-connections.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/prometheusrules/redis-down.yaml b/platform/monitoring/base/prometheusrules/redis-down.yaml deleted file mode 100644 index e69de29..0000000 From 41f8cf22f843d3aa1da9688c5c9cae777fab93a6 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 21 Jul 2026 14:06:41 +0200 Subject: [PATCH 004/122] Updated the exporter kustomization --- .../kube-prometheus-stack/exporters/kustomization.yaml | 8 ++++++++ .../base/kube-prometheus-stack/kustomization.yaml | 1 + 2 files changed, 9 insertions(+) diff --git a/platform/monitoring/base/kube-prometheus-stack/exporters/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/exporters/kustomization.yaml index e69de29..8b28dff 100644 --- a/platform/monitoring/base/kube-prometheus-stack/exporters/kustomization.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/exporters/kustomization.yaml @@ -0,0 +1,8 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - blackbox-exporter/helm-release.yaml + - postgres-exporter/helm-release.yaml + - redis-exporter/helm-release.yaml + - network-policy.yaml \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml index e745b10..e517770 100644 --- a/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml @@ -6,6 +6,7 @@ namespace: dev resources: - helm-repository.yaml - helm-release.yaml + - exporters/ - prometheusrules/ configMapGenerator: From bfee9549ac1f2bb468c5e121cab826f42e92a7dd Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 21 Jul 2026 14:17:48 +0200 Subject: [PATCH 005/122] Added recording rule --- .../recording-rules/applications.yaml | 63 +++++++++++++++++++ .../recording-rules/cluster.yaml | 35 +++++++++++ .../recording-rules/kustomization.yaml | 8 +++ .../recording-rules/nodes.yaml | 53 ++++++++++++++++ .../recording-rules/workloads.yaml | 55 ++++++++++++++++ .../base/recording-rules/applications.yaml | 0 .../base/recording-rules/cluster.yaml | 0 .../base/recording-rules/nodes.yaml | 0 .../base/recording-rules/workloads.yaml | 0 9 files changed, 214 insertions(+) create mode 100644 platform/monitoring/base/kube-prometheus-stack/recording-rules/applications.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/recording-rules/cluster.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/recording-rules/kustomization.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/recording-rules/nodes.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/recording-rules/workloads.yaml delete mode 100644 platform/monitoring/base/recording-rules/applications.yaml delete mode 100644 platform/monitoring/base/recording-rules/cluster.yaml delete mode 100644 platform/monitoring/base/recording-rules/nodes.yaml delete mode 100644 platform/monitoring/base/recording-rules/workloads.yaml diff --git a/platform/monitoring/base/kube-prometheus-stack/recording-rules/applications.yaml b/platform/monitoring/base/kube-prometheus-stack/recording-rules/applications.yaml new file mode 100644 index 0000000..03f2f99 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/recording-rules/applications.yaml @@ -0,0 +1,63 @@ +apiVersion: monitoring.coreos.com/v1 +kind: PrometheusRule + +metadata: + name: application-recording-rules + namespace: dev + + labels: + prometheus: kube-prometheus + +spec: + + groups: + + - name: application.recording.rules + + interval: 30s + + rules: + + - record: app:http_requests:rate5m + + expr: | + sum by( + application + ) + ( + rate( + http_server_requests_seconds_count[5m] + ) + ) + + + - record: app:http_errors:rate5m + + expr: | + sum by( + application + ) + ( + rate( + http_server_requests_seconds_count{ + status=~"5.." + }[5m] + ) + ) + + + - record: app:http_latency:p95 + + expr: | + histogram_quantile( + 0.95, + sum by( + application, + le + ) + ( + rate( + http_server_requests_seconds_bucket[5m] + ) + ) + ) \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/recording-rules/cluster.yaml b/platform/monitoring/base/kube-prometheus-stack/recording-rules/cluster.yaml new file mode 100644 index 0000000..f3f8963 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/recording-rules/cluster.yaml @@ -0,0 +1,35 @@ +apiVersion: monitoring.coreos.com/v1 +kind: PrometheusRule + +metadata: + name: cluster-recording-rules + namespace: dev + labels: + prometheus: kube-prometheus + +spec: + groups: + - name: cluster.recording.rules + interval: 30s + + rules: + + - record: cluster:cpu_usage:ratio + + expr: | + 1 - + avg( + rate(node_cpu_seconds_total{ + mode="idle" + }[5m]) + ) + + - record: cluster:memory_usage:ratio + + expr: | + 1 - + ( + sum(node_memory_MemAvailable_bytes) + / + sum(node_memory_MemTotal_bytes) + ) \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/recording-rules/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/recording-rules/kustomization.yaml new file mode 100644 index 0000000..ad0e211 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/recording-rules/kustomization.yaml @@ -0,0 +1,8 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - cluster.yaml + - nodes.yaml + - workloads.yaml + - applications.yaml \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/recording-rules/nodes.yaml b/platform/monitoring/base/kube-prometheus-stack/recording-rules/nodes.yaml new file mode 100644 index 0000000..eb8ea38 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/recording-rules/nodes.yaml @@ -0,0 +1,53 @@ +apiVersion: monitoring.coreos.com/v1 +kind: PrometheusRule + +metadata: + name: node-recording-rules + namespace: dev + + labels: + prometheus: kube-prometheus + +spec: + groups: + + - name: node.recording.rules + + interval: 30s + + rules: + + - record: node:cpu_usage:ratio + + expr: | + 1 - + avg by(instance) + ( + rate( + node_cpu_seconds_total{ + mode="idle" + }[5m] + ) + ) + + + - record: node:memory_usage:ratio + + expr: | + 1 - + ( + node_memory_MemAvailable_bytes + / + node_memory_MemTotal_bytes + ) + + + - record: node:disk_usage:ratio + + expr: | + 1 - + ( + node_filesystem_avail_bytes + / + node_filesystem_size_bytes + ) \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/recording-rules/workloads.yaml b/platform/monitoring/base/kube-prometheus-stack/recording-rules/workloads.yaml new file mode 100644 index 0000000..35b759f --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/recording-rules/workloads.yaml @@ -0,0 +1,55 @@ +apiVersion: monitoring.coreos.com/v1 +kind: PrometheusRule + +metadata: + name: workload-recording-rules + namespace: dev + + labels: + prometheus: kube-prometheus + +spec: + + groups: + + - name: workload.recording.rules + + interval: 30s + + rules: + + - record: namespace:pod_cpu_usage:sum + + expr: | + sum by(namespace) + ( + rate( + container_cpu_usage_seconds_total{ + container!="", + image!="" + }[5m] + ) + ) + + + - record: namespace:memory_usage_bytes:sum + + expr: | + sum by(namespace) + ( + container_memory_working_set_bytes{ + container!="", + image!="" + } + ) + + + - record: namespace:pod_restarts:rate + + expr: | + sum by(namespace) + ( + rate( + kube_pod_container_status_restarts_total[15m] + ) + ) \ No newline at end of file diff --git a/platform/monitoring/base/recording-rules/applications.yaml b/platform/monitoring/base/recording-rules/applications.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/recording-rules/cluster.yaml b/platform/monitoring/base/recording-rules/cluster.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/recording-rules/nodes.yaml b/platform/monitoring/base/recording-rules/nodes.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/recording-rules/workloads.yaml b/platform/monitoring/base/recording-rules/workloads.yaml deleted file mode 100644 index e69de29..0000000 From 5547ee57b2bdde2267bf37933cccdac776c39633 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 21 Jul 2026 14:33:56 +0200 Subject: [PATCH 006/122] Added service monitors --- .../kube-prometheus-stack/kustomization.yaml | 1 + .../aws-load-balancer-controller.yaml.yaml | 18 ++++++++++++++ .../servicemonitors/kustomization.yaml | 10 ++++++++ .../servicemonitors/order.yaml | 0 .../servicemonitors/payment.yaml | 24 ++++++------------- .../servicemonitors/product.yaml | 24 ++++++------------- .../servicemonitors/redis.yaml | 18 ++++++++++++++ .../servicemonitors/user.yaml | 24 ++++++------------- .../base/servicemonitors/ingress-nginx.yaml | 0 .../base/servicemonitors/postgres.yaml | 0 .../base/servicemonitors/redis.yaml | 0 11 files changed, 68 insertions(+), 51 deletions(-) create mode 100644 platform/monitoring/base/kube-prometheus-stack/servicemonitors/aws-load-balancer-controller.yaml.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/servicemonitors/kustomization.yaml rename platform/monitoring/base/{ => kube-prometheus-stack}/servicemonitors/order.yaml (100%) rename platform/monitoring/base/{ => kube-prometheus-stack}/servicemonitors/payment.yaml (57%) rename platform/monitoring/base/{ => kube-prometheus-stack}/servicemonitors/product.yaml (57%) create mode 100644 platform/monitoring/base/kube-prometheus-stack/servicemonitors/redis.yaml rename platform/monitoring/base/{ => kube-prometheus-stack}/servicemonitors/user.yaml (56%) delete mode 100644 platform/monitoring/base/servicemonitors/ingress-nginx.yaml delete mode 100644 platform/monitoring/base/servicemonitors/postgres.yaml delete mode 100644 platform/monitoring/base/servicemonitors/redis.yaml diff --git a/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml index e517770..4e310bc 100644 --- a/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml @@ -8,6 +8,7 @@ resources: - helm-release.yaml - exporters/ - prometheusrules/ + - servicemonitors/ configMapGenerator: - name: prometheus-stack-values diff --git a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/aws-load-balancer-controller.yaml.yaml b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/aws-load-balancer-controller.yaml.yaml new file mode 100644 index 0000000..9423023 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/aws-load-balancer-controller.yaml.yaml @@ -0,0 +1,18 @@ +apiVersion: monitoring.coreos.com/v1 +kind: ServiceMonitor + +metadata: + name: aws-load-balancer-controller + namespace: kube-system + + labels: + prometheus: kube-prometheus + +spec: + selector: + matchLabels: + app.kubernetes.io/name: aws-load-balancer-controller + + endpoints: + - port: metrics + interval: 30s \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/kustomization.yaml new file mode 100644 index 0000000..7d91be0 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/kustomization.yaml @@ -0,0 +1,10 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - order.yaml + - user.yaml + - payment.yaml + - product.yaml + - redis.yaml + - aws-load-balancer-controller.yaml \ No newline at end of file diff --git a/platform/monitoring/base/servicemonitors/order.yaml b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/order.yaml similarity index 100% rename from platform/monitoring/base/servicemonitors/order.yaml rename to platform/monitoring/base/kube-prometheus-stack/servicemonitors/order.yaml diff --git a/platform/monitoring/base/servicemonitors/payment.yaml b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/payment.yaml similarity index 57% rename from platform/monitoring/base/servicemonitors/payment.yaml rename to platform/monitoring/base/kube-prometheus-stack/servicemonitors/payment.yaml index bd4e3e9..4f491fe 100644 --- a/platform/monitoring/base/servicemonitors/payment.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/payment.yaml @@ -1,29 +1,19 @@ apiVersion: monitoring.coreos.com/v1 - kind: ServiceMonitor metadata: - name: payment-service + namespace: dev -spec: + labels: + prometheus: kube-prometheus +spec: selector: - matchLabels: - app: payment-service - namespaceSelector: - - matchNames: - - - payment - endpoints: - - - port: http - - path: /actuator/prometheus - - interval: 15s \ No newline at end of file + - port: http + path: /actuator/prometheus + interval: 30s \ No newline at end of file diff --git a/platform/monitoring/base/servicemonitors/product.yaml b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/product.yaml similarity index 57% rename from platform/monitoring/base/servicemonitors/product.yaml rename to platform/monitoring/base/kube-prometheus-stack/servicemonitors/product.yaml index 74dcff8..d8c5676 100644 --- a/platform/monitoring/base/servicemonitors/product.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/product.yaml @@ -1,29 +1,19 @@ apiVersion: monitoring.coreos.com/v1 - kind: ServiceMonitor metadata: - name: product-service + namespace: dev -spec: + labels: + prometheus: kube-prometheus +spec: selector: - matchLabels: - app: product-service - namespaceSelector: - - matchNames: - - - product - endpoints: - - - port: http - - path: /actuator/prometheus - - interval: 15s \ No newline at end of file + - port: http + path: /actuator/prometheus + interval: 30s \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/redis.yaml b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/redis.yaml new file mode 100644 index 0000000..a9494e6 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/redis.yaml @@ -0,0 +1,18 @@ +apiVersion: monitoring.coreos.com/v1 +kind: ServiceMonitor + +metadata: + name: redis + namespace: dev + + labels: + prometheus: kube-prometheus + +spec: + selector: + matchLabels: + app: redis-exporter + + endpoints: + - port: metrics + interval: 30s \ No newline at end of file diff --git a/platform/monitoring/base/servicemonitors/user.yaml b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/user.yaml similarity index 56% rename from platform/monitoring/base/servicemonitors/user.yaml rename to platform/monitoring/base/kube-prometheus-stack/servicemonitors/user.yaml index e4fe13d..6679d6c 100644 --- a/platform/monitoring/base/servicemonitors/user.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/user.yaml @@ -1,29 +1,19 @@ apiVersion: monitoring.coreos.com/v1 - kind: ServiceMonitor metadata: - name: user-service + namespace: dev -spec: + labels: + prometheus: kube-prometheus +spec: selector: - matchLabels: - app: user-service - namespaceSelector: - - matchNames: - - - user - endpoints: - - - port: http - - path: /actuator/prometheus - - interval: 15s \ No newline at end of file + - port: http + path: /actuator/prometheus + interval: 30s \ No newline at end of file diff --git a/platform/monitoring/base/servicemonitors/ingress-nginx.yaml b/platform/monitoring/base/servicemonitors/ingress-nginx.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/servicemonitors/postgres.yaml b/platform/monitoring/base/servicemonitors/postgres.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/monitoring/base/servicemonitors/redis.yaml b/platform/monitoring/base/servicemonitors/redis.yaml deleted file mode 100644 index e69de29..0000000 From 4cbeb786551f66ca32f415f2569663d88a505265 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 21 Jul 2026 14:58:18 +0200 Subject: [PATCH 007/122] Updated the namespace --- .../alertmanager/external-secret.yaml | 1 - .../blackbox-exporter/helm-release.yaml | 1 - .../exporters/network-policy.yaml | 3 +-- .../postgres-exporter/helm-release.yaml | 1 - .../redis-exporter/helm-release.yaml | 1 - .../external-secret.yaml | 1 - .../kube-prometheus-stack/helm-release.yaml | 2 +- .../kube-prometheus-stack/kustomization.yaml | 2 -- .../prometheusrules/applications.yaml | 1 - .../prometheusrules/databases.yaml | 1 - .../prometheusrules/ingress.yaml | 1 - .../prometheusrules/kubernetes.yaml | 1 - .../prometheusrules/nodes.yaml | 1 - .../prometheusrules/redis.yaml | 1 - .../recording-rules/applications.yaml | 1 - .../recording-rules/cluster.yaml | 2 +- .../recording-rules/nodes.yaml | 1 - .../recording-rules/workloads.yaml | 1 - .../aws-load-balancer-controller.yaml.yaml | 4 +++ .../servicemonitors/order.yaml | 1 - .../servicemonitors/payment.yaml | 1 - .../servicemonitors/product.yaml | 1 - .../servicemonitors/redis.yaml | 1 - .../servicemonitors/user.yaml | 1 - platform/monitoring/base/kustomization.yaml | 27 +------------------ .../overlays/dev/kustomization.yaml | 8 +++--- .../dev/monitoring.yaml} | 2 +- .../monitoring/overlays/dev/values-patch.yaml | 11 -------- 28 files changed, 13 insertions(+), 67 deletions(-) rename platform/monitoring/{base/namespace.yaml => overlays/dev/monitoring.yaml} (70%) delete mode 100644 platform/monitoring/overlays/dev/values-patch.yaml diff --git a/platform/monitoring/base/kube-prometheus-stack/alertmanager/external-secret.yaml b/platform/monitoring/base/kube-prometheus-stack/alertmanager/external-secret.yaml index a82f14b..788af79 100644 --- a/platform/monitoring/base/kube-prometheus-stack/alertmanager/external-secret.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/alertmanager/external-secret.yaml @@ -2,7 +2,6 @@ apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: alertmanager-notification-secret - namespace: dev spec: refreshInterval: 1h diff --git a/platform/monitoring/base/kube-prometheus-stack/exporters/blackbox-exporter/helm-release.yaml b/platform/monitoring/base/kube-prometheus-stack/exporters/blackbox-exporter/helm-release.yaml index 7061cf7..ea5ae0e 100644 --- a/platform/monitoring/base/kube-prometheus-stack/exporters/blackbox-exporter/helm-release.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/exporters/blackbox-exporter/helm-release.yaml @@ -3,7 +3,6 @@ kind: HelmRelease metadata: name: blackbox-exporter - namespace: dev spec: interval: 30m diff --git a/platform/monitoring/base/kube-prometheus-stack/exporters/network-policy.yaml b/platform/monitoring/base/kube-prometheus-stack/exporters/network-policy.yaml index 55fcabf..d764953 100644 --- a/platform/monitoring/base/kube-prometheus-stack/exporters/network-policy.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/exporters/network-policy.yaml @@ -3,7 +3,6 @@ kind: NetworkPolicy metadata: name: allow-prometheus - namespace: dev spec: podSelector: @@ -17,7 +16,7 @@ spec: - from: - namespaceSelector: matchLabels: - kubernetes.io/metadata.name: dev + kubernetes.io/metadata.name: monitoring podSelector: matchLabels: diff --git a/platform/monitoring/base/kube-prometheus-stack/exporters/postgres-exporter/helm-release.yaml b/platform/monitoring/base/kube-prometheus-stack/exporters/postgres-exporter/helm-release.yaml index b3318f4..dda11d3 100644 --- a/platform/monitoring/base/kube-prometheus-stack/exporters/postgres-exporter/helm-release.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/exporters/postgres-exporter/helm-release.yaml @@ -3,7 +3,6 @@ kind: HelmRelease metadata: name: postgres-exporter - namespace: dev spec: interval: 30m diff --git a/platform/monitoring/base/kube-prometheus-stack/exporters/redis-exporter/helm-release.yaml b/platform/monitoring/base/kube-prometheus-stack/exporters/redis-exporter/helm-release.yaml index a4a8d15..847c661 100644 --- a/platform/monitoring/base/kube-prometheus-stack/exporters/redis-exporter/helm-release.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/exporters/redis-exporter/helm-release.yaml @@ -3,7 +3,6 @@ kind: HelmRelease metadata: name: redis-exporter - namespace: dev spec: interval: 30m diff --git a/platform/monitoring/base/kube-prometheus-stack/external-secret.yaml b/platform/monitoring/base/kube-prometheus-stack/external-secret.yaml index ccf18bd..fe22588 100644 --- a/platform/monitoring/base/kube-prometheus-stack/external-secret.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/external-secret.yaml @@ -2,7 +2,6 @@ apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: grafana-admin - namespace: dev spec: refreshInterval: 1h diff --git a/platform/monitoring/base/kube-prometheus-stack/helm-release.yaml b/platform/monitoring/base/kube-prometheus-stack/helm-release.yaml index bed1602..79d42f1 100644 --- a/platform/monitoring/base/kube-prometheus-stack/helm-release.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/helm-release.yaml @@ -2,7 +2,7 @@ apiVersion: helm.toolkit.fluxcd.io/v2 kind: HelmRelease metadata: name: prometheus-stack - namespace: dev + spec: interval: 30m diff --git a/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml index 4e310bc..5b41961 100644 --- a/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml @@ -1,8 +1,6 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization -namespace: dev - resources: - helm-repository.yaml - helm-release.yaml diff --git a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/applications.yaml b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/applications.yaml index b9cb62f..2b7b4cf 100644 --- a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/applications.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/applications.yaml @@ -3,7 +3,6 @@ kind: PrometheusRule metadata: name: application-alerts - namespace: dev labels: prometheus: kube-prometheus diff --git a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/databases.yaml b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/databases.yaml index 6c9135d..91cf141 100644 --- a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/databases.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/databases.yaml @@ -3,7 +3,6 @@ kind: PrometheusRule metadata: name: database-alerts - namespace: dev labels: prometheus: kube-prometheus diff --git a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/ingress.yaml b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/ingress.yaml index e7c09fc..c81eaba 100644 --- a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/ingress.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/ingress.yaml @@ -3,7 +3,6 @@ kind: PrometheusRule metadata: name: ingress-alerts - namespace: dev labels: prometheus: kube-prometheus diff --git a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/kubernetes.yaml b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/kubernetes.yaml index 94bca1c..3270645 100644 --- a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/kubernetes.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/kubernetes.yaml @@ -3,7 +3,6 @@ kind: PrometheusRule metadata: name: kubernetes-alerts - namespace: dev labels: prometheus: kube-prometheus diff --git a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/nodes.yaml b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/nodes.yaml index 23bb86b..7377c57 100644 --- a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/nodes.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/nodes.yaml @@ -3,7 +3,6 @@ kind: PrometheusRule metadata: name: node-alerts - namespace: dev labels: prometheus: kube-prometheus diff --git a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/redis.yaml b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/redis.yaml index a7a0374..9603e76 100644 --- a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/redis.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/redis.yaml @@ -3,7 +3,6 @@ kind: PrometheusRule metadata: name: redis-alerts - namespace: dev labels: prometheus: kube-prometheus diff --git a/platform/monitoring/base/kube-prometheus-stack/recording-rules/applications.yaml b/platform/monitoring/base/kube-prometheus-stack/recording-rules/applications.yaml index 03f2f99..d331095 100644 --- a/platform/monitoring/base/kube-prometheus-stack/recording-rules/applications.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/recording-rules/applications.yaml @@ -3,7 +3,6 @@ kind: PrometheusRule metadata: name: application-recording-rules - namespace: dev labels: prometheus: kube-prometheus diff --git a/platform/monitoring/base/kube-prometheus-stack/recording-rules/cluster.yaml b/platform/monitoring/base/kube-prometheus-stack/recording-rules/cluster.yaml index f3f8963..c26285b 100644 --- a/platform/monitoring/base/kube-prometheus-stack/recording-rules/cluster.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/recording-rules/cluster.yaml @@ -3,7 +3,7 @@ kind: PrometheusRule metadata: name: cluster-recording-rules - namespace: dev + labels: prometheus: kube-prometheus diff --git a/platform/monitoring/base/kube-prometheus-stack/recording-rules/nodes.yaml b/platform/monitoring/base/kube-prometheus-stack/recording-rules/nodes.yaml index eb8ea38..473cb93 100644 --- a/platform/monitoring/base/kube-prometheus-stack/recording-rules/nodes.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/recording-rules/nodes.yaml @@ -3,7 +3,6 @@ kind: PrometheusRule metadata: name: node-recording-rules - namespace: dev labels: prometheus: kube-prometheus diff --git a/platform/monitoring/base/kube-prometheus-stack/recording-rules/workloads.yaml b/platform/monitoring/base/kube-prometheus-stack/recording-rules/workloads.yaml index 35b759f..14fe165 100644 --- a/platform/monitoring/base/kube-prometheus-stack/recording-rules/workloads.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/recording-rules/workloads.yaml @@ -3,7 +3,6 @@ kind: PrometheusRule metadata: name: workload-recording-rules - namespace: dev labels: prometheus: kube-prometheus diff --git a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/aws-load-balancer-controller.yaml.yaml b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/aws-load-balancer-controller.yaml.yaml index 9423023..62a4311 100644 --- a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/aws-load-balancer-controller.yaml.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/aws-load-balancer-controller.yaml.yaml @@ -13,6 +13,10 @@ spec: matchLabels: app.kubernetes.io/name: aws-load-balancer-controller + namespaceSelector: + matchNames: + - kube-system + endpoints: - port: metrics interval: 30s \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/order.yaml b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/order.yaml index ed92a33..00dfd2b 100644 --- a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/order.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/order.yaml @@ -3,7 +3,6 @@ kind: ServiceMonitor metadata: name: order-service - namespace: dev labels: prometheus: kube-prometheus diff --git a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/payment.yaml b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/payment.yaml index 4f491fe..c779c08 100644 --- a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/payment.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/payment.yaml @@ -3,7 +3,6 @@ kind: ServiceMonitor metadata: name: payment-service - namespace: dev labels: prometheus: kube-prometheus diff --git a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/product.yaml b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/product.yaml index d8c5676..57369e5 100644 --- a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/product.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/product.yaml @@ -3,7 +3,6 @@ kind: ServiceMonitor metadata: name: product-service - namespace: dev labels: prometheus: kube-prometheus diff --git a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/redis.yaml b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/redis.yaml index a9494e6..2e02e0e 100644 --- a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/redis.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/redis.yaml @@ -3,7 +3,6 @@ kind: ServiceMonitor metadata: name: redis - namespace: dev labels: prometheus: kube-prometheus diff --git a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/user.yaml b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/user.yaml index 6679d6c..63b3906 100644 --- a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/user.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/user.yaml @@ -3,7 +3,6 @@ kind: ServiceMonitor metadata: name: user-service - namespace: dev labels: prometheus: kube-prometheus diff --git a/platform/monitoring/base/kustomization.yaml b/platform/monitoring/base/kustomization.yaml index 80f1cc0..f9f2ceb 100644 --- a/platform/monitoring/base/kustomization.yaml +++ b/platform/monitoring/base/kustomization.yaml @@ -1,31 +1,6 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization -namespace: monitoring resources: - - namespace.yaml - - # ServiceMonitors - - servicemonitors/user.yaml - - servicemonitors/order.yaml - - servicemonitors/payment.yaml - - servicemonitors/product.yaml - - # Alert Rules - - prometheusrules/high-cpu.yaml - - prometheusrules/high-memory.yaml - - prometheusrules/pod-restarts.yaml - - prometheusrules/database-down.yaml - -configMapGenerator: - - name: grafana-dashboards - files: - - grafana-dashboards/kubernetes.json - - grafana-dashboards/jvm.json - - grafana-dashboards/postgres.json - - grafana-dashboards/predis.json - - grafana-dashboards/springboot.json - -generatorOptions: - disableNameSuffixHash: true \ No newline at end of file + - kube-prometheus-stack \ No newline at end of file diff --git a/platform/monitoring/overlays/dev/kustomization.yaml b/platform/monitoring/overlays/dev/kustomization.yaml index 43e54ee..ef66e29 100644 --- a/platform/monitoring/overlays/dev/kustomization.yaml +++ b/platform/monitoring/overlays/dev/kustomization.yaml @@ -1,8 +1,8 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization -resources: - - ../../base +namespace: dev -patches: - - path: values-patch.yaml \ No newline at end of file +resources: + - monitoring.yaml + - ../../base \ No newline at end of file diff --git a/platform/monitoring/base/namespace.yaml b/platform/monitoring/overlays/dev/monitoring.yaml similarity index 70% rename from platform/monitoring/base/namespace.yaml rename to platform/monitoring/overlays/dev/monitoring.yaml index f52192b..0b345a8 100644 --- a/platform/monitoring/base/namespace.yaml +++ b/platform/monitoring/overlays/dev/monitoring.yaml @@ -2,4 +2,4 @@ apiVersion: v1 kind: Namespace metadata: - name: monitoring \ No newline at end of file + name: dev \ No newline at end of file diff --git a/platform/monitoring/overlays/dev/values-patch.yaml b/platform/monitoring/overlays/dev/values-patch.yaml deleted file mode 100644 index 969319b..0000000 --- a/platform/monitoring/overlays/dev/values-patch.yaml +++ /dev/null @@ -1,11 +0,0 @@ -grafana: - - persistence: - - size: 5Gi - -prometheus: - - prometheusSpec: - - retention: 5d \ No newline at end of file From e4425c003efe55a4d843b085887b4423f769b7a3 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 21 Jul 2026 15:45:07 +0200 Subject: [PATCH 008/122] Added logging --- .../logging/base/fluent-bit/helm-release.yaml | 18 +++++++ .../base/fluent-bit/kustomization.yaml | 6 +++ platform/logging/base/fluent-bit/values.yaml | 32 ++++++++++++ platform/logging/base/kustomization.yaml | 7 +++ .../networkpolicy/allow-logging.yaml | 0 .../logging/base/log-retention/retention.yaml | 0 platform/logging/base/loki/helm-release.yaml | 38 ++++++++++++++ platform/logging/base/loki/kustomization.yaml | 6 +++ platform/logging/base/loki/values.yaml | 50 +++++++++++++++++++ platform/logging/base/namespace.yaml | 0 .../base/networkpolicy/allow-logging.yaml | 32 ++++++++++++ .../base/networkpolicy/kustomization.yaml | 5 ++ .../logging/overlay/dev/kustomization.yaml | 8 +++ platform/logging/overlay/dev/namespace.yaml | 5 ++ .../base/kube-prometheus-stack/values.yaml | 6 +++ 15 files changed, 213 insertions(+) create mode 100644 platform/logging/base/fluent-bit/kustomization.yaml delete mode 100644 platform/logging/base/log-retention/networkpolicy/allow-logging.yaml delete mode 100644 platform/logging/base/log-retention/retention.yaml create mode 100644 platform/logging/base/loki/kustomization.yaml delete mode 100644 platform/logging/base/namespace.yaml create mode 100644 platform/logging/base/networkpolicy/allow-logging.yaml create mode 100644 platform/logging/base/networkpolicy/kustomization.yaml create mode 100644 platform/logging/overlay/dev/kustomization.yaml create mode 100644 platform/logging/overlay/dev/namespace.yaml diff --git a/platform/logging/base/fluent-bit/helm-release.yaml b/platform/logging/base/fluent-bit/helm-release.yaml index e69de29..e7676cc 100644 --- a/platform/logging/base/fluent-bit/helm-release.yaml +++ b/platform/logging/base/fluent-bit/helm-release.yaml @@ -0,0 +1,18 @@ +apiVersion: helm.toolkit.fluxcd.io/v2 + +kind: HelmRelease + +metadata: + name: fluent-bit + +spec: + interval: 30m + + chart: + spec: + chart: fluent-bit + version: "0.x" + sourceRef: + kind: HelmRepository + name: fluent + namespace: flux-system \ No newline at end of file diff --git a/platform/logging/base/fluent-bit/kustomization.yaml b/platform/logging/base/fluent-bit/kustomization.yaml new file mode 100644 index 0000000..bcd1ac0 --- /dev/null +++ b/platform/logging/base/fluent-bit/kustomization.yaml @@ -0,0 +1,6 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - helm-release.yaml + - values.yaml \ No newline at end of file diff --git a/platform/logging/base/fluent-bit/values.yaml b/platform/logging/base/fluent-bit/values.yaml index e69de29..78474fc 100644 --- a/platform/logging/base/fluent-bit/values.yaml +++ b/platform/logging/base/fluent-bit/values.yaml @@ -0,0 +1,32 @@ +config: + + service: | + [SERVICE] + Flush 5 + Log_Level info + Parsers_File parsers.conf + + + inputs: | + [INPUT] + Name tail + Path /var/log/containers/*.log + Parser docker + Tag kube.* + + + filters: | + [FILTER] + Name kubernetes + Match kube.* + Merge_Log On + Keep_Log Off + + + outputs: | + [OUTPUT] + Name loki + Match * + Host loki.logging.svc.cluster.local + Port 3100 + Labels job=fluent-bit \ No newline at end of file diff --git a/platform/logging/base/kustomization.yaml b/platform/logging/base/kustomization.yaml index e69de29..6639f07 100644 --- a/platform/logging/base/kustomization.yaml +++ b/platform/logging/base/kustomization.yaml @@ -0,0 +1,7 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - fluent-bit/ + - loki/ + - networkpolicy/ diff --git a/platform/logging/base/log-retention/networkpolicy/allow-logging.yaml b/platform/logging/base/log-retention/networkpolicy/allow-logging.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/logging/base/log-retention/retention.yaml b/platform/logging/base/log-retention/retention.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/logging/base/loki/helm-release.yaml b/platform/logging/base/loki/helm-release.yaml index e69de29..358e747 100644 --- a/platform/logging/base/loki/helm-release.yaml +++ b/platform/logging/base/loki/helm-release.yaml @@ -0,0 +1,38 @@ +apiVersion: helm.toolkit.fluxcd.io/v2 + +kind: HelmRelease + +metadata: + name: loki + +spec: + interval: 30m + + chart: + spec: + chart: loki + version: "6.x" + sourceRef: + kind: HelmRepository + name: grafana + namespace: flux-system + + values: + deploymentMode: SingleBinary + + loki: + auth_enabled: false + + commonConfig: + replication_factor: 1 + + storage: + type: filesystem + + singleBinary: + replicas: 1 + + persistence: + enabled: true + storageClass: gp3 + size: 50Gi \ No newline at end of file diff --git a/platform/logging/base/loki/kustomization.yaml b/platform/logging/base/loki/kustomization.yaml new file mode 100644 index 0000000..bcd1ac0 --- /dev/null +++ b/platform/logging/base/loki/kustomization.yaml @@ -0,0 +1,6 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - helm-release.yaml + - values.yaml \ No newline at end of file diff --git a/platform/logging/base/loki/values.yaml b/platform/logging/base/loki/values.yaml index e69de29..c455ca4 100644 --- a/platform/logging/base/loki/values.yaml +++ b/platform/logging/base/loki/values.yaml @@ -0,0 +1,50 @@ +deploymentMode: SingleBinary + +singleBinary: + replicas: 1 + +loki: + auth_enabled: false + + commonConfig: + replication_factor: 1 + + schemaConfig: + configs: + - from: "2024-01-01" + store: tsdb + object_store: filesystem + schema: v13 + index: + prefix: loki_index_ + period: 24h + + storage: + type: filesystem + + limits_config: + retention_period: 30d + + compactor: + retention_enabled: true + working_directory: /var/loki/retention + + server: + http_listen_port: 3100 + + analytics: + reporting_enabled: false + + pattern_ingester: + enabled: false + +persistence: + enabled: true + storageClassName: gp3 + size: 50Gi + +monitoring: + serviceMonitor: + enabled: true + labels: + prometheus: kube-prometheus \ No newline at end of file diff --git a/platform/logging/base/namespace.yaml b/platform/logging/base/namespace.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/logging/base/networkpolicy/allow-logging.yaml b/platform/logging/base/networkpolicy/allow-logging.yaml new file mode 100644 index 0000000..64d2065 --- /dev/null +++ b/platform/logging/base/networkpolicy/allow-logging.yaml @@ -0,0 +1,32 @@ +apiVersion: networking.k8s.io/v1 + +kind: NetworkPolicy + +metadata: + name: allow-logging + +spec: + + podSelector: + matchLabels: + app.kubernetes.io/name: loki + + policyTypes: + - Ingress + + ingress: + + - from: + + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: logging + + podSelector: + matchLabels: + app.kubernetes.io/name: fluent-bit + + ports: + + - protocol: TCP + port: 3100 \ No newline at end of file diff --git a/platform/logging/base/networkpolicy/kustomization.yaml b/platform/logging/base/networkpolicy/kustomization.yaml new file mode 100644 index 0000000..042d93c --- /dev/null +++ b/platform/logging/base/networkpolicy/kustomization.yaml @@ -0,0 +1,5 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - allow-logging.yaml \ No newline at end of file diff --git a/platform/logging/overlay/dev/kustomization.yaml b/platform/logging/overlay/dev/kustomization.yaml new file mode 100644 index 0000000..ef66e29 --- /dev/null +++ b/platform/logging/overlay/dev/kustomization.yaml @@ -0,0 +1,8 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +namespace: dev + +resources: + - monitoring.yaml + - ../../base \ No newline at end of file diff --git a/platform/logging/overlay/dev/namespace.yaml b/platform/logging/overlay/dev/namespace.yaml new file mode 100644 index 0000000..0b345a8 --- /dev/null +++ b/platform/logging/overlay/dev/namespace.yaml @@ -0,0 +1,5 @@ +apiVersion: v1 +kind: Namespace + +metadata: + name: dev \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/values.yaml b/platform/monitoring/base/kube-prometheus-stack/values.yaml index cd8dbef..7b72927 100644 --- a/platform/monitoring/base/kube-prometheus-stack/values.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/values.yaml @@ -14,6 +14,12 @@ grafana: storageClassName: gp3 size: 20Gi + additionalDataSources: + - name: Loki + type: loki + access: proxy + url: http://loki.logging.svc.cluster.local:3100 + defaultDashboardsEnabled: true sidecar: From 2dc1f4bc05aa5045bd371988f71fd2449150fd8d Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 21 Jul 2026 16:58:50 +0200 Subject: [PATCH 009/122] Added ingress for observability --- .../helm-release.yaml | 30 +++++++++++++++++++ .../helm-repository.yaml | 10 +++++++ .../kustomization.yaml} | 0 .../aws-load-balancer-controller/value.yaml | 17 +++++++++++ .../clusterissuers/letsencrypt.yaml | 19 ++++++++++++ .../base/cert-manager/helm-release.yaml | 28 +++++++++++++++++ .../base/cert-manager/helm-repository.yaml | 10 +++++++ ...ncrypt-staging.yaml => kustomization.yaml} | 0 .../ingress/base/cert-manager/values.yaml | 11 +++++++ .../base/external-dns/helm-release.yaml | 30 +++++++++++++++++++ .../base/external-dns/helm-repository.yaml | 10 +++++++ .../kustomization.yaml} | 0 .../ingress/base/external-dns/values.yaml | 19 ++++++++++++ .../ingress/base/ingress-nginx/values.yaml | 0 platform/ingress/base/kustomization.yaml | 7 +++++ platform/ingress/base/namespace.yaml | 0 .../ingress/overlay/dev/flux/ingress.yaml | 27 +++++++++++++++++ .../overlay/dev/ingress-namespace.yaml | 5 ++++ .../ingress/overlay/dev/kustomization.yaml | 11 +++++++ 19 files changed, 234 insertions(+) create mode 100644 platform/ingress/base/aws-load-balancer-controller/helm-repository.yaml rename platform/ingress/base/{cert-manager/clusterissuers/letsencrypt-prod.yaml => aws-load-balancer-controller/kustomization.yaml} (100%) create mode 100644 platform/ingress/base/cert-manager/clusterissuers/letsencrypt.yaml create mode 100644 platform/ingress/base/cert-manager/helm-repository.yaml rename platform/ingress/base/cert-manager/{clusterissuers/letsencrypt-staging.yaml => kustomization.yaml} (100%) create mode 100644 platform/ingress/base/external-dns/helm-repository.yaml rename platform/ingress/base/{ingress-nginx/helm-release.yaml => external-dns/kustomization.yaml} (100%) delete mode 100644 platform/ingress/base/ingress-nginx/values.yaml delete mode 100644 platform/ingress/base/namespace.yaml create mode 100644 platform/ingress/overlay/dev/flux/ingress.yaml create mode 100644 platform/ingress/overlay/dev/ingress-namespace.yaml create mode 100644 platform/ingress/overlay/dev/kustomization.yaml diff --git a/platform/ingress/base/aws-load-balancer-controller/helm-release.yaml b/platform/ingress/base/aws-load-balancer-controller/helm-release.yaml index e69de29..9a103f5 100644 --- a/platform/ingress/base/aws-load-balancer-controller/helm-release.yaml +++ b/platform/ingress/base/aws-load-balancer-controller/helm-release.yaml @@ -0,0 +1,30 @@ +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease + +metadata: + name: aws-load-balancer-controller + +spec: + interval: 30m + + chart: + spec: + chart: aws-load-balancer-controller + version: "1.13.4" + sourceRef: + kind: HelmRepository + name: eks + namespace: flux-system + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + valuesFrom: + - kind: ConfigMap + name: aws-load-balancer-controller-values + valuesKey: values.yaml \ No newline at end of file diff --git a/platform/ingress/base/aws-load-balancer-controller/helm-repository.yaml b/platform/ingress/base/aws-load-balancer-controller/helm-repository.yaml new file mode 100644 index 0000000..6a35e29 --- /dev/null +++ b/platform/ingress/base/aws-load-balancer-controller/helm-repository.yaml @@ -0,0 +1,10 @@ +apiVersion: source.toolkit.fluxcd.io/v1 +kind: HelmRepository + +metadata: + name: eks + namespace: flux-system + +spec: + interval: 24h + url: https://aws.github.io/eks-charts \ No newline at end of file diff --git a/platform/ingress/base/cert-manager/clusterissuers/letsencrypt-prod.yaml b/platform/ingress/base/aws-load-balancer-controller/kustomization.yaml similarity index 100% rename from platform/ingress/base/cert-manager/clusterissuers/letsencrypt-prod.yaml rename to platform/ingress/base/aws-load-balancer-controller/kustomization.yaml diff --git a/platform/ingress/base/aws-load-balancer-controller/value.yaml b/platform/ingress/base/aws-load-balancer-controller/value.yaml index e69de29..9a9a481 100644 --- a/platform/ingress/base/aws-load-balancer-controller/value.yaml +++ b/platform/ingress/base/aws-load-balancer-controller/value.yaml @@ -0,0 +1,17 @@ +clusterName: ${CLUSTER_NAME} + +region: ${AWS_REGION} + +vpcId: ${VPC_ID} + +serviceAccount: + create: true + name: aws-load-balancer-controller + +replicaCount: 2 + +metrics: + serviceMonitor: + enabled: true + additionalLabels: + prometheus: kube-prometheus \ No newline at end of file diff --git a/platform/ingress/base/cert-manager/clusterissuers/letsencrypt.yaml b/platform/ingress/base/cert-manager/clusterissuers/letsencrypt.yaml new file mode 100644 index 0000000..208b06d --- /dev/null +++ b/platform/ingress/base/cert-manager/clusterissuers/letsencrypt.yaml @@ -0,0 +1,19 @@ +apiVersion: cert-manager.io/v1 +kind: ClusterIssuer + +metadata: + name: letsencrypt + +spec: + acme: + email: ${ACME_EMAIL} + + server: https://acme-v02.api.letsencrypt.org/directory + + privateKeySecretRef: + name: letsencrypt + + solvers: + - http01: + ingress: + ingressClassName: alb \ No newline at end of file diff --git a/platform/ingress/base/cert-manager/helm-release.yaml b/platform/ingress/base/cert-manager/helm-release.yaml index e69de29..d339d98 100644 --- a/platform/ingress/base/cert-manager/helm-release.yaml +++ b/platform/ingress/base/cert-manager/helm-release.yaml @@ -0,0 +1,28 @@ +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease + +metadata: + name: cert-manager + +spec: + interval: 30m + + chart: + spec: + chart: cert-manager + version: "v1.18.2" + sourceRef: + kind: HelmRepository + name: jetstack + namespace: flux-system + + install: + crds: CreateReplace + + upgrade: + crds: CreateReplace + + valuesFrom: + - kind: ConfigMap + name: cert-manager-values + valuesKey: values.yaml \ No newline at end of file diff --git a/platform/ingress/base/cert-manager/helm-repository.yaml b/platform/ingress/base/cert-manager/helm-repository.yaml new file mode 100644 index 0000000..23db72c --- /dev/null +++ b/platform/ingress/base/cert-manager/helm-repository.yaml @@ -0,0 +1,10 @@ +apiVersion: source.toolkit.fluxcd.io/v1 +kind: HelmRepository + +metadata: + name: jetstack + namespace: flux-system + +spec: + interval: 24h + url: https://charts.jetstack.io \ No newline at end of file diff --git a/platform/ingress/base/cert-manager/clusterissuers/letsencrypt-staging.yaml b/platform/ingress/base/cert-manager/kustomization.yaml similarity index 100% rename from platform/ingress/base/cert-manager/clusterissuers/letsencrypt-staging.yaml rename to platform/ingress/base/cert-manager/kustomization.yaml diff --git a/platform/ingress/base/cert-manager/values.yaml b/platform/ingress/base/cert-manager/values.yaml index e69de29..00d42be 100644 --- a/platform/ingress/base/cert-manager/values.yaml +++ b/platform/ingress/base/cert-manager/values.yaml @@ -0,0 +1,11 @@ +crds: + enabled: true + +replicaCount: 2 + +prometheus: + enabled: true + servicemonitor: + enabled: true + labels: + prometheus: kube-prometheus \ No newline at end of file diff --git a/platform/ingress/base/external-dns/helm-release.yaml b/platform/ingress/base/external-dns/helm-release.yaml index e69de29..ad88994 100644 --- a/platform/ingress/base/external-dns/helm-release.yaml +++ b/platform/ingress/base/external-dns/helm-release.yaml @@ -0,0 +1,30 @@ +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease + +metadata: + name: external-dns + +spec: + interval: 30m + + chart: + spec: + chart: external-dns + version: "1.18.0" + sourceRef: + kind: HelmRepository + name: external-dns + namespace: flux-system + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + valuesFrom: + - kind: ConfigMap + name: external-dns-values + valuesKey: values.yaml \ No newline at end of file diff --git a/platform/ingress/base/external-dns/helm-repository.yaml b/platform/ingress/base/external-dns/helm-repository.yaml new file mode 100644 index 0000000..7784e51 --- /dev/null +++ b/platform/ingress/base/external-dns/helm-repository.yaml @@ -0,0 +1,10 @@ +apiVersion: source.toolkit.fluxcd.io/v1 +kind: HelmRepository + +metadata: + name: external-dns + namespace: flux-system + +spec: + interval: 24h + url: https://kubernetes-sigs.github.io/external-dns \ No newline at end of file diff --git a/platform/ingress/base/ingress-nginx/helm-release.yaml b/platform/ingress/base/external-dns/kustomization.yaml similarity index 100% rename from platform/ingress/base/ingress-nginx/helm-release.yaml rename to platform/ingress/base/external-dns/kustomization.yaml diff --git a/platform/ingress/base/external-dns/values.yaml b/platform/ingress/base/external-dns/values.yaml index e69de29..ee65d36 100644 --- a/platform/ingress/base/external-dns/values.yaml +++ b/platform/ingress/base/external-dns/values.yaml @@ -0,0 +1,19 @@ +provider: aws + +policy: sync + +registry: txt + +txtOwnerId: ${CLUSTER_NAME} + +domainFilters: + - ${BASE_DOMAIN} + +serviceAccount: + create: true + name: external-dns + +serviceMonitor: + enabled: true + additionalLabels: + prometheus: kube-prometheus \ No newline at end of file diff --git a/platform/ingress/base/ingress-nginx/values.yaml b/platform/ingress/base/ingress-nginx/values.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/ingress/base/kustomization.yaml b/platform/ingress/base/kustomization.yaml index e69de29..6cfd7fb 100644 --- a/platform/ingress/base/kustomization.yaml +++ b/platform/ingress/base/kustomization.yaml @@ -0,0 +1,7 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - aws-load-balancer-controller/ + - external-dns/ + - cert-manager/ \ No newline at end of file diff --git a/platform/ingress/base/namespace.yaml b/platform/ingress/base/namespace.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/ingress/overlay/dev/flux/ingress.yaml b/platform/ingress/overlay/dev/flux/ingress.yaml new file mode 100644 index 0000000..0022b8a --- /dev/null +++ b/platform/ingress/overlay/dev/flux/ingress.yaml @@ -0,0 +1,27 @@ +apiVersion: kustomize.toolkit.fluxcd.io/v1 +kind: Kustomization + +metadata: + name: ingress + namespace: flux-system + +spec: + interval: 10m + + path: ./ingress/overlays/dev + + prune: true + + sourceRef: + kind: GitRepository + name: infrastructure + + wait: true + + postBuild: + substitute: + CLUSTER_NAME: eks-dev-cluster + AWS_REGION: us-east-1 + VPC_ID: vpc-0123456789abcdef + BASE_DOMAIN: dev.emmanuelogah.com + ACME_EMAIL: admin@emmanuelogah.com \ No newline at end of file diff --git a/platform/ingress/overlay/dev/ingress-namespace.yaml b/platform/ingress/overlay/dev/ingress-namespace.yaml new file mode 100644 index 0000000..0b345a8 --- /dev/null +++ b/platform/ingress/overlay/dev/ingress-namespace.yaml @@ -0,0 +1,5 @@ +apiVersion: v1 +kind: Namespace + +metadata: + name: dev \ No newline at end of file diff --git a/platform/ingress/overlay/dev/kustomization.yaml b/platform/ingress/overlay/dev/kustomization.yaml new file mode 100644 index 0000000..a3ea8d6 --- /dev/null +++ b/platform/ingress/overlay/dev/kustomization.yaml @@ -0,0 +1,11 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +namespace: dev + +resources: + - ../../base + + +patches: + - path: aws-load-balancer-controller-patch.yaml \ No newline at end of file From 01ea7db2a55b2a9cc6f5d586ad96810001cbaa6f Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Wed, 22 Jul 2026 10:24:49 +0200 Subject: [PATCH 010/122] Added network and network policies to the observability --- apps/order-service/base/kustomization.yaml | 3 +- .../base/networkpolicies/allow-dns.yaml | 31 +++++++++++++++++++ .../base/networkpolicies/allow-ingress.yaml | 24 ++++++++++++++ .../base/networkpolicies/allow-postgres.yaml | 23 ++++++++++++++ .../networkpolicies/allow-prometheus.yaml | 28 +++++++++++++++++ .../base/networkpolicies/allow-redis.yaml | 23 ++++++++++++++ .../base/networkpolicies/default-deny.yaml | 12 +++++++ .../base/networkpolicies/kustomization.yaml | 8 +++++ apps/payment-service/base/kustomization.yaml | 3 +- .../base/networkpolicies/allow-dns.yaml | 31 +++++++++++++++++++ .../base/networkpolicies/allow-ingress.yaml | 24 ++++++++++++++ .../base/networkpolicies/allow-postgres.yaml | 23 ++++++++++++++ .../networkpolicies/allow-prometheus.yaml | 28 +++++++++++++++++ .../base/networkpolicies/allow-redis.yaml | 23 ++++++++++++++ .../base/networkpolicies/default-deny.yaml | 12 +++++++ .../base/networkpolicies/kustomization.yaml | 8 +++++ apps/product-service/base/kustomization.yaml | 3 +- .../base/networkpolicies/allow-dns.yaml | 31 +++++++++++++++++++ .../base/networkpolicies/allow-ingress.yaml | 24 ++++++++++++++ .../base/networkpolicies/allow-postgres.yaml | 23 ++++++++++++++ .../networkpolicies/allow-prometheus.yaml | 28 +++++++++++++++++ .../base/networkpolicies/allow-redis.yaml | 23 ++++++++++++++ .../base/networkpolicies/default-deny.yaml | 12 +++++++ .../base/networkpolicies/kustomization.yaml | 8 +++++ apps/user-service/base/kustomization.yaml | 3 +- .../base/networkpolicies/allow-dns.yaml | 31 +++++++++++++++++++ .../base/networkpolicies/allow-ingress.yaml | 24 ++++++++++++++ .../base/networkpolicies/allow-postgres.yaml | 23 ++++++++++++++ .../networkpolicies/allow-prometheus.yaml | 28 +++++++++++++++++ .../base/networkpolicies/allow-redis.yaml | 23 ++++++++++++++ .../base/networkpolicies/default-deny.yaml | 12 +++++++ .../base/networkpolicies/kustomization.yaml | 8 +++++ .../overlays/dev/kustomization.yaml | 2 +- ...itoring.yaml => monitoring-namespace.yaml} | 0 .../base/gateway-api/kustomization.yaml | 5 +++ .../standard-install.yaml} | 0 platform/networking/base/kustomization.yaml | 6 ++++ .../base/metrics-server/helm-release.yaml | 31 +++++++++++++++++++ .../base/metrics-server/helm-repository.yaml | 10 ++++++ .../base/metrics-server/kustomization.yaml | 14 +++++++++ .../base/metrics-server/values.yaml | 12 +++++++ platform/networking/base/namespace.yaml | 0 .../networking/overlay/dev/kustomization.yaml | 5 +++ 43 files changed, 688 insertions(+), 5 deletions(-) create mode 100644 apps/order-service/base/networkpolicies/allow-dns.yaml create mode 100644 apps/order-service/base/networkpolicies/allow-ingress.yaml create mode 100644 apps/order-service/base/networkpolicies/allow-postgres.yaml create mode 100644 apps/order-service/base/networkpolicies/allow-prometheus.yaml create mode 100644 apps/order-service/base/networkpolicies/allow-redis.yaml create mode 100644 apps/order-service/base/networkpolicies/default-deny.yaml create mode 100644 apps/order-service/base/networkpolicies/kustomization.yaml create mode 100644 apps/payment-service/base/networkpolicies/allow-dns.yaml create mode 100644 apps/payment-service/base/networkpolicies/allow-ingress.yaml create mode 100644 apps/payment-service/base/networkpolicies/allow-postgres.yaml create mode 100644 apps/payment-service/base/networkpolicies/allow-prometheus.yaml create mode 100644 apps/payment-service/base/networkpolicies/allow-redis.yaml create mode 100644 apps/payment-service/base/networkpolicies/default-deny.yaml create mode 100644 apps/payment-service/base/networkpolicies/kustomization.yaml create mode 100644 apps/product-service/base/networkpolicies/allow-dns.yaml create mode 100644 apps/product-service/base/networkpolicies/allow-ingress.yaml create mode 100644 apps/product-service/base/networkpolicies/allow-postgres.yaml create mode 100644 apps/product-service/base/networkpolicies/allow-prometheus.yaml create mode 100644 apps/product-service/base/networkpolicies/allow-redis.yaml create mode 100644 apps/product-service/base/networkpolicies/default-deny.yaml create mode 100644 apps/product-service/base/networkpolicies/kustomization.yaml create mode 100644 apps/user-service/base/networkpolicies/allow-dns.yaml create mode 100644 apps/user-service/base/networkpolicies/allow-ingress.yaml create mode 100644 apps/user-service/base/networkpolicies/allow-postgres.yaml create mode 100644 apps/user-service/base/networkpolicies/allow-prometheus.yaml create mode 100644 apps/user-service/base/networkpolicies/allow-redis.yaml create mode 100644 apps/user-service/base/networkpolicies/default-deny.yaml create mode 100644 apps/user-service/base/networkpolicies/kustomization.yaml rename platform/monitoring/overlays/dev/{monitoring.yaml => monitoring-namespace.yaml} (100%) create mode 100644 platform/networking/base/gateway-api/kustomization.yaml rename platform/networking/base/{dns/coredns-patch.yaml => gateway-api/standard-install.yaml} (100%) create mode 100644 platform/networking/base/metrics-server/helm-repository.yaml create mode 100644 platform/networking/base/metrics-server/kustomization.yaml delete mode 100644 platform/networking/base/namespace.yaml create mode 100644 platform/networking/overlay/dev/kustomization.yaml diff --git a/apps/order-service/base/kustomization.yaml b/apps/order-service/base/kustomization.yaml index e81f6e6..07b93fb 100644 --- a/apps/order-service/base/kustomization.yaml +++ b/apps/order-service/base/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization resources: - deployment.yaml - service.yaml - - poddisruption.yaml \ No newline at end of file + - poddisruption.yaml + - networkpolicies/ \ No newline at end of file diff --git a/apps/order-service/base/networkpolicies/allow-dns.yaml b/apps/order-service/base/networkpolicies/allow-dns.yaml new file mode 100644 index 0000000..bb0229a --- /dev/null +++ b/apps/order-service/base/networkpolicies/allow-dns.yaml @@ -0,0 +1,31 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-dns + +spec: + podSelector: + matchLabels: + app: order-service + + policyTypes: + - Egress + + egress: + - to: + + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: kube-system + + podSelector: + matchLabels: + k8s-app: kube-dns + + ports: + - protocol: UDP + port: 53 + + - protocol: TCP + port: 53 \ No newline at end of file diff --git a/apps/order-service/base/networkpolicies/allow-ingress.yaml b/apps/order-service/base/networkpolicies/allow-ingress.yaml new file mode 100644 index 0000000..7487894 --- /dev/null +++ b/apps/order-service/base/networkpolicies/allow-ingress.yaml @@ -0,0 +1,24 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-ingress + +spec: + podSelector: + matchLabels: + app: order-service + + policyTypes: + - Ingress + + ingress: + - from: + + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: ingress-system + + ports: + - protocol: TCP + port: 8083 \ No newline at end of file diff --git a/apps/order-service/base/networkpolicies/allow-postgres.yaml b/apps/order-service/base/networkpolicies/allow-postgres.yaml new file mode 100644 index 0000000..f318b06 --- /dev/null +++ b/apps/order-service/base/networkpolicies/allow-postgres.yaml @@ -0,0 +1,23 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-postgres + +spec: + podSelector: + matchLabels: + app: order-service + + policyTypes: + - Egress + + egress: + - to: + - podSelector: + matchLabels: + app.kubernetes.io/name: postgresql + + ports: + - protocol: TCP + port: 5432 \ No newline at end of file diff --git a/apps/order-service/base/networkpolicies/allow-prometheus.yaml b/apps/order-service/base/networkpolicies/allow-prometheus.yaml new file mode 100644 index 0000000..fb2bcf7 --- /dev/null +++ b/apps/order-service/base/networkpolicies/allow-prometheus.yaml @@ -0,0 +1,28 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-prometheus + +spec: + podSelector: + matchLabels: + app: order-service + + policyTypes: + - Ingress + + ingress: + - from: + + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: monitoring + + podSelector: + matchLabels: + app.kubernetes.io/name: prometheus + + ports: + - protocol: TCP + port: 8083 \ No newline at end of file diff --git a/apps/order-service/base/networkpolicies/allow-redis.yaml b/apps/order-service/base/networkpolicies/allow-redis.yaml new file mode 100644 index 0000000..d15cfb2 --- /dev/null +++ b/apps/order-service/base/networkpolicies/allow-redis.yaml @@ -0,0 +1,23 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-redis + +spec: + podSelector: + matchLabels: + app: order-service + + policyTypes: + - Egress + + egress: + - to: + - podSelector: + matchLabels: + app.kubernetes.io/name: redis + + ports: + - protocol: TCP + port: 6379 \ No newline at end of file diff --git a/apps/order-service/base/networkpolicies/default-deny.yaml b/apps/order-service/base/networkpolicies/default-deny.yaml new file mode 100644 index 0000000..34ec623 --- /dev/null +++ b/apps/order-service/base/networkpolicies/default-deny.yaml @@ -0,0 +1,12 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: default-deny + +spec: + podSelector: {} + + policyTypes: + - Ingress + - Egress \ No newline at end of file diff --git a/apps/order-service/base/networkpolicies/kustomization.yaml b/apps/order-service/base/networkpolicies/kustomization.yaml new file mode 100644 index 0000000..d603926 --- /dev/null +++ b/apps/order-service/base/networkpolicies/kustomization.yaml @@ -0,0 +1,8 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - default-deny.yaml + - allow-ingress.yaml + - allow-dns.yaml + - allow-prometheus.yaml \ No newline at end of file diff --git a/apps/payment-service/base/kustomization.yaml b/apps/payment-service/base/kustomization.yaml index e81f6e6..07b93fb 100644 --- a/apps/payment-service/base/kustomization.yaml +++ b/apps/payment-service/base/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization resources: - deployment.yaml - service.yaml - - poddisruption.yaml \ No newline at end of file + - poddisruption.yaml + - networkpolicies/ \ No newline at end of file diff --git a/apps/payment-service/base/networkpolicies/allow-dns.yaml b/apps/payment-service/base/networkpolicies/allow-dns.yaml new file mode 100644 index 0000000..bb0229a --- /dev/null +++ b/apps/payment-service/base/networkpolicies/allow-dns.yaml @@ -0,0 +1,31 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-dns + +spec: + podSelector: + matchLabels: + app: order-service + + policyTypes: + - Egress + + egress: + - to: + + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: kube-system + + podSelector: + matchLabels: + k8s-app: kube-dns + + ports: + - protocol: UDP + port: 53 + + - protocol: TCP + port: 53 \ No newline at end of file diff --git a/apps/payment-service/base/networkpolicies/allow-ingress.yaml b/apps/payment-service/base/networkpolicies/allow-ingress.yaml new file mode 100644 index 0000000..9b98e09 --- /dev/null +++ b/apps/payment-service/base/networkpolicies/allow-ingress.yaml @@ -0,0 +1,24 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-ingress + +spec: + podSelector: + matchLabels: + app: order-service + + policyTypes: + - Ingress + + ingress: + - from: + + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: ingress-system + + ports: + - protocol: TCP + port: 8084 \ No newline at end of file diff --git a/apps/payment-service/base/networkpolicies/allow-postgres.yaml b/apps/payment-service/base/networkpolicies/allow-postgres.yaml new file mode 100644 index 0000000..f318b06 --- /dev/null +++ b/apps/payment-service/base/networkpolicies/allow-postgres.yaml @@ -0,0 +1,23 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-postgres + +spec: + podSelector: + matchLabels: + app: order-service + + policyTypes: + - Egress + + egress: + - to: + - podSelector: + matchLabels: + app.kubernetes.io/name: postgresql + + ports: + - protocol: TCP + port: 5432 \ No newline at end of file diff --git a/apps/payment-service/base/networkpolicies/allow-prometheus.yaml b/apps/payment-service/base/networkpolicies/allow-prometheus.yaml new file mode 100644 index 0000000..1a1b5b7 --- /dev/null +++ b/apps/payment-service/base/networkpolicies/allow-prometheus.yaml @@ -0,0 +1,28 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-prometheus + +spec: + podSelector: + matchLabels: + app: order-service + + policyTypes: + - Ingress + + ingress: + - from: + + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: monitoring + + podSelector: + matchLabels: + app.kubernetes.io/name: prometheus + + ports: + - protocol: TCP + port: 8084 \ No newline at end of file diff --git a/apps/payment-service/base/networkpolicies/allow-redis.yaml b/apps/payment-service/base/networkpolicies/allow-redis.yaml new file mode 100644 index 0000000..d15cfb2 --- /dev/null +++ b/apps/payment-service/base/networkpolicies/allow-redis.yaml @@ -0,0 +1,23 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-redis + +spec: + podSelector: + matchLabels: + app: order-service + + policyTypes: + - Egress + + egress: + - to: + - podSelector: + matchLabels: + app.kubernetes.io/name: redis + + ports: + - protocol: TCP + port: 6379 \ No newline at end of file diff --git a/apps/payment-service/base/networkpolicies/default-deny.yaml b/apps/payment-service/base/networkpolicies/default-deny.yaml new file mode 100644 index 0000000..34ec623 --- /dev/null +++ b/apps/payment-service/base/networkpolicies/default-deny.yaml @@ -0,0 +1,12 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: default-deny + +spec: + podSelector: {} + + policyTypes: + - Ingress + - Egress \ No newline at end of file diff --git a/apps/payment-service/base/networkpolicies/kustomization.yaml b/apps/payment-service/base/networkpolicies/kustomization.yaml new file mode 100644 index 0000000..d603926 --- /dev/null +++ b/apps/payment-service/base/networkpolicies/kustomization.yaml @@ -0,0 +1,8 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - default-deny.yaml + - allow-ingress.yaml + - allow-dns.yaml + - allow-prometheus.yaml \ No newline at end of file diff --git a/apps/product-service/base/kustomization.yaml b/apps/product-service/base/kustomization.yaml index e81f6e6..07b93fb 100644 --- a/apps/product-service/base/kustomization.yaml +++ b/apps/product-service/base/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization resources: - deployment.yaml - service.yaml - - poddisruption.yaml \ No newline at end of file + - poddisruption.yaml + - networkpolicies/ \ No newline at end of file diff --git a/apps/product-service/base/networkpolicies/allow-dns.yaml b/apps/product-service/base/networkpolicies/allow-dns.yaml new file mode 100644 index 0000000..bb0229a --- /dev/null +++ b/apps/product-service/base/networkpolicies/allow-dns.yaml @@ -0,0 +1,31 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-dns + +spec: + podSelector: + matchLabels: + app: order-service + + policyTypes: + - Egress + + egress: + - to: + + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: kube-system + + podSelector: + matchLabels: + k8s-app: kube-dns + + ports: + - protocol: UDP + port: 53 + + - protocol: TCP + port: 53 \ No newline at end of file diff --git a/apps/product-service/base/networkpolicies/allow-ingress.yaml b/apps/product-service/base/networkpolicies/allow-ingress.yaml new file mode 100644 index 0000000..6d6279f --- /dev/null +++ b/apps/product-service/base/networkpolicies/allow-ingress.yaml @@ -0,0 +1,24 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-ingress + +spec: + podSelector: + matchLabels: + app: order-service + + policyTypes: + - Ingress + + ingress: + - from: + + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: ingress-system + + ports: + - protocol: TCP + port: 8082 \ No newline at end of file diff --git a/apps/product-service/base/networkpolicies/allow-postgres.yaml b/apps/product-service/base/networkpolicies/allow-postgres.yaml new file mode 100644 index 0000000..f318b06 --- /dev/null +++ b/apps/product-service/base/networkpolicies/allow-postgres.yaml @@ -0,0 +1,23 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-postgres + +spec: + podSelector: + matchLabels: + app: order-service + + policyTypes: + - Egress + + egress: + - to: + - podSelector: + matchLabels: + app.kubernetes.io/name: postgresql + + ports: + - protocol: TCP + port: 5432 \ No newline at end of file diff --git a/apps/product-service/base/networkpolicies/allow-prometheus.yaml b/apps/product-service/base/networkpolicies/allow-prometheus.yaml new file mode 100644 index 0000000..3beb9d4 --- /dev/null +++ b/apps/product-service/base/networkpolicies/allow-prometheus.yaml @@ -0,0 +1,28 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-prometheus + +spec: + podSelector: + matchLabels: + app: order-service + + policyTypes: + - Ingress + + ingress: + - from: + + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: monitoring + + podSelector: + matchLabels: + app.kubernetes.io/name: prometheus + + ports: + - protocol: TCP + port: 8082 \ No newline at end of file diff --git a/apps/product-service/base/networkpolicies/allow-redis.yaml b/apps/product-service/base/networkpolicies/allow-redis.yaml new file mode 100644 index 0000000..d15cfb2 --- /dev/null +++ b/apps/product-service/base/networkpolicies/allow-redis.yaml @@ -0,0 +1,23 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-redis + +spec: + podSelector: + matchLabels: + app: order-service + + policyTypes: + - Egress + + egress: + - to: + - podSelector: + matchLabels: + app.kubernetes.io/name: redis + + ports: + - protocol: TCP + port: 6379 \ No newline at end of file diff --git a/apps/product-service/base/networkpolicies/default-deny.yaml b/apps/product-service/base/networkpolicies/default-deny.yaml new file mode 100644 index 0000000..34ec623 --- /dev/null +++ b/apps/product-service/base/networkpolicies/default-deny.yaml @@ -0,0 +1,12 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: default-deny + +spec: + podSelector: {} + + policyTypes: + - Ingress + - Egress \ No newline at end of file diff --git a/apps/product-service/base/networkpolicies/kustomization.yaml b/apps/product-service/base/networkpolicies/kustomization.yaml new file mode 100644 index 0000000..d603926 --- /dev/null +++ b/apps/product-service/base/networkpolicies/kustomization.yaml @@ -0,0 +1,8 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - default-deny.yaml + - allow-ingress.yaml + - allow-dns.yaml + - allow-prometheus.yaml \ No newline at end of file diff --git a/apps/user-service/base/kustomization.yaml b/apps/user-service/base/kustomization.yaml index e81f6e6..07b93fb 100644 --- a/apps/user-service/base/kustomization.yaml +++ b/apps/user-service/base/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization resources: - deployment.yaml - service.yaml - - poddisruption.yaml \ No newline at end of file + - poddisruption.yaml + - networkpolicies/ \ No newline at end of file diff --git a/apps/user-service/base/networkpolicies/allow-dns.yaml b/apps/user-service/base/networkpolicies/allow-dns.yaml new file mode 100644 index 0000000..bb0229a --- /dev/null +++ b/apps/user-service/base/networkpolicies/allow-dns.yaml @@ -0,0 +1,31 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-dns + +spec: + podSelector: + matchLabels: + app: order-service + + policyTypes: + - Egress + + egress: + - to: + + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: kube-system + + podSelector: + matchLabels: + k8s-app: kube-dns + + ports: + - protocol: UDP + port: 53 + + - protocol: TCP + port: 53 \ No newline at end of file diff --git a/apps/user-service/base/networkpolicies/allow-ingress.yaml b/apps/user-service/base/networkpolicies/allow-ingress.yaml new file mode 100644 index 0000000..a74ea2d --- /dev/null +++ b/apps/user-service/base/networkpolicies/allow-ingress.yaml @@ -0,0 +1,24 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-ingress + +spec: + podSelector: + matchLabels: + app: order-service + + policyTypes: + - Ingress + + ingress: + - from: + + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: ingress-system + + ports: + - protocol: TCP + port: 8081 \ No newline at end of file diff --git a/apps/user-service/base/networkpolicies/allow-postgres.yaml b/apps/user-service/base/networkpolicies/allow-postgres.yaml new file mode 100644 index 0000000..f318b06 --- /dev/null +++ b/apps/user-service/base/networkpolicies/allow-postgres.yaml @@ -0,0 +1,23 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-postgres + +spec: + podSelector: + matchLabels: + app: order-service + + policyTypes: + - Egress + + egress: + - to: + - podSelector: + matchLabels: + app.kubernetes.io/name: postgresql + + ports: + - protocol: TCP + port: 5432 \ No newline at end of file diff --git a/apps/user-service/base/networkpolicies/allow-prometheus.yaml b/apps/user-service/base/networkpolicies/allow-prometheus.yaml new file mode 100644 index 0000000..b619cde --- /dev/null +++ b/apps/user-service/base/networkpolicies/allow-prometheus.yaml @@ -0,0 +1,28 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-prometheus + +spec: + podSelector: + matchLabels: + app: order-service + + policyTypes: + - Ingress + + ingress: + - from: + + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: monitoring + + podSelector: + matchLabels: + app.kubernetes.io/name: prometheus + + ports: + - protocol: TCP + port: 8081 \ No newline at end of file diff --git a/apps/user-service/base/networkpolicies/allow-redis.yaml b/apps/user-service/base/networkpolicies/allow-redis.yaml new file mode 100644 index 0000000..d15cfb2 --- /dev/null +++ b/apps/user-service/base/networkpolicies/allow-redis.yaml @@ -0,0 +1,23 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-redis + +spec: + podSelector: + matchLabels: + app: order-service + + policyTypes: + - Egress + + egress: + - to: + - podSelector: + matchLabels: + app.kubernetes.io/name: redis + + ports: + - protocol: TCP + port: 6379 \ No newline at end of file diff --git a/apps/user-service/base/networkpolicies/default-deny.yaml b/apps/user-service/base/networkpolicies/default-deny.yaml new file mode 100644 index 0000000..34ec623 --- /dev/null +++ b/apps/user-service/base/networkpolicies/default-deny.yaml @@ -0,0 +1,12 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: default-deny + +spec: + podSelector: {} + + policyTypes: + - Ingress + - Egress \ No newline at end of file diff --git a/apps/user-service/base/networkpolicies/kustomization.yaml b/apps/user-service/base/networkpolicies/kustomization.yaml new file mode 100644 index 0000000..d603926 --- /dev/null +++ b/apps/user-service/base/networkpolicies/kustomization.yaml @@ -0,0 +1,8 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - default-deny.yaml + - allow-ingress.yaml + - allow-dns.yaml + - allow-prometheus.yaml \ No newline at end of file diff --git a/platform/monitoring/overlays/dev/kustomization.yaml b/platform/monitoring/overlays/dev/kustomization.yaml index ef66e29..149da04 100644 --- a/platform/monitoring/overlays/dev/kustomization.yaml +++ b/platform/monitoring/overlays/dev/kustomization.yaml @@ -4,5 +4,5 @@ kind: Kustomization namespace: dev resources: - - monitoring.yaml + - monitoring-namespace.yaml - ../../base \ No newline at end of file diff --git a/platform/monitoring/overlays/dev/monitoring.yaml b/platform/monitoring/overlays/dev/monitoring-namespace.yaml similarity index 100% rename from platform/monitoring/overlays/dev/monitoring.yaml rename to platform/monitoring/overlays/dev/monitoring-namespace.yaml diff --git a/platform/networking/base/gateway-api/kustomization.yaml b/platform/networking/base/gateway-api/kustomization.yaml new file mode 100644 index 0000000..cb54840 --- /dev/null +++ b/platform/networking/base/gateway-api/kustomization.yaml @@ -0,0 +1,5 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - standard-install.yaml \ No newline at end of file diff --git a/platform/networking/base/dns/coredns-patch.yaml b/platform/networking/base/gateway-api/standard-install.yaml similarity index 100% rename from platform/networking/base/dns/coredns-patch.yaml rename to platform/networking/base/gateway-api/standard-install.yaml diff --git a/platform/networking/base/kustomization.yaml b/platform/networking/base/kustomization.yaml index e69de29..4914a6a 100644 --- a/platform/networking/base/kustomization.yaml +++ b/platform/networking/base/kustomization.yaml @@ -0,0 +1,6 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - metrics-server/ + - gateway-api/ \ No newline at end of file diff --git a/platform/networking/base/metrics-server/helm-release.yaml b/platform/networking/base/metrics-server/helm-release.yaml index e69de29..649e38d 100644 --- a/platform/networking/base/metrics-server/helm-release.yaml +++ b/platform/networking/base/metrics-server/helm-release.yaml @@ -0,0 +1,31 @@ +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease + +metadata: + name: metrics-server + namespace: kube-system + +spec: + interval: 30m + + chart: + spec: + chart: metrics-server + version: "3.13.0" + sourceRef: + kind: HelmRepository + name: metrics-server + namespace: flux-system + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + valuesFrom: + - kind: ConfigMap + name: metrics-server-values + valuesKey: values.yaml \ No newline at end of file diff --git a/platform/networking/base/metrics-server/helm-repository.yaml b/platform/networking/base/metrics-server/helm-repository.yaml new file mode 100644 index 0000000..1a0b5cb --- /dev/null +++ b/platform/networking/base/metrics-server/helm-repository.yaml @@ -0,0 +1,10 @@ +apiVersion: source.toolkit.fluxcd.io/v1 +kind: HelmRepository + +metadata: + name: metrics-server + namespace: flux-system + +spec: + interval: 24h + url: https://kubernetes-sigs.github.io/metrics-server \ No newline at end of file diff --git a/platform/networking/base/metrics-server/kustomization.yaml b/platform/networking/base/metrics-server/kustomization.yaml new file mode 100644 index 0000000..585a8b4 --- /dev/null +++ b/platform/networking/base/metrics-server/kustomization.yaml @@ -0,0 +1,14 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - helm-repository.yaml + - helm-release.yaml + +configMapGenerator: + - name: metrics-server-values + files: + - values.yaml + +generatorOptions: + disableNameSuffixHash: true \ No newline at end of file diff --git a/platform/networking/base/metrics-server/values.yaml b/platform/networking/base/metrics-server/values.yaml index e69de29..d43e459 100644 --- a/platform/networking/base/metrics-server/values.yaml +++ b/platform/networking/base/metrics-server/values.yaml @@ -0,0 +1,12 @@ +replicas: 2 + +serviceMonitor: + enabled: true + additionalLabels: + prometheus: kube-prometheus + +args: + - --cert-dir=/tmp + - --kubelet-preferred-address-types=InternalIP,Hostname + - --kubelet-use-node-status-port + - --metric-resolution=15s \ No newline at end of file diff --git a/platform/networking/base/namespace.yaml b/platform/networking/base/namespace.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/networking/overlay/dev/kustomization.yaml b/platform/networking/overlay/dev/kustomization.yaml new file mode 100644 index 0000000..681848f --- /dev/null +++ b/platform/networking/overlay/dev/kustomization.yaml @@ -0,0 +1,5 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - ../../base \ No newline at end of file From a30f37a6ede1b5fd4cdded9bcc463280461229b5 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Wed, 22 Jul 2026 11:17:17 +0200 Subject: [PATCH 011/122] Added security --- apps/order-service/base/deployment.yaml | 2 + apps/payment-service/base/deployment.yaml | 2 + apps/product-service/base/deployment.yaml | 2 + apps/user-service/base/deployment.yaml | 2 + .../base/external-secrets/values.yaml | 0 platform/security/base/kustomization.yaml | 6 ++ .../security/base/kyverno/helm-release.yaml | 31 ++++++++++ .../base/kyverno/helm-repository.yaml | 10 ++++ .../security/base/kyverno/kustomization.yaml | 14 +++++ platform/security/base/kyverno/values.yaml | 22 +++++++ platform/security/base/namespace.yaml | 0 .../base/policies/disallow-hostpath.yaml | 36 +++++++++++ .../base/policies/disallow-latest-tag.yaml | 42 +++++++++++++ .../base/policies/disallow-privileged.yaml | 37 ++++++++++++ .../security/base/policies/kustomization.yaml | 15 +++++ .../base/policies/policy-exception.yaml | 20 +++++++ .../base/policies/require-labels.yaml | 42 +++++++++++++ .../base/policies/require-limits.yaml | 60 +++++++++++++++++++ .../base/policies/require-networkpolicy.yaml | 28 +++++++++ .../base/policies/require-non-root.yaml | 40 +++++++++++++ .../security/base/policies/require-pdb.yaml | 29 +++++++++ .../base/policies/require-probes.yaml | 30 ++++++++++ .../policies/require-readonly-rootfs.yaml | 41 +++++++++++++ .../base/policies/restrict-privileged.yaml | 0 .../base/sealed-secrets/helm-release.yaml | 0 .../security/base/sealed-secrets/values.yaml | 0 .../dev/kustomization.yaml} | 0 .../overlay/dev/security-namespace.yaml | 5 ++ 28 files changed, 516 insertions(+) delete mode 100644 platform/security/base/external-secrets/values.yaml create mode 100644 platform/security/base/kyverno/helm-repository.yaml create mode 100644 platform/security/base/kyverno/kustomization.yaml delete mode 100644 platform/security/base/namespace.yaml create mode 100644 platform/security/base/policies/disallow-hostpath.yaml create mode 100644 platform/security/base/policies/disallow-privileged.yaml create mode 100644 platform/security/base/policies/kustomization.yaml create mode 100644 platform/security/base/policies/policy-exception.yaml create mode 100644 platform/security/base/policies/require-labels.yaml create mode 100644 platform/security/base/policies/require-networkpolicy.yaml create mode 100644 platform/security/base/policies/require-non-root.yaml create mode 100644 platform/security/base/policies/require-pdb.yaml create mode 100644 platform/security/base/policies/require-readonly-rootfs.yaml delete mode 100644 platform/security/base/policies/restrict-privileged.yaml delete mode 100644 platform/security/base/sealed-secrets/helm-release.yaml delete mode 100644 platform/security/base/sealed-secrets/values.yaml rename platform/security/{base/external-secrets/helm-release.yaml => overlay/dev/kustomization.yaml} (100%) create mode 100644 platform/security/overlay/dev/security-namespace.yaml diff --git a/apps/order-service/base/deployment.yaml b/apps/order-service/base/deployment.yaml index 0164a39..4a6fd2e 100644 --- a/apps/order-service/base/deployment.yaml +++ b/apps/order-service/base/deployment.yaml @@ -22,6 +22,8 @@ spec: metadata: labels: app: order-service + networkpolicy.enabled: "true" + pdb.enabled: "true" spec: terminationGracePeriodSeconds: 30 diff --git a/apps/payment-service/base/deployment.yaml b/apps/payment-service/base/deployment.yaml index 1897ce4..afacaf4 100644 --- a/apps/payment-service/base/deployment.yaml +++ b/apps/payment-service/base/deployment.yaml @@ -11,6 +11,8 @@ spec: selector: matchLabels: app: payment-service + networkpolicy.enabled: "true" + pdb.enabled: "true" strategy: type: RollingUpdate diff --git a/apps/product-service/base/deployment.yaml b/apps/product-service/base/deployment.yaml index ae78343..ff6f4d4 100644 --- a/apps/product-service/base/deployment.yaml +++ b/apps/product-service/base/deployment.yaml @@ -11,6 +11,8 @@ spec: selector: matchLabels: app: product-service + networkpolicy.enabled: "true" + pdb.enabled: "true" strategy: type: RollingUpdate diff --git a/apps/user-service/base/deployment.yaml b/apps/user-service/base/deployment.yaml index 1daef37..915b948 100644 --- a/apps/user-service/base/deployment.yaml +++ b/apps/user-service/base/deployment.yaml @@ -11,6 +11,8 @@ spec: selector: matchLabels: app: user-service + networkpolicy.enabled: "true" + pdb.enabled: "true" strategy: type: RollingUpdate diff --git a/platform/security/base/external-secrets/values.yaml b/platform/security/base/external-secrets/values.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/security/base/kustomization.yaml b/platform/security/base/kustomization.yaml index e69de29..cee4ab7 100644 --- a/platform/security/base/kustomization.yaml +++ b/platform/security/base/kustomization.yaml @@ -0,0 +1,6 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - kyverno/ + - policies/ \ No newline at end of file diff --git a/platform/security/base/kyverno/helm-release.yaml b/platform/security/base/kyverno/helm-release.yaml index e69de29..8adbb81 100644 --- a/platform/security/base/kyverno/helm-release.yaml +++ b/platform/security/base/kyverno/helm-release.yaml @@ -0,0 +1,31 @@ +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease + +metadata: + name: kyverno + namespace: security + +spec: + interval: 30m + + chart: + spec: + chart: kyverno + version: "3.3.7" + sourceRef: + kind: HelmRepository + name: kyverno + namespace: flux-system + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + valuesFrom: + - kind: ConfigMap + name: kyverno-values + valuesKey: values.yaml \ No newline at end of file diff --git a/platform/security/base/kyverno/helm-repository.yaml b/platform/security/base/kyverno/helm-repository.yaml new file mode 100644 index 0000000..b8eac36 --- /dev/null +++ b/platform/security/base/kyverno/helm-repository.yaml @@ -0,0 +1,10 @@ +apiVersion: source.toolkit.fluxcd.io/v1 +kind: HelmRepository + +metadata: + name: kyverno + namespace: flux-system + +spec: + interval: 24h + url: https://kyverno.github.io/kyverno \ No newline at end of file diff --git a/platform/security/base/kyverno/kustomization.yaml b/platform/security/base/kyverno/kustomization.yaml new file mode 100644 index 0000000..f8d6263 --- /dev/null +++ b/platform/security/base/kyverno/kustomization.yaml @@ -0,0 +1,14 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - helm-repository.yaml + - helm-release.yaml + +configMapGenerator: + - name: kyverno-values + files: + - values.yaml + +generatorOptions: + disableNameSuffixHash: true \ No newline at end of file diff --git a/platform/security/base/kyverno/values.yaml b/platform/security/base/kyverno/values.yaml index e69de29..b2f1a05 100644 --- a/platform/security/base/kyverno/values.yaml +++ b/platform/security/base/kyverno/values.yaml @@ -0,0 +1,22 @@ +replicaCount: 2 + +admissionController: + replicas: 2 + +backgroundController: + replicas: 2 + +cleanupController: + replicas: 2 + +reportsController: + replicas: 2 + +serviceMonitor: + enabled: true + + additionalLabels: + prometheus: kube-prometheus + +grafana: + enabled: false \ No newline at end of file diff --git a/platform/security/base/namespace.yaml b/platform/security/base/namespace.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/security/base/policies/disallow-hostpath.yaml b/platform/security/base/policies/disallow-hostpath.yaml new file mode 100644 index 0000000..bb1f7bb --- /dev/null +++ b/platform/security/base/policies/disallow-hostpath.yaml @@ -0,0 +1,36 @@ +apiVersion: kyverno.io/v1 +kind: ClusterPolicy + +metadata: + name: disallow-hostpath + +spec: + validationFailureAction: Audit + + background: true + + rules: + + - name: hostpath-volumes + + match: + any: + - resources: + kinds: + - Pod + + exclude: + any: + - resources: + namespaces: + - kube-system + - kyverno + - flux-system + + validate: + message: "HostPath volumes are not allowed." + + pattern: + spec: + =(volumes): + - X(hostPath): "null" \ No newline at end of file diff --git a/platform/security/base/policies/disallow-latest-tag.yaml b/platform/security/base/policies/disallow-latest-tag.yaml index e69de29..74b292a 100644 --- a/platform/security/base/policies/disallow-latest-tag.yaml +++ b/platform/security/base/policies/disallow-latest-tag.yaml @@ -0,0 +1,42 @@ +apiVersion: kyverno.io/v1 +kind: ClusterPolicy + +metadata: + name: disallow-latest-tag + +spec: + validationFailureAction: Audit + + background: true + + rules: + + - name: validate-image-tag + + match: + any: + - resources: + kinds: + - Deployment + - StatefulSet + - DaemonSet + - Job + - CronJob + + exclude: + any: + - resources: + namespaces: + - kube-system + - kyverno + - flux-system + + validate: + message: "Images must use a version tag and cannot use latest." + + pattern: + spec: + template: + spec: + containers: + - image: "!*:latest" \ No newline at end of file diff --git a/platform/security/base/policies/disallow-privileged.yaml b/platform/security/base/policies/disallow-privileged.yaml new file mode 100644 index 0000000..b48dcda --- /dev/null +++ b/platform/security/base/policies/disallow-privileged.yaml @@ -0,0 +1,37 @@ +apiVersion: kyverno.io/v1 +kind: ClusterPolicy + +metadata: + name: disallow-privileged + +spec: + validationFailureAction: Audit + + background: true + + rules: + + - name: privileged-container + + match: + any: + - resources: + kinds: + - Pod + + exclude: + any: + - resources: + namespaces: + - kube-system + - kyverno + - flux-system + + validate: + message: "Privileged containers are not allowed." + + pattern: + spec: + containers: + - securityContext: + privileged: "false" \ No newline at end of file diff --git a/platform/security/base/policies/kustomization.yaml b/platform/security/base/policies/kustomization.yaml new file mode 100644 index 0000000..89f7304 --- /dev/null +++ b/platform/security/base/policies/kustomization.yaml @@ -0,0 +1,15 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - require-probes.yaml + - require-limits.yaml + - disallow-latest-tag.yaml + - disallow-privileged.yaml + - disallow-hostpath.yaml + - require-readonly-rootfs.yaml + - require-non-root.yaml + - require-networkpolicy.yaml + - require-pdb.yaml + - require-labels.yaml + - policy-exception.yaml \ No newline at end of file diff --git a/platform/security/base/policies/policy-exception.yaml b/platform/security/base/policies/policy-exception.yaml new file mode 100644 index 0000000..40f8db1 --- /dev/null +++ b/platform/security/base/policies/policy-exception.yaml @@ -0,0 +1,20 @@ +apiVersion: kyverno.io/v2 +kind: PolicyException + +metadata: + name: system-namespaces-exception + namespace: kyverno + +spec: + exceptions: + - policyName: "*" + ruleNames: + - "*" + + match: + any: + - resources: + namespaces: + - kube-system + - kyverno + - flux-system \ No newline at end of file diff --git a/platform/security/base/policies/require-labels.yaml b/platform/security/base/policies/require-labels.yaml new file mode 100644 index 0000000..1f867eb --- /dev/null +++ b/platform/security/base/policies/require-labels.yaml @@ -0,0 +1,42 @@ +apiVersion: kyverno.io/v1 +kind: ClusterPolicy + +metadata: + name: require-labels + +spec: + validationFailureAction: Audit + + background: true + + rules: + + - name: require-standard-labels + + match: + any: + - resources: + kinds: + - Deployment + - StatefulSet + - DaemonSet + + exclude: + any: + - resources: + namespaces: + - kube-system + - kyverno + - flux-system + + validate: + + message: "Resources must include standard Kubernetes labels." + + pattern: + metadata: + labels: + app.kubernetes.io/name: "?*" + app.kubernetes.io/component: "?*" + app.kubernetes.io/part-of: "?*" + app.kubernetes.io/version: "?*" \ No newline at end of file diff --git a/platform/security/base/policies/require-limits.yaml b/platform/security/base/policies/require-limits.yaml index e69de29..6b1884f 100644 --- a/platform/security/base/policies/require-limits.yaml +++ b/platform/security/base/policies/require-limits.yaml @@ -0,0 +1,60 @@ +apiVersion: kyverno.io/v1 +kind: ClusterPolicy + +metadata: + name: require-resource-limits + +spec: + validationFailureAction: Audit + + background: true + + rules: + + - name: require-container-resources + + match: + any: + - resources: + kinds: + - Deployment + - StatefulSet + - DaemonSet + - Job + - CronJob + + exclude: + any: + - resources: + namespaces: + - kube-system + - kyverno + - flux-system + + validate: + message: >- + All containers must define CPU and memory requests and limits. + + foreach: + + - list: "request.object.spec.template.spec.containers" + + pattern: + resources: + requests: + cpu: "?*" + memory: "?*" + limits: + cpu: "?*" + memory: "?*" + + - list: "request.object.spec.template.spec.initContainers" + + pattern: + resources: + requests: + cpu: "?*" + memory: "?*" + limits: + cpu: "?*" + memory: "?*" \ No newline at end of file diff --git a/platform/security/base/policies/require-networkpolicy.yaml b/platform/security/base/policies/require-networkpolicy.yaml new file mode 100644 index 0000000..16d6187 --- /dev/null +++ b/platform/security/base/policies/require-networkpolicy.yaml @@ -0,0 +1,28 @@ +apiVersion: kyverno.io/v1 +kind: ClusterPolicy + +metadata: + name: require-networkpolicy + +spec: + validationFailureAction: Audit + + background: true + + rules: + + - name: require-networkpolicy-label + + match: + any: + - resources: + kinds: + - Deployment + + validate: + message: "Deployment must define networkpolicy.enabled=true label." + + pattern: + metadata: + labels: + networkpolicy.enabled: "true" \ No newline at end of file diff --git a/platform/security/base/policies/require-non-root.yaml b/platform/security/base/policies/require-non-root.yaml new file mode 100644 index 0000000..7d1093b --- /dev/null +++ b/platform/security/base/policies/require-non-root.yaml @@ -0,0 +1,40 @@ +apiVersion: kyverno.io/v1 +kind: ClusterPolicy + +metadata: + name: require-non-root + +spec: + validationFailureAction: Audit + + background: true + + rules: + + - name: run-as-non-root + + match: + any: + - resources: + kinds: + - Deployment + - StatefulSet + - DaemonSet + + exclude: + any: + - resources: + namespaces: + - kube-system + - kyverno + - flux-system + + validate: + message: "Containers must run as non-root." + + pattern: + spec: + template: + spec: + securityContext: + runAsNonRoot: true \ No newline at end of file diff --git a/platform/security/base/policies/require-pdb.yaml b/platform/security/base/policies/require-pdb.yaml new file mode 100644 index 0000000..26c1215 --- /dev/null +++ b/platform/security/base/policies/require-pdb.yaml @@ -0,0 +1,29 @@ +apiVersion: kyverno.io/v1 +kind: ClusterPolicy + +metadata: + name: require-pdb + +spec: + validationFailureAction: Audit + + background: true + + rules: + + - name: require-pdb-label + + match: + any: + - resources: + kinds: + - Deployment + + validate: + + message: "Deployments must define pdb.enabled=true label." + + pattern: + metadata: + labels: + pdb.enabled: "true" \ No newline at end of file diff --git a/platform/security/base/policies/require-probes.yaml b/platform/security/base/policies/require-probes.yaml index e69de29..b1ca1a3 100644 --- a/platform/security/base/policies/require-probes.yaml +++ b/platform/security/base/policies/require-probes.yaml @@ -0,0 +1,30 @@ +apiVersion: kyverno.io/v1 +kind: ClusterPolicy + +metadata: + name: require-probes + +spec: + validationFailureAction: Audit + + background: true + + rules: + - name: check-probes + + match: + any: + - resources: + kinds: + - Deployment + + validate: + message: "Containers must define liveness and readiness probes." + + pattern: + spec: + template: + spec: + containers: + - livenessProbe: "?*" + readinessProbe: "?*" \ No newline at end of file diff --git a/platform/security/base/policies/require-readonly-rootfs.yaml b/platform/security/base/policies/require-readonly-rootfs.yaml new file mode 100644 index 0000000..efa6fd0 --- /dev/null +++ b/platform/security/base/policies/require-readonly-rootfs.yaml @@ -0,0 +1,41 @@ +apiVersion: kyverno.io/v1 +kind: ClusterPolicy + +metadata: + name: require-readonly-rootfs + +spec: + validationFailureAction: Audit + + background: true + + rules: + + - name: readonly-root-filesystem + + match: + any: + - resources: + kinds: + - Deployment + - StatefulSet + - DaemonSet + + exclude: + any: + - resources: + namespaces: + - kube-system + - kyverno + - flux-system + + validate: + message: "Containers must use a read-only root filesystem." + + pattern: + spec: + template: + spec: + containers: + - securityContext: + readOnlyRootFilesystem: true \ No newline at end of file diff --git a/platform/security/base/policies/restrict-privileged.yaml b/platform/security/base/policies/restrict-privileged.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/security/base/sealed-secrets/helm-release.yaml b/platform/security/base/sealed-secrets/helm-release.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/security/base/sealed-secrets/values.yaml b/platform/security/base/sealed-secrets/values.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/security/base/external-secrets/helm-release.yaml b/platform/security/overlay/dev/kustomization.yaml similarity index 100% rename from platform/security/base/external-secrets/helm-release.yaml rename to platform/security/overlay/dev/kustomization.yaml diff --git a/platform/security/overlay/dev/security-namespace.yaml b/platform/security/overlay/dev/security-namespace.yaml new file mode 100644 index 0000000..0b345a8 --- /dev/null +++ b/platform/security/overlay/dev/security-namespace.yaml @@ -0,0 +1,5 @@ +apiVersion: v1 +kind: Namespace + +metadata: + name: dev \ No newline at end of file From 5e65228aa42bed1bca3b96a5c5bdbdb72b736806 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Wed, 22 Jul 2026 11:35:25 +0200 Subject: [PATCH 012/122] Added tracing --- README.md | 2 + apps/order-service/base/deployment.yaml | 4 ++ apps/payment-service/base/deployment.yaml | 4 ++ apps/product-service/base/deployment.yaml | 4 ++ apps/user-service/base/deployment.yaml | 4 ++ .../base/instrumentation/java-agent.yaml | 35 +++++++++++ .../base/instrumentation/kustomization.yaml | 6 ++ .../base/instrumentation/spring-boot.yaml | 45 ++++++++++++++ platform/tracing/base/kustomization.yaml | 8 +++ .../base/networkpolicy/allow-tracing.yaml | 41 +++++++++++++ .../kustomization.yaml} | 0 .../opentelemetry-collector/helm-release.yaml | 30 ++++++++++ .../helm-repository.yaml | 11 ++++ .../kustomization.yaml} | 0 .../opentelemetry-collector/pipelines.yaml | 51 ++++++++++++++++ .../base/opentelemetry-collector/values.yaml | 58 +++++++++++++++++++ platform/tracing/base/tempo/helm-release.yaml | 32 ++++++++++ .../tracing/base/tempo/helm-repository.yaml | 10 ++++ .../kustomization.yaml} | 0 platform/tracing/base/tempo/values.yaml | 43 ++++++++++++++ .../dev/kustomization.yaml} | 0 .../overlay/dev/tracing-namespace.yaml | 5 ++ 22 files changed, 393 insertions(+) create mode 100644 platform/tracing/base/instrumentation/java-agent.yaml create mode 100644 platform/tracing/base/instrumentation/kustomization.yaml create mode 100644 platform/tracing/base/instrumentation/spring-boot.yaml rename platform/tracing/base/{namespace.yaml => networkpolicy/kustomization.yaml} (100%) create mode 100644 platform/tracing/base/opentelemetry-collector/helm-release.yaml create mode 100644 platform/tracing/base/opentelemetry-collector/helm-repository.yaml rename platform/tracing/base/{pentelemetry-collector/helm-release.yaml => opentelemetry-collector/kustomization.yaml} (100%) create mode 100644 platform/tracing/base/opentelemetry-collector/pipelines.yaml create mode 100644 platform/tracing/base/opentelemetry-collector/values.yaml create mode 100644 platform/tracing/base/tempo/helm-repository.yaml rename platform/tracing/base/{pentelemetry-collector/pipelines.yaml => tempo/kustomization.yaml} (100%) rename platform/tracing/{base/pentelemetry-collector/values.yaml => overlay/dev/kustomization.yaml} (100%) create mode 100644 platform/tracing/overlay/dev/tracing-namespace.yaml diff --git a/README.md b/README.md index 8d1b7be..02dc433 100644 --- a/README.md +++ b/README.md @@ -1,5 +1,7 @@ # Kubernetes-argocd +Building it this way will help you understand not only Kubernetes, but also how production platforms are assembled: GitOps, observability, security, networking, and application instrumentation. + ### Architecture diff --git a/apps/order-service/base/deployment.yaml b/apps/order-service/base/deployment.yaml index 4a6fd2e..aa1d27e 100644 --- a/apps/order-service/base/deployment.yaml +++ b/apps/order-service/base/deployment.yaml @@ -3,6 +3,10 @@ kind: Deployment metadata: name: order-service + annotations: + + instrumentation.opentelemetry.io/inject-java: "true" + spec: replicas: 2 diff --git a/apps/payment-service/base/deployment.yaml b/apps/payment-service/base/deployment.yaml index afacaf4..d8e619a 100644 --- a/apps/payment-service/base/deployment.yaml +++ b/apps/payment-service/base/deployment.yaml @@ -3,6 +3,10 @@ kind: Deployment metadata: name: payment-service + annotations: + + instrumentation.opentelemetry.io/inject-java: "true" + spec: replicas: 2 diff --git a/apps/product-service/base/deployment.yaml b/apps/product-service/base/deployment.yaml index ff6f4d4..3679ba8 100644 --- a/apps/product-service/base/deployment.yaml +++ b/apps/product-service/base/deployment.yaml @@ -3,6 +3,10 @@ kind: Deployment metadata: name: product-service + annotations: + + instrumentation.opentelemetry.io/inject-java: "true" + spec: replicas: 2 diff --git a/apps/user-service/base/deployment.yaml b/apps/user-service/base/deployment.yaml index 915b948..a9bbb31 100644 --- a/apps/user-service/base/deployment.yaml +++ b/apps/user-service/base/deployment.yaml @@ -3,6 +3,10 @@ kind: Deployment metadata: name: user-service + annotations: + + instrumentation.opentelemetry.io/inject-java: "true" + spec: replicas: 2 diff --git a/platform/tracing/base/instrumentation/java-agent.yaml b/platform/tracing/base/instrumentation/java-agent.yaml new file mode 100644 index 0000000..b5077fe --- /dev/null +++ b/platform/tracing/base/instrumentation/java-agent.yaml @@ -0,0 +1,35 @@ +apiVersion: v1 +kind: ConfigMap + +metadata: + name: opentelemetry-java-agent-config + namespace: tracing + + +data: + + JAVA_TOOL_OPTIONS: >- + -javaagent:/otel/opentelemetry-javaagent.jar + + + OTEL_SERVICE_NAME: order-service + + + OTEL_EXPORTER_OTLP_ENDPOINT: >- + http://opentelemetry-collector.tracing.svc.cluster.local:4317 + + + OTEL_EXPORTER_OTLP_PROTOCOL: grpc + + + OTEL_TRACES_EXPORTER: otlp + + + OTEL_METRICS_EXPORTER: none + + + OTEL_LOGS_EXPORTER: none + + + OTEL_RESOURCE_ATTRIBUTES: >- + service.namespace=dev \ No newline at end of file diff --git a/platform/tracing/base/instrumentation/kustomization.yaml b/platform/tracing/base/instrumentation/kustomization.yaml new file mode 100644 index 0000000..5064b82 --- /dev/null +++ b/platform/tracing/base/instrumentation/kustomization.yaml @@ -0,0 +1,6 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - spring-boot.yaml + - java-agent.yaml \ No newline at end of file diff --git a/platform/tracing/base/instrumentation/spring-boot.yaml b/platform/tracing/base/instrumentation/spring-boot.yaml new file mode 100644 index 0000000..f20f89f --- /dev/null +++ b/platform/tracing/base/instrumentation/spring-boot.yaml @@ -0,0 +1,45 @@ +apiVersion: opentelemetry.io/v1alpha1 +kind: Instrumentation + +metadata: + name: spring-boot-instrumentation + namespace: tracing + +spec: + + exporter: + + endpoint: http://opentelemetry-collector.tracing.svc.cluster.local:4317 + + + propagators: + + - tracecontext + - baggage + - b3 + + + sampler: + + type: parentbased_traceidratio + + argument: "1.0" + + + java: + + image: ghcr.io/open-telemetry/opentelemetry-operator/autoinstrumentation-java:latest + + env: + + - name: OTEL_LOGS_EXPORTER + value: none + + - name: OTEL_METRICS_EXPORTER + value: none + + - name: OTEL_TRACES_EXPORTER + value: otlp + + - name: OTEL_RESOURCE_ATTRIBUTES + value: service.namespace=dev \ No newline at end of file diff --git a/platform/tracing/base/kustomization.yaml b/platform/tracing/base/kustomization.yaml index e69de29..1cd956a 100644 --- a/platform/tracing/base/kustomization.yaml +++ b/platform/tracing/base/kustomization.yaml @@ -0,0 +1,8 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - namespace.yaml + - tempo/ + - opentelemetry-collector/ + - networkpolicy/ \ No newline at end of file diff --git a/platform/tracing/base/networkpolicy/allow-tracing.yaml b/platform/tracing/base/networkpolicy/allow-tracing.yaml index e69de29..86d4fd0 100644 --- a/platform/tracing/base/networkpolicy/allow-tracing.yaml +++ b/platform/tracing/base/networkpolicy/allow-tracing.yaml @@ -0,0 +1,41 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + + name: allow-tracing + + namespace: tracing + + +spec: + + podSelector: + + matchLabels: + + app.kubernetes.io/name: opentelemetry-collector + + + policyTypes: + + - Ingress + + + ingress: + + + - from: + + - namespaceSelector: {} + + ports: + + - protocol: TCP + + port: 4317 + + + - protocol: TCP + + port: 4318 \ No newline at end of file diff --git a/platform/tracing/base/namespace.yaml b/platform/tracing/base/networkpolicy/kustomization.yaml similarity index 100% rename from platform/tracing/base/namespace.yaml rename to platform/tracing/base/networkpolicy/kustomization.yaml diff --git a/platform/tracing/base/opentelemetry-collector/helm-release.yaml b/platform/tracing/base/opentelemetry-collector/helm-release.yaml new file mode 100644 index 0000000..2f78d1b --- /dev/null +++ b/platform/tracing/base/opentelemetry-collector/helm-release.yaml @@ -0,0 +1,30 @@ +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease + +metadata: + name: opentelemetry-collector + namespace: tracing + + +spec: + + interval: 30m + + + chart: + spec: + chart: opentelemetry-collector + + version: "0.113.0" + + sourceRef: + kind: HelmRepository + name: open-telemetry + namespace: flux-system + + + valuesFrom: + + - kind: ConfigMap + name: otel-values + valuesKey: values.yaml \ No newline at end of file diff --git a/platform/tracing/base/opentelemetry-collector/helm-repository.yaml b/platform/tracing/base/opentelemetry-collector/helm-repository.yaml new file mode 100644 index 0000000..340129f --- /dev/null +++ b/platform/tracing/base/opentelemetry-collector/helm-repository.yaml @@ -0,0 +1,11 @@ +apiVersion: source.toolkit.fluxcd.io/v1 +kind: HelmRepository + +metadata: + name: open-telemetry + namespace: flux-system + +spec: + interval: 24h + + url: https://open-telemetry.github.io/opentelemetry-helm-charts \ No newline at end of file diff --git a/platform/tracing/base/pentelemetry-collector/helm-release.yaml b/platform/tracing/base/opentelemetry-collector/kustomization.yaml similarity index 100% rename from platform/tracing/base/pentelemetry-collector/helm-release.yaml rename to platform/tracing/base/opentelemetry-collector/kustomization.yaml diff --git a/platform/tracing/base/opentelemetry-collector/pipelines.yaml b/platform/tracing/base/opentelemetry-collector/pipelines.yaml new file mode 100644 index 0000000..e096221 --- /dev/null +++ b/platform/tracing/base/opentelemetry-collector/pipelines.yaml @@ -0,0 +1,51 @@ +config: + + receivers: + + otlp: + + protocols: + + grpc: + + endpoint: 0.0.0.0:4317 + + http: + + endpoint: 0.0.0.0:4318 + + + processors: + + batch: + + + exporters: + + otlp/tempo: + + endpoint: + tempo.tracing.svc.cluster.local:4317 + + tls: + + insecure: true + + + service: + + pipelines: + + traces: + + receivers: + + - otlp + + processors: + + - batch + + exporters: + + - otlp/tempo \ No newline at end of file diff --git a/platform/tracing/base/opentelemetry-collector/values.yaml b/platform/tracing/base/opentelemetry-collector/values.yaml new file mode 100644 index 0000000..ead4595 --- /dev/null +++ b/platform/tracing/base/opentelemetry-collector/values.yaml @@ -0,0 +1,58 @@ +mode: deployment + + +replicaCount: 2 + + +image: + + repository: otel/opentelemetry-collector-contrib + + +ports: + + otlp: + enabled: true + + containerPort: 4317 + + servicePort: 4317 + + protocol: TCP + + + otlp-http: + enabled: true + + containerPort: 4318 + + servicePort: 4318 + + protocol: TCP + + +config: + exporters: + + otlp/tempo: + + endpoint: tempo.tracing.svc.cluster.local:4317 + + tls: + insecure: true + + + service: + + pipelines: + + traces: + + receivers: + - otlp + + processors: + - batch + + exporters: + - otlp/tempo \ No newline at end of file diff --git a/platform/tracing/base/tempo/helm-release.yaml b/platform/tracing/base/tempo/helm-release.yaml index e69de29..65d2d5f 100644 --- a/platform/tracing/base/tempo/helm-release.yaml +++ b/platform/tracing/base/tempo/helm-release.yaml @@ -0,0 +1,32 @@ +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease + +metadata: + name: tempo + namespace: tracing + +spec: + interval: 30m + + chart: + spec: + chart: tempo + version: "1.18.2" + + sourceRef: + kind: HelmRepository + name: grafana + namespace: flux-system + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + valuesFrom: + - kind: ConfigMap + name: tempo-values + valuesKey: values.yaml \ No newline at end of file diff --git a/platform/tracing/base/tempo/helm-repository.yaml b/platform/tracing/base/tempo/helm-repository.yaml new file mode 100644 index 0000000..a10939e --- /dev/null +++ b/platform/tracing/base/tempo/helm-repository.yaml @@ -0,0 +1,10 @@ +apiVersion: source.toolkit.fluxcd.io/v1 +kind: HelmRepository + +metadata: + name: grafana + namespace: flux-system + +spec: + interval: 24h + url: https://grafana.github.io/helm-charts \ No newline at end of file diff --git a/platform/tracing/base/pentelemetry-collector/pipelines.yaml b/platform/tracing/base/tempo/kustomization.yaml similarity index 100% rename from platform/tracing/base/pentelemetry-collector/pipelines.yaml rename to platform/tracing/base/tempo/kustomization.yaml diff --git a/platform/tracing/base/tempo/values.yaml b/platform/tracing/base/tempo/values.yaml index e69de29..d083a73 100644 --- a/platform/tracing/base/tempo/values.yaml +++ b/platform/tracing/base/tempo/values.yaml @@ -0,0 +1,43 @@ +tempo: + reportingEnabled: false + +tempoQuery: + enabled: true + + +storage: + trace: + backend: local + + local: + path: /var/tempo/traces + + +persistence: + enabled: true + + storageClassName: gp3 + + size: 20Gi + + +service: + type: ClusterIP + + +metricsGenerator: + enabled: true + + remoteWrite: + - url: http://prometheus-stack-kube-prom-prometheus.monitoring.svc.cluster.local:9090/api/v1/write + + +resources: + + requests: + cpu: 250m + memory: 512Mi + + limits: + cpu: 1000m + memory: 1Gi \ No newline at end of file diff --git a/platform/tracing/base/pentelemetry-collector/values.yaml b/platform/tracing/overlay/dev/kustomization.yaml similarity index 100% rename from platform/tracing/base/pentelemetry-collector/values.yaml rename to platform/tracing/overlay/dev/kustomization.yaml diff --git a/platform/tracing/overlay/dev/tracing-namespace.yaml b/platform/tracing/overlay/dev/tracing-namespace.yaml new file mode 100644 index 0000000..0b345a8 --- /dev/null +++ b/platform/tracing/overlay/dev/tracing-namespace.yaml @@ -0,0 +1,5 @@ +apiVersion: v1 +kind: Namespace + +metadata: + name: dev \ No newline at end of file From dcf4dc304b96f944063370af3e698fce39be4b0d Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Sun, 26 Jul 2026 21:40:56 +0200 Subject: [PATCH 013/122] Added monitoring --- README.md | 31 +++++++++++++++++++ ...ing.txt => applicationset-monitoring.yaml} | 4 +-- .../dev/flux/ingress.yaml | 0 .../dev/ingress-namespace.yaml | 0 .../dev/kustomization.yaml | 0 .../dev/kustomization.yaml | 0 .../{overlay => overlays}/dev/namespace.yaml | 0 .../dev/kustomization.yaml | 0 platform/overlays/dev/kustomization.yaml | 10 ++++++ .../security/overlay/dev/kustomization.yaml | 0 .../security/overlays/dev/kustomization.yaml | 6 ++++ .../dev/security-namespace.yaml | 0 .../storage/base/backup/backup-schedules.yaml | 0 platform/storage/base/backup/velero/helm.yaml | 0 .../storage/base/backup/velero/values.yaml | 0 .../base/ebs-csi-driver/helm-release.yaml | 0 .../storage/base/ebs-csi-driver/values.yaml | 0 .../base/efs-csi-driver/helm-release.yaml | 0 .../storage/base/efs-csi-driver/values.yaml | 0 platform/storage/base/kustomization.yaml | 0 platform/storage/base/namespace.yaml | 0 platform/storage/base/storageclasses/efs.yaml | 0 platform/storage/base/storageclasses/gp3.yaml | 0 platform/storage/base/storageclasses/io2.yaml | 0 .../base/volume-snapshots/schedules.yaml | 0 .../base/volume-snapshots/snapshotclass.yaml | 0 .../base/instrumentation/spring-boot.yaml | 1 - platform/tracing/base/kustomization.yaml | 2 +- .../base/networkpolicy/allow-tracing.yaml | 2 -- .../base/networkpolicy/kustomization.yaml | 6 ++++ .../opentelemetry-collector/helm-release.yaml | 1 - .../kustomization.yaml | 9 ++++++ platform/tracing/base/tempo/helm-release.yaml | 1 - .../tracing/base/tempo/kustomization.yaml | 8 +++++ .../tracing/overlay/dev/kustomization.yaml | 0 .../tracing/overlays/dev/kustomization.yaml | 7 +++++ .../dev/tracing-namespace.yaml | 0 37 files changed, 80 insertions(+), 8 deletions(-) rename argocd/dev/{applicationset-monitoring.txt => applicationset-monitoring.yaml} (87%) rename platform/ingress/{overlay => overlays}/dev/flux/ingress.yaml (100%) rename platform/ingress/{overlay => overlays}/dev/ingress-namespace.yaml (100%) rename platform/ingress/{overlay => overlays}/dev/kustomization.yaml (100%) rename platform/logging/{overlay => overlays}/dev/kustomization.yaml (100%) rename platform/logging/{overlay => overlays}/dev/namespace.yaml (100%) rename platform/networking/{overlay => overlays}/dev/kustomization.yaml (100%) create mode 100644 platform/overlays/dev/kustomization.yaml delete mode 100644 platform/security/overlay/dev/kustomization.yaml create mode 100644 platform/security/overlays/dev/kustomization.yaml rename platform/security/{overlay => overlays}/dev/security-namespace.yaml (100%) delete mode 100644 platform/storage/base/backup/backup-schedules.yaml delete mode 100644 platform/storage/base/backup/velero/helm.yaml delete mode 100644 platform/storage/base/backup/velero/values.yaml delete mode 100644 platform/storage/base/ebs-csi-driver/helm-release.yaml delete mode 100644 platform/storage/base/ebs-csi-driver/values.yaml delete mode 100644 platform/storage/base/efs-csi-driver/helm-release.yaml delete mode 100644 platform/storage/base/efs-csi-driver/values.yaml delete mode 100644 platform/storage/base/kustomization.yaml delete mode 100644 platform/storage/base/namespace.yaml delete mode 100644 platform/storage/base/storageclasses/efs.yaml delete mode 100644 platform/storage/base/storageclasses/gp3.yaml delete mode 100644 platform/storage/base/storageclasses/io2.yaml delete mode 100644 platform/storage/base/volume-snapshots/schedules.yaml delete mode 100644 platform/storage/base/volume-snapshots/snapshotclass.yaml delete mode 100644 platform/tracing/overlay/dev/kustomization.yaml create mode 100644 platform/tracing/overlays/dev/kustomization.yaml rename platform/tracing/{overlay => overlays}/dev/tracing-namespace.yaml (100%) diff --git a/README.md b/README.md index 02dc433..43c9445 100644 --- a/README.md +++ b/README.md @@ -425,3 +425,34 @@ infrastructure │ ├── cluster-secret-store.yaml │ ├── ingress.yaml │ └── namespace-database.yaml + + +platform/ +├── monitoring/ +│ ├── base/ +│ └── overlays/ +│ ├── dev/ +│ ├── staging/ +│ └── prod/ +├── logging/ +│ ├── base/ +│ └── overlays/ +│ ├── dev/ +│ ├── staging/ +│ └── prod/ +├── networking/ +│ ├── base/ +│ └── overlays/ +│ ├── dev/ +│ ├── staging/ +│ └── prod/ +└── tracing/ +| ├── base/ +| └── overlays/ +| ├── dev/ +| ├── staging/ +| └── prod/ +├── overlays/ +│ ├── dev/ +│ ├── staging/ +│ └── prod/ \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.txt b/argocd/dev/applicationset-monitoring.yaml similarity index 87% rename from argocd/dev/applicationset-monitoring.txt rename to argocd/dev/applicationset-monitoring.yaml index 6ea8e06..34b5735 100644 --- a/argocd/dev/applicationset-monitoring.txt +++ b/argocd/dev/applicationset-monitoring.yaml @@ -10,8 +10,8 @@ spec: - list: elements: - name: monitoring - path: platform/monitoring/overlays/dev - namespace: monitoring + path: platform/overlays/dev + namespace: dev template: metadata: diff --git a/platform/ingress/overlay/dev/flux/ingress.yaml b/platform/ingress/overlays/dev/flux/ingress.yaml similarity index 100% rename from platform/ingress/overlay/dev/flux/ingress.yaml rename to platform/ingress/overlays/dev/flux/ingress.yaml diff --git a/platform/ingress/overlay/dev/ingress-namespace.yaml b/platform/ingress/overlays/dev/ingress-namespace.yaml similarity index 100% rename from platform/ingress/overlay/dev/ingress-namespace.yaml rename to platform/ingress/overlays/dev/ingress-namespace.yaml diff --git a/platform/ingress/overlay/dev/kustomization.yaml b/platform/ingress/overlays/dev/kustomization.yaml similarity index 100% rename from platform/ingress/overlay/dev/kustomization.yaml rename to platform/ingress/overlays/dev/kustomization.yaml diff --git a/platform/logging/overlay/dev/kustomization.yaml b/platform/logging/overlays/dev/kustomization.yaml similarity index 100% rename from platform/logging/overlay/dev/kustomization.yaml rename to platform/logging/overlays/dev/kustomization.yaml diff --git a/platform/logging/overlay/dev/namespace.yaml b/platform/logging/overlays/dev/namespace.yaml similarity index 100% rename from platform/logging/overlay/dev/namespace.yaml rename to platform/logging/overlays/dev/namespace.yaml diff --git a/platform/networking/overlay/dev/kustomization.yaml b/platform/networking/overlays/dev/kustomization.yaml similarity index 100% rename from platform/networking/overlay/dev/kustomization.yaml rename to platform/networking/overlays/dev/kustomization.yaml diff --git a/platform/overlays/dev/kustomization.yaml b/platform/overlays/dev/kustomization.yaml new file mode 100644 index 0000000..d76d8a8 --- /dev/null +++ b/platform/overlays/dev/kustomization.yaml @@ -0,0 +1,10 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - ../../ingress/overlays/dev + - ../../logging/overlays/dev + - ../../monitoring/overlays/dev + - ../../networking/overlays/dev + - ../../security/overlays/dev + - ../../tracing/overlays/dev \ No newline at end of file diff --git a/platform/security/overlay/dev/kustomization.yaml b/platform/security/overlay/dev/kustomization.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/security/overlays/dev/kustomization.yaml b/platform/security/overlays/dev/kustomization.yaml new file mode 100644 index 0000000..994cfb5 --- /dev/null +++ b/platform/security/overlays/dev/kustomization.yaml @@ -0,0 +1,6 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + + +resources: + - ../../base/ \ No newline at end of file diff --git a/platform/security/overlay/dev/security-namespace.yaml b/platform/security/overlays/dev/security-namespace.yaml similarity index 100% rename from platform/security/overlay/dev/security-namespace.yaml rename to platform/security/overlays/dev/security-namespace.yaml diff --git a/platform/storage/base/backup/backup-schedules.yaml b/platform/storage/base/backup/backup-schedules.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/storage/base/backup/velero/helm.yaml b/platform/storage/base/backup/velero/helm.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/storage/base/backup/velero/values.yaml b/platform/storage/base/backup/velero/values.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/storage/base/ebs-csi-driver/helm-release.yaml b/platform/storage/base/ebs-csi-driver/helm-release.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/storage/base/ebs-csi-driver/values.yaml b/platform/storage/base/ebs-csi-driver/values.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/storage/base/efs-csi-driver/helm-release.yaml b/platform/storage/base/efs-csi-driver/helm-release.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/storage/base/efs-csi-driver/values.yaml b/platform/storage/base/efs-csi-driver/values.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/storage/base/kustomization.yaml b/platform/storage/base/kustomization.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/storage/base/namespace.yaml b/platform/storage/base/namespace.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/storage/base/storageclasses/efs.yaml b/platform/storage/base/storageclasses/efs.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/storage/base/storageclasses/gp3.yaml b/platform/storage/base/storageclasses/gp3.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/storage/base/storageclasses/io2.yaml b/platform/storage/base/storageclasses/io2.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/storage/base/volume-snapshots/schedules.yaml b/platform/storage/base/volume-snapshots/schedules.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/storage/base/volume-snapshots/snapshotclass.yaml b/platform/storage/base/volume-snapshots/snapshotclass.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/tracing/base/instrumentation/spring-boot.yaml b/platform/tracing/base/instrumentation/spring-boot.yaml index f20f89f..a0592c7 100644 --- a/platform/tracing/base/instrumentation/spring-boot.yaml +++ b/platform/tracing/base/instrumentation/spring-boot.yaml @@ -3,7 +3,6 @@ kind: Instrumentation metadata: name: spring-boot-instrumentation - namespace: tracing spec: diff --git a/platform/tracing/base/kustomization.yaml b/platform/tracing/base/kustomization.yaml index 1cd956a..4a8f26d 100644 --- a/platform/tracing/base/kustomization.yaml +++ b/platform/tracing/base/kustomization.yaml @@ -2,7 +2,7 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - namespace.yaml + - tracing-namespace.yaml - tempo/ - opentelemetry-collector/ - networkpolicy/ \ No newline at end of file diff --git a/platform/tracing/base/networkpolicy/allow-tracing.yaml b/platform/tracing/base/networkpolicy/allow-tracing.yaml index 86d4fd0..8adff7b 100644 --- a/platform/tracing/base/networkpolicy/allow-tracing.yaml +++ b/platform/tracing/base/networkpolicy/allow-tracing.yaml @@ -5,8 +5,6 @@ metadata: name: allow-tracing - namespace: tracing - spec: diff --git a/platform/tracing/base/networkpolicy/kustomization.yaml b/platform/tracing/base/networkpolicy/kustomization.yaml index e69de29..ac60293 100644 --- a/platform/tracing/base/networkpolicy/kustomization.yaml +++ b/platform/tracing/base/networkpolicy/kustomization.yaml @@ -0,0 +1,6 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + + +resources: + - allow-tracing.yaml \ No newline at end of file diff --git a/platform/tracing/base/opentelemetry-collector/helm-release.yaml b/platform/tracing/base/opentelemetry-collector/helm-release.yaml index 2f78d1b..a67b969 100644 --- a/platform/tracing/base/opentelemetry-collector/helm-release.yaml +++ b/platform/tracing/base/opentelemetry-collector/helm-release.yaml @@ -3,7 +3,6 @@ kind: HelmRelease metadata: name: opentelemetry-collector - namespace: tracing spec: diff --git a/platform/tracing/base/opentelemetry-collector/kustomization.yaml b/platform/tracing/base/opentelemetry-collector/kustomization.yaml index e69de29..b7eeecc 100644 --- a/platform/tracing/base/opentelemetry-collector/kustomization.yaml +++ b/platform/tracing/base/opentelemetry-collector/kustomization.yaml @@ -0,0 +1,9 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + + +resources: + - helm-release.yaml + - help-repository.yaml + - pipelines.yaml + - values.yaml \ No newline at end of file diff --git a/platform/tracing/base/tempo/helm-release.yaml b/platform/tracing/base/tempo/helm-release.yaml index 65d2d5f..763c576 100644 --- a/platform/tracing/base/tempo/helm-release.yaml +++ b/platform/tracing/base/tempo/helm-release.yaml @@ -3,7 +3,6 @@ kind: HelmRelease metadata: name: tempo - namespace: tracing spec: interval: 30m diff --git a/platform/tracing/base/tempo/kustomization.yaml b/platform/tracing/base/tempo/kustomization.yaml index e69de29..429d734 100644 --- a/platform/tracing/base/tempo/kustomization.yaml +++ b/platform/tracing/base/tempo/kustomization.yaml @@ -0,0 +1,8 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + + +resources: + - helm-release.yaml + - help-repository.yaml + - values.yaml \ No newline at end of file diff --git a/platform/tracing/overlay/dev/kustomization.yaml b/platform/tracing/overlay/dev/kustomization.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/tracing/overlays/dev/kustomization.yaml b/platform/tracing/overlays/dev/kustomization.yaml new file mode 100644 index 0000000..c6ce0a9 --- /dev/null +++ b/platform/tracing/overlays/dev/kustomization.yaml @@ -0,0 +1,7 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +namespace: dev + +resources: + - ../../base \ No newline at end of file diff --git a/platform/tracing/overlay/dev/tracing-namespace.yaml b/platform/tracing/overlays/dev/tracing-namespace.yaml similarity index 100% rename from platform/tracing/overlay/dev/tracing-namespace.yaml rename to platform/tracing/overlays/dev/tracing-namespace.yaml From c2c872a96d586d4c5e97b9c9c329c077f6358c3e Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 28 Jul 2026 14:27:26 +0000 Subject: [PATCH 014/122] Promote product-service to eafec6d57f9e546a989fe551bb2ee2cf0b92bfbd --- apps/product-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/product-service/overlays/dev/kustomization.yaml b/apps/product-service/overlays/dev/kustomization.yaml index 40bfdbd..8c4da11 100644 --- a/apps/product-service/overlays/dev/kustomization.yaml +++ b/apps/product-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service - newTag: 345d54e836039442ab120287b7961cd092761182 + newTag: eafec6d57f9e546a989fe551bb2ee2cf0b92bfbd From 848df19fce48e491d142906e8251dc728266abc8 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 28 Jul 2026 14:27:41 +0000 Subject: [PATCH 015/122] Promote order-service to eafec6d57f9e546a989fe551bb2ee2cf0b92bfbd --- apps/order-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/order-service/overlays/dev/kustomization.yaml b/apps/order-service/overlays/dev/kustomization.yaml index 47c5a38..372698c 100644 --- a/apps/order-service/overlays/dev/kustomization.yaml +++ b/apps/order-service/overlays/dev/kustomization.yaml @@ -10,7 +10,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service - newTag: 345d54e836039442ab120287b7961cd092761182 + newTag: eafec6d57f9e546a989fe551bb2ee2cf0b92bfbd replicas: - count: 1 From 8335ddcb10fa7bc59c81d8d2fc363c19dfbef7a6 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 28 Jul 2026 14:27:44 +0000 Subject: [PATCH 016/122] Promote payment-service to eafec6d57f9e546a989fe551bb2ee2cf0b92bfbd --- apps/payment-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/payment-service/overlays/dev/kustomization.yaml b/apps/payment-service/overlays/dev/kustomization.yaml index f663cfa..d91cc82 100644 --- a/apps/payment-service/overlays/dev/kustomization.yaml +++ b/apps/payment-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service - newTag: 345d54e836039442ab120287b7961cd092761182 + newTag: eafec6d57f9e546a989fe551bb2ee2cf0b92bfbd From cad7e74516630a56ff05de0324a8297f4ba542ce Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 28 Jul 2026 14:27:58 +0000 Subject: [PATCH 017/122] Promote user-service to eafec6d57f9e546a989fe551bb2ee2cf0b92bfbd --- apps/user-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/user-service/overlays/dev/kustomization.yaml b/apps/user-service/overlays/dev/kustomization.yaml index d6ffecf..4ab8fd8 100644 --- a/apps/user-service/overlays/dev/kustomization.yaml +++ b/apps/user-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service - newTag: 345d54e836039442ab120287b7961cd092761182 + newTag: eafec6d57f9e546a989fe551bb2ee2cf0b92bfbd From 79029d221f8a49f1a5155f7fb7ec9f3d8a5ecb3e Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 28 Jul 2026 16:43:24 +0200 Subject: [PATCH 018/122] Updated the platform resources --- argocd/dev/applicationset-apps.yaml | 1 + argocd/dev/applicationset-infra.yaml | 1 + argocd/dev/applicationset-monitoring.yaml | 3 ++- argocd/dev/kustomization.yaml | 2 +- argocd/dev/root-app.yaml | 3 +-- infrastructure/overlay/dev/ingress.yaml | 2 +- .../base/aws-load-balancer-controller/kustomization.yaml | 7 +++++++ platform/ingress/base/cert-manager/kustomization.yaml | 8 ++++++++ platform/ingress/base/external-dns/kustomization.yaml | 7 +++++++ 9 files changed, 29 insertions(+), 5 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 516f6ee..0320df7 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -37,4 +37,5 @@ spec: syncOptions: - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 7c553f8..280d561 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -35,4 +35,5 @@ spec: selfHeal: true syncOptions: - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 34b5735..f6011b3 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,4 +32,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 2925759..ff7673f 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,5 +4,5 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - # - applicationset-monitoring.yaml + - applicationset-monitoring.yaml \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index b57edb5..4d5040d 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,5 +20,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/infrastructure/overlay/dev/ingress.yaml b/infrastructure/overlay/dev/ingress.yaml index e25b6cc..4937212 100644 --- a/infrastructure/overlay/dev/ingress.yaml +++ b/infrastructure/overlay/dev/ingress.yaml @@ -11,7 +11,7 @@ metadata: # HTTPS configuration alb.ingress.kubernetes.io/listen-ports: '[{"HTTP":80},{"HTTPS":443}]' - alb.ingress.kubernetes.io/certificate-arn: arn:aws:acm:us-east-1:579871530627:certificate/eb8a2976-d497-462a-8bd1-2603b0309ec2 + alb.ingress.kubernetes.io/certificate-arn: arn:aws:acm:us-east-1:579871530627:certificate/dca3c1a0-b8ed-494c-b512-213630efd2dd # Redirect HTTP to HTTPS alb.ingress.kubernetes.io/ssl-redirect: '443' diff --git a/platform/ingress/base/aws-load-balancer-controller/kustomization.yaml b/platform/ingress/base/aws-load-balancer-controller/kustomization.yaml index e69de29..788894f 100644 --- a/platform/ingress/base/aws-load-balancer-controller/kustomization.yaml +++ b/platform/ingress/base/aws-load-balancer-controller/kustomization.yaml @@ -0,0 +1,7 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - values.yaml + - helm-release.yaml + - help-repository.yaml \ No newline at end of file diff --git a/platform/ingress/base/cert-manager/kustomization.yaml b/platform/ingress/base/cert-manager/kustomization.yaml index e69de29..29924c4 100644 --- a/platform/ingress/base/cert-manager/kustomization.yaml +++ b/platform/ingress/base/cert-manager/kustomization.yaml @@ -0,0 +1,8 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - values.yaml + - helm-release.yaml + - help-repository.yaml + - clusterissuers/letsencrypt.yaml \ No newline at end of file diff --git a/platform/ingress/base/external-dns/kustomization.yaml b/platform/ingress/base/external-dns/kustomization.yaml index e69de29..788894f 100644 --- a/platform/ingress/base/external-dns/kustomization.yaml +++ b/platform/ingress/base/external-dns/kustomization.yaml @@ -0,0 +1,7 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - values.yaml + - helm-release.yaml + - help-repository.yaml \ No newline at end of file From bb9e6c935afb7bc8b67c8f43c18e7e2ea96f2e10 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 28 Jul 2026 17:00:28 +0200 Subject: [PATCH 019/122] Updated the platform resources --- argocd/dev/applicationset-apps.yaml | 3 +-- argocd/dev/applicationset-infra.yaml | 3 +-- argocd/dev/applicationset-monitoring.yaml | 1 + argocd/dev/kustomization.yaml | 1 + argocd/dev/root-app.yaml | 3 ++- infrastructure/overlay/dev/user-db-secret.yaml | 2 +- 6 files changed, 7 insertions(+), 6 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 0320df7..513d7f4 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -37,5 +37,4 @@ spec: syncOptions: - CreateNamespace=true - - \ No newline at end of file + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 280d561..6836bd7 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -35,5 +35,4 @@ spec: selfHeal: true syncOptions: - CreateNamespace=true - - \ No newline at end of file + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index f6011b3..1a8a3ff 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -33,4 +33,5 @@ spec: automated: prune: true selfHeal: true + \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index ff7673f..90cc3b1 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -5,4 +5,5 @@ resources: - applicationset-apps.yaml - applicationset-infra.yaml - applicationset-monitoring.yaml + \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 4d5040d..641c453 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,4 +20,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/infrastructure/overlay/dev/user-db-secret.yaml b/infrastructure/overlay/dev/user-db-secret.yaml index a4a7a4b..c8d51a9 100644 --- a/infrastructure/overlay/dev/user-db-secret.yaml +++ b/infrastructure/overlay/dev/user-db-secret.yaml @@ -15,4 +15,4 @@ spec: dataFrom: - extract: - key: /prod/user/db \ No newline at end of file + key: /dev/user/db \ No newline at end of file From 7b2447699608a0185246947b035baf77e0376de2 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 28 Jul 2026 17:15:35 +0200 Subject: [PATCH 020/122] Updated the platform resources --- apps/payment-service/base/deployment.yaml | 2 ++ apps/product-service/base/deployment.yaml | 2 ++ apps/user-service/base/deployment.yaml | 2 ++ argocd/dev/applicationset-apps.yaml | 3 +-- argocd/dev/applicationset-infra.yaml | 3 +-- argocd/dev/applicationset-monitoring.yaml | 4 +--- argocd/dev/kustomization.yaml | 1 - argocd/dev/root-app.yaml | 3 +-- 8 files changed, 10 insertions(+), 10 deletions(-) diff --git a/apps/payment-service/base/deployment.yaml b/apps/payment-service/base/deployment.yaml index d8e619a..1e9901a 100644 --- a/apps/payment-service/base/deployment.yaml +++ b/apps/payment-service/base/deployment.yaml @@ -28,6 +28,8 @@ spec: metadata: labels: app: payment-service + networkpolicy.enabled: "true" + pdb.enabled: "true" spec: terminationGracePeriodSeconds: 30 diff --git a/apps/product-service/base/deployment.yaml b/apps/product-service/base/deployment.yaml index 3679ba8..bf9beb9 100644 --- a/apps/product-service/base/deployment.yaml +++ b/apps/product-service/base/deployment.yaml @@ -28,6 +28,8 @@ spec: metadata: labels: app: product-service + networkpolicy.enabled: "true" + pdb.enabled: "true" spec: terminationGracePeriodSeconds: 30 diff --git a/apps/user-service/base/deployment.yaml b/apps/user-service/base/deployment.yaml index a9bbb31..8fceae7 100644 --- a/apps/user-service/base/deployment.yaml +++ b/apps/user-service/base/deployment.yaml @@ -28,6 +28,8 @@ spec: metadata: labels: app: user-service + networkpolicy.enabled: "true" + pdb.enabled: "true" spec: terminationGracePeriodSeconds: 30 diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 513d7f4..d891f32 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,5 +36,4 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 6836bd7..bb80e3c 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,5 +34,4 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 1a8a3ff..72d99c1 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,6 +32,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 90cc3b1..ff7673f 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -5,5 +5,4 @@ resources: - applicationset-apps.yaml - applicationset-infra.yaml - applicationset-monitoring.yaml - \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 641c453..76495e1 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,5 +20,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file From f6cff88847d1e2d5884a2ec4e5395c5c4473a651 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 28 Jul 2026 17:24:53 +0200 Subject: [PATCH 021/122] Updated the platform resources --- apps/payment-service/base/deployment.yaml | 2 -- apps/product-service/base/deployment.yaml | 2 -- apps/user-service/base/deployment.yaml | 2 -- argocd/dev/applicationset-apps.yaml | 3 ++- argocd/dev/applicationset-infra.yaml | 3 ++- argocd/dev/applicationset-monitoring.yaml | 3 ++- argocd/dev/root-app.yaml | 3 ++- 7 files changed, 8 insertions(+), 10 deletions(-) diff --git a/apps/payment-service/base/deployment.yaml b/apps/payment-service/base/deployment.yaml index 1e9901a..8ca16dd 100644 --- a/apps/payment-service/base/deployment.yaml +++ b/apps/payment-service/base/deployment.yaml @@ -15,8 +15,6 @@ spec: selector: matchLabels: app: payment-service - networkpolicy.enabled: "true" - pdb.enabled: "true" strategy: type: RollingUpdate diff --git a/apps/product-service/base/deployment.yaml b/apps/product-service/base/deployment.yaml index bf9beb9..2b7649b 100644 --- a/apps/product-service/base/deployment.yaml +++ b/apps/product-service/base/deployment.yaml @@ -15,8 +15,6 @@ spec: selector: matchLabels: app: product-service - networkpolicy.enabled: "true" - pdb.enabled: "true" strategy: type: RollingUpdate diff --git a/apps/user-service/base/deployment.yaml b/apps/user-service/base/deployment.yaml index 8fceae7..8060d2b 100644 --- a/apps/user-service/base/deployment.yaml +++ b/apps/user-service/base/deployment.yaml @@ -15,8 +15,6 @@ spec: selector: matchLabels: app: user-service - networkpolicy.enabled: "true" - pdb.enabled: "true" strategy: type: RollingUpdate diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index d891f32..651b944 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,4 +36,5 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index bb80e3c..0e2ee45 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,4 +34,5 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 72d99c1..0b71483 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,4 +32,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 76495e1..47f4512 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,4 +20,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file From 6adb22fd4360016561a492ea0766c5de93986e68 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 28 Jul 2026 15:50:39 +0000 Subject: [PATCH 022/122] Promote product-service to cc4950da0f80d7c9c44c52192faec727123b8a98 --- apps/product-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/product-service/overlays/dev/kustomization.yaml b/apps/product-service/overlays/dev/kustomization.yaml index 8c4da11..ff3ed92 100644 --- a/apps/product-service/overlays/dev/kustomization.yaml +++ b/apps/product-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service - newTag: eafec6d57f9e546a989fe551bb2ee2cf0b92bfbd + newTag: cc4950da0f80d7c9c44c52192faec727123b8a98 From e133baa158b89d2f61e4e8ac080eb55f09f657a9 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 28 Jul 2026 15:51:07 +0000 Subject: [PATCH 023/122] Promote order-service to cc4950da0f80d7c9c44c52192faec727123b8a98 --- apps/order-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/order-service/overlays/dev/kustomization.yaml b/apps/order-service/overlays/dev/kustomization.yaml index 372698c..99c7f4e 100644 --- a/apps/order-service/overlays/dev/kustomization.yaml +++ b/apps/order-service/overlays/dev/kustomization.yaml @@ -10,7 +10,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service - newTag: eafec6d57f9e546a989fe551bb2ee2cf0b92bfbd + newTag: cc4950da0f80d7c9c44c52192faec727123b8a98 replicas: - count: 1 From 11fdf4e7e9259688388bb5276db0116db82bb5fc Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 28 Jul 2026 15:51:08 +0000 Subject: [PATCH 024/122] Promote user-service to cc4950da0f80d7c9c44c52192faec727123b8a98 --- apps/user-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/user-service/overlays/dev/kustomization.yaml b/apps/user-service/overlays/dev/kustomization.yaml index 4ab8fd8..8a5b92c 100644 --- a/apps/user-service/overlays/dev/kustomization.yaml +++ b/apps/user-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service - newTag: eafec6d57f9e546a989fe551bb2ee2cf0b92bfbd + newTag: cc4950da0f80d7c9c44c52192faec727123b8a98 From 481fe3c1c8333f05ef348c00aa555eb071d493cf Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 28 Jul 2026 15:51:17 +0000 Subject: [PATCH 025/122] Promote payment-service to cc4950da0f80d7c9c44c52192faec727123b8a98 --- apps/payment-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/payment-service/overlays/dev/kustomization.yaml b/apps/payment-service/overlays/dev/kustomization.yaml index d91cc82..06b67e9 100644 --- a/apps/payment-service/overlays/dev/kustomization.yaml +++ b/apps/payment-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service - newTag: eafec6d57f9e546a989fe551bb2ee2cf0b92bfbd + newTag: cc4950da0f80d7c9c44c52192faec727123b8a98 From 7a45f36282ce92bca77f16553c9cb25233cb1e3a Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 28 Jul 2026 17:54:31 +0200 Subject: [PATCH 026/122] Updated the platform resources --- argocd/dev/applicationset-apps.yaml | 3 +-- argocd/dev/applicationset-infra.yaml | 3 +-- argocd/dev/applicationset-monitoring.yaml | 3 +-- argocd/dev/kustomization.yaml | 3 +-- argocd/dev/root-app.yaml | 3 +-- 5 files changed, 5 insertions(+), 10 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 651b944..197f11e 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,5 +36,4 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 0e2ee45..232eda5 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,5 +34,4 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 0b71483..1d79556 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,5 +32,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index ff7673f..c13e6f0 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,5 +4,4 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml - \ No newline at end of file + - applicationset-monitoring.yaml \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 47f4512..76495e1 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,5 +20,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file From 1c2dae2faa2cc4d9649a800746ecc1d50d9300a2 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Wed, 29 Jul 2026 22:15:57 +0200 Subject: [PATCH 027/122] Modified the ingress, logging and monitoring folder of the platform --- .../aws-load-balancer-controller.yaml | 41 ++++++++++ .../kustomization.yaml | 4 +- .../helm-release.yaml | 30 -------- .../helm-repository.yaml | 10 --- .../aws-load-balancer-controller/value.yaml | 17 ----- .../base/cert-manager/cert-manager.yaml | 18 +++++ .../clusterissuers/letsencrypt.yaml | 2 +- .../base/cert-manager/helm-release.yaml | 28 ------- .../base/cert-manager/helm-repository.yaml | 10 --- .../base/cert-manager/kustomization.yaml | 6 +- .../ingress/base/cert-manager/values.yaml | 11 --- .../base/external-dns/external-dns.yaml | 45 +++++++++++ .../base/external-dns/helm-release.yaml | 30 -------- .../base/external-dns/helm-repository.yaml | 10 --- .../base/external-dns/kustomization.yaml | 4 +- .../ingress/base/external-dns/values.yaml | 19 ----- .../aws-load-balancer-controller-patch.yaml | 25 ++++++ .../overlays/dev/external-dns-patch.yaml | 30 ++++++++ .../ingress/overlays/dev/flux/ingress.yaml | 27 ------- .../ingress/overlays/dev/kustomization.yaml | 8 +- .../overlays/dev/letsencrypt-patch.yaml | 9 +++ .../logging/base/fluent-bit/fluent-bit.yaml | 54 +++++++++++++ .../logging/base/fluent-bit/helm-release.yaml | 18 ----- .../base/fluent-bit/kustomization.yaml | 3 +- platform/logging/base/fluent-bit/values.yaml | 32 -------- platform/logging/base/loki/helm-release.yaml | 38 ---------- platform/logging/base/loki/kustomization.yaml | 3 +- platform/logging/base/loki/loki.yaml | 76 +++++++++++++++++++ platform/logging/base/loki/values.yaml | 50 ------------ .../logging/overlays/dev/kustomization.yaml | 2 +- ...{namespace.yaml => logging-namespace.yaml} | 0 .../alertmanager/external-secret.yaml | 4 +- .../kube-prometheus-stack/application.yaml | 23 ++++++ .../blackbox-exporter/application.yaml | 22 ++++++ .../blackbox-exporter/kustomization.yaml | 6 ++ .../blackbox-exporter/values-common.yaml | 11 +++ .../blackbox-exporter/helm-release.yaml | 29 ------- .../exporters/kustomization.yaml | 8 -- .../postgres-exporter/helm-release.yaml | 27 ------- .../redis-exporter/helm-release.yaml | 21 ----- .../kube-prometheus-stack/helm-release.yaml | 31 -------- .../helm-repository.yaml | 8 -- .../allow-node-exporter.yaml} | 4 +- .../allow-postgres-exporter.yaml | 27 +++++++ .../networkpolicies/allow-redis-exporter.yaml | 27 +++++++ .../networkpolicies/kustomization.yaml | 7 ++ .../postgres-exporter/application.yaml | 28 +++++++ .../postgres-exporter/kustomization.yaml | 6 ++ .../postgres-exporter/values-common.yaml | 6 ++ .../redis-exporter/application.yaml | 23 ++++++ .../redis-exporter/kustomization.yaml | 6 ++ .../redis-exporter/values-common.yaml | 2 + ...yaml => aws-load-balancer-controller.yaml} | 0 .../{values.yaml => values-common.yaml} | 0 platform/monitoring/base/kustomization.yaml | 17 ++++- .../dev/kube-prometheus-stack-patch.yaml | 12 +++ .../overlays/dev/kustomization.yaml | 13 +++- .../overlays/dev/order/application.yaml | 34 +++++++++ .../overlays/dev/payment/application.yaml | 34 +++++++++ .../overlays/dev/postgres-exporter-patch.yaml | 12 +++ .../overlays/dev/product/application.yaml | 34 +++++++++ .../overlays/dev/user/application.yaml | 34 +++++++++ .../monitoring/overlays/dev/values-dev.yaml | 20 +++++ 63 files changed, 716 insertions(+), 480 deletions(-) create mode 100644 platform/ingress/base/applications/aws-load-balancer-controller.yaml rename platform/ingress/base/{aws-load-balancer-controller => applications}/kustomization.yaml (55%) delete mode 100644 platform/ingress/base/aws-load-balancer-controller/helm-release.yaml delete mode 100644 platform/ingress/base/aws-load-balancer-controller/helm-repository.yaml delete mode 100644 platform/ingress/base/aws-load-balancer-controller/value.yaml create mode 100644 platform/ingress/base/cert-manager/cert-manager.yaml delete mode 100644 platform/ingress/base/cert-manager/helm-release.yaml delete mode 100644 platform/ingress/base/cert-manager/helm-repository.yaml delete mode 100644 platform/ingress/base/cert-manager/values.yaml create mode 100644 platform/ingress/base/external-dns/external-dns.yaml delete mode 100644 platform/ingress/base/external-dns/helm-release.yaml delete mode 100644 platform/ingress/base/external-dns/helm-repository.yaml delete mode 100644 platform/ingress/base/external-dns/values.yaml create mode 100644 platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml create mode 100644 platform/ingress/overlays/dev/external-dns-patch.yaml delete mode 100644 platform/ingress/overlays/dev/flux/ingress.yaml create mode 100644 platform/ingress/overlays/dev/letsencrypt-patch.yaml create mode 100644 platform/logging/base/fluent-bit/fluent-bit.yaml delete mode 100644 platform/logging/base/fluent-bit/helm-release.yaml delete mode 100644 platform/logging/base/fluent-bit/values.yaml delete mode 100644 platform/logging/base/loki/helm-release.yaml create mode 100644 platform/logging/base/loki/loki.yaml delete mode 100644 platform/logging/base/loki/values.yaml rename platform/logging/overlays/dev/{namespace.yaml => logging-namespace.yaml} (100%) create mode 100644 platform/monitoring/base/kube-prometheus-stack/application.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/blackbox-exporter/application.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/blackbox-exporter/kustomization.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/blackbox-exporter/values-common.yaml delete mode 100644 platform/monitoring/base/kube-prometheus-stack/exporters/blackbox-exporter/helm-release.yaml delete mode 100644 platform/monitoring/base/kube-prometheus-stack/exporters/kustomization.yaml delete mode 100644 platform/monitoring/base/kube-prometheus-stack/exporters/postgres-exporter/helm-release.yaml delete mode 100644 platform/monitoring/base/kube-prometheus-stack/exporters/redis-exporter/helm-release.yaml delete mode 100644 platform/monitoring/base/kube-prometheus-stack/helm-release.yaml delete mode 100644 platform/monitoring/base/kube-prometheus-stack/helm-repository.yaml rename platform/monitoring/base/kube-prometheus-stack/{exporters/network-policy.yaml => networkpolicies/allow-node-exporter.yaml} (83%) create mode 100644 platform/monitoring/base/kube-prometheus-stack/networkpolicies/allow-postgres-exporter.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/networkpolicies/allow-redis-exporter.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/networkpolicies/kustomization.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/postgres-exporter/application.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/postgres-exporter/kustomization.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/postgres-exporter/values-common.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/redis-exporter/application.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/redis-exporter/kustomization.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/redis-exporter/values-common.yaml rename platform/monitoring/base/kube-prometheus-stack/servicemonitors/{aws-load-balancer-controller.yaml.yaml => aws-load-balancer-controller.yaml} (100%) rename platform/monitoring/base/kube-prometheus-stack/{values.yaml => values-common.yaml} (100%) create mode 100644 platform/monitoring/overlays/dev/kube-prometheus-stack-patch.yaml create mode 100644 platform/monitoring/overlays/dev/order/application.yaml create mode 100644 platform/monitoring/overlays/dev/payment/application.yaml create mode 100644 platform/monitoring/overlays/dev/postgres-exporter-patch.yaml create mode 100644 platform/monitoring/overlays/dev/product/application.yaml create mode 100644 platform/monitoring/overlays/dev/user/application.yaml create mode 100644 platform/monitoring/overlays/dev/values-dev.yaml diff --git a/platform/ingress/base/applications/aws-load-balancer-controller.yaml b/platform/ingress/base/applications/aws-load-balancer-controller.yaml new file mode 100644 index 0000000..379a1bd --- /dev/null +++ b/platform/ingress/base/applications/aws-load-balancer-controller.yaml @@ -0,0 +1,41 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: aws-load-balancer-controller + namespace: argocd + +spec: + project: default + + source: + repoURL: https://aws.github.io/eks-charts + chart: aws-load-balancer-controller + targetRevision: 1.13.4 + + helm: + values: | + clusterName: REPLACE_ME + region: REPLACE_ME + vpcId: REPLACE_ME + + serviceAccount: + create: true + name: aws-load-balancer-controller + + replicaCount: 2 + + metrics: + serviceMonitor: + enabled: true + additionalLabels: + prometheus: kube-prometheus + + destination: + server: https://kubernetes.default.svc + namespace: kube-system + + syncPolicy: + automated: + prune: true + selfHeal: true \ No newline at end of file diff --git a/platform/ingress/base/aws-load-balancer-controller/kustomization.yaml b/platform/ingress/base/applications/kustomization.yaml similarity index 55% rename from platform/ingress/base/aws-load-balancer-controller/kustomization.yaml rename to platform/ingress/base/applications/kustomization.yaml index 788894f..4761fb4 100644 --- a/platform/ingress/base/aws-load-balancer-controller/kustomization.yaml +++ b/platform/ingress/base/applications/kustomization.yaml @@ -2,6 +2,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - values.yaml - - helm-release.yaml - - help-repository.yaml \ No newline at end of file + - aws-load-balancer-controller.yaml \ No newline at end of file diff --git a/platform/ingress/base/aws-load-balancer-controller/helm-release.yaml b/platform/ingress/base/aws-load-balancer-controller/helm-release.yaml deleted file mode 100644 index 9a103f5..0000000 --- a/platform/ingress/base/aws-load-balancer-controller/helm-release.yaml +++ /dev/null @@ -1,30 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease - -metadata: - name: aws-load-balancer-controller - -spec: - interval: 30m - - chart: - spec: - chart: aws-load-balancer-controller - version: "1.13.4" - sourceRef: - kind: HelmRepository - name: eks - namespace: flux-system - - install: - remediation: - retries: 3 - - upgrade: - remediation: - retries: 3 - - valuesFrom: - - kind: ConfigMap - name: aws-load-balancer-controller-values - valuesKey: values.yaml \ No newline at end of file diff --git a/platform/ingress/base/aws-load-balancer-controller/helm-repository.yaml b/platform/ingress/base/aws-load-balancer-controller/helm-repository.yaml deleted file mode 100644 index 6a35e29..0000000 --- a/platform/ingress/base/aws-load-balancer-controller/helm-repository.yaml +++ /dev/null @@ -1,10 +0,0 @@ -apiVersion: source.toolkit.fluxcd.io/v1 -kind: HelmRepository - -metadata: - name: eks - namespace: flux-system - -spec: - interval: 24h - url: https://aws.github.io/eks-charts \ No newline at end of file diff --git a/platform/ingress/base/aws-load-balancer-controller/value.yaml b/platform/ingress/base/aws-load-balancer-controller/value.yaml deleted file mode 100644 index 9a9a481..0000000 --- a/platform/ingress/base/aws-load-balancer-controller/value.yaml +++ /dev/null @@ -1,17 +0,0 @@ -clusterName: ${CLUSTER_NAME} - -region: ${AWS_REGION} - -vpcId: ${VPC_ID} - -serviceAccount: - create: true - name: aws-load-balancer-controller - -replicaCount: 2 - -metrics: - serviceMonitor: - enabled: true - additionalLabels: - prometheus: kube-prometheus \ No newline at end of file diff --git a/platform/ingress/base/cert-manager/cert-manager.yaml b/platform/ingress/base/cert-manager/cert-manager.yaml new file mode 100644 index 0000000..3a3e385 --- /dev/null +++ b/platform/ingress/base/cert-manager/cert-manager.yaml @@ -0,0 +1,18 @@ +source: + repoURL: https://charts.jetstack.io + chart: cert-manager + targetRevision: v1.18.2 + + helm: + values: | + crds: + enabled: true + + replicaCount: 2 + + prometheus: + enabled: true + servicemonitor: + enabled: true + labels: + prometheus: kube-prometheus \ No newline at end of file diff --git a/platform/ingress/base/cert-manager/clusterissuers/letsencrypt.yaml b/platform/ingress/base/cert-manager/clusterissuers/letsencrypt.yaml index 208b06d..1dea7e0 100644 --- a/platform/ingress/base/cert-manager/clusterissuers/letsencrypt.yaml +++ b/platform/ingress/base/cert-manager/clusterissuers/letsencrypt.yaml @@ -6,7 +6,7 @@ metadata: spec: acme: - email: ${ACME_EMAIL} + email: REPLACE_ME server: https://acme-v02.api.letsencrypt.org/directory diff --git a/platform/ingress/base/cert-manager/helm-release.yaml b/platform/ingress/base/cert-manager/helm-release.yaml deleted file mode 100644 index d339d98..0000000 --- a/platform/ingress/base/cert-manager/helm-release.yaml +++ /dev/null @@ -1,28 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease - -metadata: - name: cert-manager - -spec: - interval: 30m - - chart: - spec: - chart: cert-manager - version: "v1.18.2" - sourceRef: - kind: HelmRepository - name: jetstack - namespace: flux-system - - install: - crds: CreateReplace - - upgrade: - crds: CreateReplace - - valuesFrom: - - kind: ConfigMap - name: cert-manager-values - valuesKey: values.yaml \ No newline at end of file diff --git a/platform/ingress/base/cert-manager/helm-repository.yaml b/platform/ingress/base/cert-manager/helm-repository.yaml deleted file mode 100644 index 23db72c..0000000 --- a/platform/ingress/base/cert-manager/helm-repository.yaml +++ /dev/null @@ -1,10 +0,0 @@ -apiVersion: source.toolkit.fluxcd.io/v1 -kind: HelmRepository - -metadata: - name: jetstack - namespace: flux-system - -spec: - interval: 24h - url: https://charts.jetstack.io \ No newline at end of file diff --git a/platform/ingress/base/cert-manager/kustomization.yaml b/platform/ingress/base/cert-manager/kustomization.yaml index 29924c4..89155d2 100644 --- a/platform/ingress/base/cert-manager/kustomization.yaml +++ b/platform/ingress/base/cert-manager/kustomization.yaml @@ -2,7 +2,5 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - values.yaml - - helm-release.yaml - - help-repository.yaml - - clusterissuers/letsencrypt.yaml \ No newline at end of file + - clusterissuers/letsencrypt.yaml + - cert-manager.yaml \ No newline at end of file diff --git a/platform/ingress/base/cert-manager/values.yaml b/platform/ingress/base/cert-manager/values.yaml deleted file mode 100644 index 00d42be..0000000 --- a/platform/ingress/base/cert-manager/values.yaml +++ /dev/null @@ -1,11 +0,0 @@ -crds: - enabled: true - -replicaCount: 2 - -prometheus: - enabled: true - servicemonitor: - enabled: true - labels: - prometheus: kube-prometheus \ No newline at end of file diff --git a/platform/ingress/base/external-dns/external-dns.yaml b/platform/ingress/base/external-dns/external-dns.yaml new file mode 100644 index 0000000..fe7c065 --- /dev/null +++ b/platform/ingress/base/external-dns/external-dns.yaml @@ -0,0 +1,45 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: external-dns + namespace: argocd + +spec: + project: default + + source: + repoURL: https://kubernetes-sigs.github.io/external-dns + chart: external-dns + targetRevision: 1.18.0 + + helm: + values: | + provider: aws + + policy: sync + + registry: txt + + txtOwnerId: REPLACE_ME + + domainFilters: + - REPLACE_ME + + serviceAccount: + create: true + name: external-dns + + serviceMonitor: + enabled: true + additionalLabels: + prometheus: kube-prometheus + + destination: + server: https://kubernetes.default.svc + namespace: kube-system + + syncPolicy: + automated: + prune: true + selfHeal: true \ No newline at end of file diff --git a/platform/ingress/base/external-dns/helm-release.yaml b/platform/ingress/base/external-dns/helm-release.yaml deleted file mode 100644 index ad88994..0000000 --- a/platform/ingress/base/external-dns/helm-release.yaml +++ /dev/null @@ -1,30 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease - -metadata: - name: external-dns - -spec: - interval: 30m - - chart: - spec: - chart: external-dns - version: "1.18.0" - sourceRef: - kind: HelmRepository - name: external-dns - namespace: flux-system - - install: - remediation: - retries: 3 - - upgrade: - remediation: - retries: 3 - - valuesFrom: - - kind: ConfigMap - name: external-dns-values - valuesKey: values.yaml \ No newline at end of file diff --git a/platform/ingress/base/external-dns/helm-repository.yaml b/platform/ingress/base/external-dns/helm-repository.yaml deleted file mode 100644 index 7784e51..0000000 --- a/platform/ingress/base/external-dns/helm-repository.yaml +++ /dev/null @@ -1,10 +0,0 @@ -apiVersion: source.toolkit.fluxcd.io/v1 -kind: HelmRepository - -metadata: - name: external-dns - namespace: flux-system - -spec: - interval: 24h - url: https://kubernetes-sigs.github.io/external-dns \ No newline at end of file diff --git a/platform/ingress/base/external-dns/kustomization.yaml b/platform/ingress/base/external-dns/kustomization.yaml index 788894f..2c0eec7 100644 --- a/platform/ingress/base/external-dns/kustomization.yaml +++ b/platform/ingress/base/external-dns/kustomization.yaml @@ -2,6 +2,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - values.yaml - - helm-release.yaml - - help-repository.yaml \ No newline at end of file + - external-dns.yaml \ No newline at end of file diff --git a/platform/ingress/base/external-dns/values.yaml b/platform/ingress/base/external-dns/values.yaml deleted file mode 100644 index ee65d36..0000000 --- a/platform/ingress/base/external-dns/values.yaml +++ /dev/null @@ -1,19 +0,0 @@ -provider: aws - -policy: sync - -registry: txt - -txtOwnerId: ${CLUSTER_NAME} - -domainFilters: - - ${BASE_DOMAIN} - -serviceAccount: - create: true - name: external-dns - -serviceMonitor: - enabled: true - additionalLabels: - prometheus: kube-prometheus \ No newline at end of file diff --git a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml new file mode 100644 index 0000000..14694a3 --- /dev/null +++ b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml @@ -0,0 +1,25 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: aws-load-balancer-controller + +spec: + source: + helm: + values: | + clusterName: eks-dev-cluster + region: us-east-1 + vpcId: vpc-0123456789abcdef + + serviceAccount: + create: true + name: aws-load-balancer-controller + + replicaCount: 2 + + metrics: + serviceMonitor: + enabled: true + additionalLabels: + prometheus: kube-prometheus \ No newline at end of file diff --git a/platform/ingress/overlays/dev/external-dns-patch.yaml b/platform/ingress/overlays/dev/external-dns-patch.yaml new file mode 100644 index 0000000..785829d --- /dev/null +++ b/platform/ingress/overlays/dev/external-dns-patch.yaml @@ -0,0 +1,30 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: external-dns + namespace: argocd + +spec: + source: + helm: + values: | + provider: aws + + policy: sync + + registry: txt + + txtOwnerId: eks-dev-cluster + + domainFilters: + - api.dev.emmanuelogah.com + + serviceAccount: + create: true + name: external-dns + + serviceMonitor: + enabled: true + additionalLabels: + prometheus: kube-prometheus \ No newline at end of file diff --git a/platform/ingress/overlays/dev/flux/ingress.yaml b/platform/ingress/overlays/dev/flux/ingress.yaml deleted file mode 100644 index 0022b8a..0000000 --- a/platform/ingress/overlays/dev/flux/ingress.yaml +++ /dev/null @@ -1,27 +0,0 @@ -apiVersion: kustomize.toolkit.fluxcd.io/v1 -kind: Kustomization - -metadata: - name: ingress - namespace: flux-system - -spec: - interval: 10m - - path: ./ingress/overlays/dev - - prune: true - - sourceRef: - kind: GitRepository - name: infrastructure - - wait: true - - postBuild: - substitute: - CLUSTER_NAME: eks-dev-cluster - AWS_REGION: us-east-1 - VPC_ID: vpc-0123456789abcdef - BASE_DOMAIN: dev.emmanuelogah.com - ACME_EMAIL: admin@emmanuelogah.com \ No newline at end of file diff --git a/platform/ingress/overlays/dev/kustomization.yaml b/platform/ingress/overlays/dev/kustomization.yaml index a3ea8d6..d2d5617 100644 --- a/platform/ingress/overlays/dev/kustomization.yaml +++ b/platform/ingress/overlays/dev/kustomization.yaml @@ -5,7 +5,7 @@ namespace: dev resources: - ../../base - - -patches: - - path: aws-load-balancer-controller-patch.yaml \ No newline at end of file + - ingress-namespace.yaml + - external-dns-patch.yaml + - aws-load-balancer-controller-patch.yaml + - letsencrypt-patch.yaml \ No newline at end of file diff --git a/platform/ingress/overlays/dev/letsencrypt-patch.yaml b/platform/ingress/overlays/dev/letsencrypt-patch.yaml new file mode 100644 index 0000000..6cf846e --- /dev/null +++ b/platform/ingress/overlays/dev/letsencrypt-patch.yaml @@ -0,0 +1,9 @@ +apiVersion: cert-manager.io/v1 +kind: ClusterIssuer + +metadata: + name: letsencrypt + +spec: + acme: + email: admin@dev.example.com \ No newline at end of file diff --git a/platform/logging/base/fluent-bit/fluent-bit.yaml b/platform/logging/base/fluent-bit/fluent-bit.yaml new file mode 100644 index 0000000..a9edff3 --- /dev/null +++ b/platform/logging/base/fluent-bit/fluent-bit.yaml @@ -0,0 +1,54 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: fluent-bit + namespace: argocd + +spec: + project: default + + source: + repoURL: https://fluent.github.io/helm-charts + chart: fluent-bit + targetRevision: 0.x + + helm: + values: | + config: + service: | + [SERVICE] + Flush 5 + Log_Level info + Parsers_File parsers.conf + + inputs: | + [INPUT] + Name tail + Path /var/log/containers/*.log + Parser docker + Tag kube.* + + filters: | + [FILTER] + Name kubernetes + Match kube.* + Merge_Log On + Keep_Log Off + + outputs: | + [OUTPUT] + Name loki + Match * + Host loki.logging.svc.cluster.local + Port 3100 + Labels job=fluent-bit + + destination: + server: https://kubernetes.default.svc + namespace: logging + + syncPolicy: + automated: + prune: true + selfHeal: true \ No newline at end of file diff --git a/platform/logging/base/fluent-bit/helm-release.yaml b/platform/logging/base/fluent-bit/helm-release.yaml deleted file mode 100644 index e7676cc..0000000 --- a/platform/logging/base/fluent-bit/helm-release.yaml +++ /dev/null @@ -1,18 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 - -kind: HelmRelease - -metadata: - name: fluent-bit - -spec: - interval: 30m - - chart: - spec: - chart: fluent-bit - version: "0.x" - sourceRef: - kind: HelmRepository - name: fluent - namespace: flux-system \ No newline at end of file diff --git a/platform/logging/base/fluent-bit/kustomization.yaml b/platform/logging/base/fluent-bit/kustomization.yaml index bcd1ac0..4d8c1a5 100644 --- a/platform/logging/base/fluent-bit/kustomization.yaml +++ b/platform/logging/base/fluent-bit/kustomization.yaml @@ -2,5 +2,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - helm-release.yaml - - values.yaml \ No newline at end of file + - fluent-bit.yaml \ No newline at end of file diff --git a/platform/logging/base/fluent-bit/values.yaml b/platform/logging/base/fluent-bit/values.yaml deleted file mode 100644 index 78474fc..0000000 --- a/platform/logging/base/fluent-bit/values.yaml +++ /dev/null @@ -1,32 +0,0 @@ -config: - - service: | - [SERVICE] - Flush 5 - Log_Level info - Parsers_File parsers.conf - - - inputs: | - [INPUT] - Name tail - Path /var/log/containers/*.log - Parser docker - Tag kube.* - - - filters: | - [FILTER] - Name kubernetes - Match kube.* - Merge_Log On - Keep_Log Off - - - outputs: | - [OUTPUT] - Name loki - Match * - Host loki.logging.svc.cluster.local - Port 3100 - Labels job=fluent-bit \ No newline at end of file diff --git a/platform/logging/base/loki/helm-release.yaml b/platform/logging/base/loki/helm-release.yaml deleted file mode 100644 index 358e747..0000000 --- a/platform/logging/base/loki/helm-release.yaml +++ /dev/null @@ -1,38 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 - -kind: HelmRelease - -metadata: - name: loki - -spec: - interval: 30m - - chart: - spec: - chart: loki - version: "6.x" - sourceRef: - kind: HelmRepository - name: grafana - namespace: flux-system - - values: - deploymentMode: SingleBinary - - loki: - auth_enabled: false - - commonConfig: - replication_factor: 1 - - storage: - type: filesystem - - singleBinary: - replicas: 1 - - persistence: - enabled: true - storageClass: gp3 - size: 50Gi \ No newline at end of file diff --git a/platform/logging/base/loki/kustomization.yaml b/platform/logging/base/loki/kustomization.yaml index bcd1ac0..ace3aac 100644 --- a/platform/logging/base/loki/kustomization.yaml +++ b/platform/logging/base/loki/kustomization.yaml @@ -2,5 +2,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - helm-release.yaml - - values.yaml \ No newline at end of file + - loki.yaml \ No newline at end of file diff --git a/platform/logging/base/loki/loki.yaml b/platform/logging/base/loki/loki.yaml new file mode 100644 index 0000000..daa6b80 --- /dev/null +++ b/platform/logging/base/loki/loki.yaml @@ -0,0 +1,76 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: loki + namespace: argocd + +spec: + project: default + + source: + repoURL: https://grafana.github.io/helm-charts + chart: loki + targetRevision: 6.x + + helm: + values: | + deploymentMode: SingleBinary + + singleBinary: + replicas: 1 + + loki: + auth_enabled: false + + commonConfig: + replication_factor: 1 + + schemaConfig: + configs: + - from: "2024-01-01" + store: tsdb + object_store: filesystem + schema: v13 + index: + prefix: loki_index_ + period: 24h + + storage: + type: filesystem + + limits_config: + retention_period: 30d + + compactor: + retention_enabled: true + working_directory: /var/loki/retention + + server: + http_listen_port: 3100 + + analytics: + reporting_enabled: false + + pattern_ingester: + enabled: false + + persistence: + enabled: true + storageClassName: gp3 + size: 50Gi + + monitoring: + serviceMonitor: + enabled: true + labels: + prometheus: kube-prometheus + + destination: + server: https://kubernetes.default.svc + namespace: logging + + syncPolicy: + automated: + prune: true + selfHeal: true \ No newline at end of file diff --git a/platform/logging/base/loki/values.yaml b/platform/logging/base/loki/values.yaml deleted file mode 100644 index c455ca4..0000000 --- a/platform/logging/base/loki/values.yaml +++ /dev/null @@ -1,50 +0,0 @@ -deploymentMode: SingleBinary - -singleBinary: - replicas: 1 - -loki: - auth_enabled: false - - commonConfig: - replication_factor: 1 - - schemaConfig: - configs: - - from: "2024-01-01" - store: tsdb - object_store: filesystem - schema: v13 - index: - prefix: loki_index_ - period: 24h - - storage: - type: filesystem - - limits_config: - retention_period: 30d - - compactor: - retention_enabled: true - working_directory: /var/loki/retention - - server: - http_listen_port: 3100 - - analytics: - reporting_enabled: false - - pattern_ingester: - enabled: false - -persistence: - enabled: true - storageClassName: gp3 - size: 50Gi - -monitoring: - serviceMonitor: - enabled: true - labels: - prometheus: kube-prometheus \ No newline at end of file diff --git a/platform/logging/overlays/dev/kustomization.yaml b/platform/logging/overlays/dev/kustomization.yaml index ef66e29..7722e40 100644 --- a/platform/logging/overlays/dev/kustomization.yaml +++ b/platform/logging/overlays/dev/kustomization.yaml @@ -4,5 +4,5 @@ kind: Kustomization namespace: dev resources: - - monitoring.yaml + - logging-namespace.yaml - ../../base \ No newline at end of file diff --git a/platform/logging/overlays/dev/namespace.yaml b/platform/logging/overlays/dev/logging-namespace.yaml similarity index 100% rename from platform/logging/overlays/dev/namespace.yaml rename to platform/logging/overlays/dev/logging-namespace.yaml diff --git a/platform/monitoring/base/kube-prometheus-stack/alertmanager/external-secret.yaml b/platform/monitoring/base/kube-prometheus-stack/alertmanager/external-secret.yaml index 788af79..d890a99 100644 --- a/platform/monitoring/base/kube-prometheus-stack/alertmanager/external-secret.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/alertmanager/external-secret.yaml @@ -1,5 +1,6 @@ apiVersion: external-secrets.io/v1 kind: ExternalSecret + metadata: name: alertmanager-notification-secret @@ -7,11 +8,12 @@ spec: refreshInterval: 1h secretStoreRef: - name: aws-secretsmanager kind: ClusterSecretStore + name: aws-secretsmanager target: name: alertmanager-notification-secret + creationPolicy: Owner data: - secretKey: slack-webhook diff --git a/platform/monitoring/base/kube-prometheus-stack/application.yaml b/platform/monitoring/base/kube-prometheus-stack/application.yaml new file mode 100644 index 0000000..d3b22b9 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/application.yaml @@ -0,0 +1,23 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: kube-prometheus-stack + namespace: argocd + +spec: + project: default + + source: + repoURL: https://prometheus-community.github.io/helm-charts + chart: kube-prometheus-stack + targetRevision: 72.6.0 + + destination: + server: https://kubernetes.default.svc + namespace: monitoring + + syncPolicy: + automated: + prune: true + selfHeal: true \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/blackbox-exporter/application.yaml b/platform/monitoring/base/kube-prometheus-stack/blackbox-exporter/application.yaml new file mode 100644 index 0000000..08f3b13 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/blackbox-exporter/application.yaml @@ -0,0 +1,22 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: blackbox-exporter + namespace: argocd + +spec: + project: default + + source: + repoURL: https://prometheus-community.github.io/helm-charts + chart: prometheus-blackbox-exporter + targetRevision: 9.0.0 + + destination: + server: https://kubernetes.default.svc + + syncPolicy: + automated: + prune: true + selfHeal: true \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/blackbox-exporter/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/blackbox-exporter/kustomization.yaml new file mode 100644 index 0000000..2322e3f --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/blackbox-exporter/kustomization.yaml @@ -0,0 +1,6 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - application.yaml + - values-common.yaml \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/blackbox-exporter/values-common.yaml b/platform/monitoring/base/kube-prometheus-stack/blackbox-exporter/values-common.yaml new file mode 100644 index 0000000..aae8ee6 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/blackbox-exporter/values-common.yaml @@ -0,0 +1,11 @@ +serviceMonitor: + enabled: true + +config: + modules: + http_2xx: + prober: http + timeout: 5s + + http: + preferred_ip_protocol: ip4 \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/exporters/blackbox-exporter/helm-release.yaml b/platform/monitoring/base/kube-prometheus-stack/exporters/blackbox-exporter/helm-release.yaml deleted file mode 100644 index ea5ae0e..0000000 --- a/platform/monitoring/base/kube-prometheus-stack/exporters/blackbox-exporter/helm-release.yaml +++ /dev/null @@ -1,29 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease - -metadata: - name: blackbox-exporter - -spec: - interval: 30m - - chart: - spec: - chart: prometheus-blackbox-exporter - version: "9.0.0" - sourceRef: - kind: HelmRepository - name: prometheus-community - namespace: flux-system - - values: - serviceMonitor: - enabled: true - - config: - modules: - http_2xx: - prober: http - timeout: 5s - http: - preferred_ip_protocol: ip4 \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/exporters/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/exporters/kustomization.yaml deleted file mode 100644 index 8b28dff..0000000 --- a/platform/monitoring/base/kube-prometheus-stack/exporters/kustomization.yaml +++ /dev/null @@ -1,8 +0,0 @@ -apiVersion: kustomize.config.k8s.io/v1beta1 -kind: Kustomization - -resources: - - blackbox-exporter/helm-release.yaml - - postgres-exporter/helm-release.yaml - - redis-exporter/helm-release.yaml - - network-policy.yaml \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/exporters/postgres-exporter/helm-release.yaml b/platform/monitoring/base/kube-prometheus-stack/exporters/postgres-exporter/helm-release.yaml deleted file mode 100644 index dda11d3..0000000 --- a/platform/monitoring/base/kube-prometheus-stack/exporters/postgres-exporter/helm-release.yaml +++ /dev/null @@ -1,27 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease - -metadata: - name: postgres-exporter - -spec: - interval: 30m - - chart: - spec: - chart: prometheus-postgres-exporter - version: "6.8.0" - sourceRef: - kind: HelmRepository - name: prometheus-community - namespace: flux-system - - values: - serviceMonitor: - enabled: true - - config: - datasource: - host: postgres.default.svc.cluster.local - port: "5432" - database: postgres \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/exporters/redis-exporter/helm-release.yaml b/platform/monitoring/base/kube-prometheus-stack/exporters/redis-exporter/helm-release.yaml deleted file mode 100644 index 847c661..0000000 --- a/platform/monitoring/base/kube-prometheus-stack/exporters/redis-exporter/helm-release.yaml +++ /dev/null @@ -1,21 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease - -metadata: - name: redis-exporter - -spec: - interval: 30m - - chart: - spec: - chart: prometheus-redis-exporter - version: "6.8.0" - sourceRef: - kind: HelmRepository - name: prometheus-community - namespace: flux-system - - values: - serviceMonitor: - enabled: true \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/helm-release.yaml b/platform/monitoring/base/kube-prometheus-stack/helm-release.yaml deleted file mode 100644 index 79d42f1..0000000 --- a/platform/monitoring/base/kube-prometheus-stack/helm-release.yaml +++ /dev/null @@ -1,31 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease -metadata: - name: prometheus-stack - -spec: - interval: 30m - - chart: - spec: - chart: kube-prometheus-stack - version: "72.6.0" - sourceRef: - kind: HelmRepository - name: prometheus-community - namespace: flux-system - - install: - createNamespace: true - remediation: - retries: 3 - - upgrade: - remediation: - retries: 3 - remediateLastFailure: true - - valuesFrom: - - kind: ConfigMap - name: prometheus-stack-values - valuesKey: values.yaml \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/helm-repository.yaml b/platform/monitoring/base/kube-prometheus-stack/helm-repository.yaml deleted file mode 100644 index 7fb95d4..0000000 --- a/platform/monitoring/base/kube-prometheus-stack/helm-repository.yaml +++ /dev/null @@ -1,8 +0,0 @@ -apiVersion: source.toolkit.fluxcd.io/v1 -kind: HelmRepository -metadata: - name: prometheus-community - namespace: flux-system -spec: - interval: 24h - url: https://prometheus-community.github.io/helm-charts \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/exporters/network-policy.yaml b/platform/monitoring/base/kube-prometheus-stack/networkpolicies/allow-node-exporter.yaml similarity index 83% rename from platform/monitoring/base/kube-prometheus-stack/exporters/network-policy.yaml rename to platform/monitoring/base/kube-prometheus-stack/networkpolicies/allow-node-exporter.yaml index d764953..1af7450 100644 --- a/platform/monitoring/base/kube-prometheus-stack/exporters/network-policy.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/networkpolicies/allow-node-exporter.yaml @@ -2,12 +2,12 @@ apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: - name: allow-prometheus + name: allow-prometheus-node-exporter spec: podSelector: matchLabels: - app.kubernetes.io/component: exporter + app.kubernetes.io/name: node-exporter policyTypes: - Ingress diff --git a/platform/monitoring/base/kube-prometheus-stack/networkpolicies/allow-postgres-exporter.yaml b/platform/monitoring/base/kube-prometheus-stack/networkpolicies/allow-postgres-exporter.yaml new file mode 100644 index 0000000..7721461 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/networkpolicies/allow-postgres-exporter.yaml @@ -0,0 +1,27 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-prometheus-postgres-exporter + +spec: + podSelector: + matchLabels: + app.kubernetes.io/name: prometheus-postgres-exporter + + policyTypes: + - Ingress + + ingress: + - from: + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: monitoring + + podSelector: + matchLabels: + app.kubernetes.io/name: prometheus + + ports: + - protocol: TCP + port: 9187 \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/networkpolicies/allow-redis-exporter.yaml b/platform/monitoring/base/kube-prometheus-stack/networkpolicies/allow-redis-exporter.yaml new file mode 100644 index 0000000..84573cd --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/networkpolicies/allow-redis-exporter.yaml @@ -0,0 +1,27 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: allow-prometheus-redis-exporter + +spec: + podSelector: + matchLabels: + app.kubernetes.io/name: redis-exporter + + policyTypes: + - Ingress + + ingress: + - from: + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: monitoring + + podSelector: + matchLabels: + app.kubernetes.io/name: prometheus + + ports: + - protocol: TCP + port: 9121 \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/networkpolicies/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/networkpolicies/kustomization.yaml new file mode 100644 index 0000000..1513ce1 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/networkpolicies/kustomization.yaml @@ -0,0 +1,7 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - allow-node-exporter.yaml + - allow-postgres-exporter.yaml + - allow-redis-exporter.yaml \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/postgres-exporter/application.yaml b/platform/monitoring/base/kube-prometheus-stack/postgres-exporter/application.yaml new file mode 100644 index 0000000..2bff4c1 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/postgres-exporter/application.yaml @@ -0,0 +1,28 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: postgres-exporter + namespace: argocd + +spec: + project: default + + source: + repoURL: https://prometheus-community.github.io/helm-charts + chart: prometheus-postgres-exporter + targetRevision: 6.8.0 + + helm: + valuesObject: + serviceMonitor: + enabled: true + + destination: + server: https://kubernetes.default.svc + namespace: monitoring + + syncPolicy: + automated: + prune: true + selfHeal: true \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/postgres-exporter/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/postgres-exporter/kustomization.yaml new file mode 100644 index 0000000..2322e3f --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/postgres-exporter/kustomization.yaml @@ -0,0 +1,6 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - application.yaml + - values-common.yaml \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/postgres-exporter/values-common.yaml b/platform/monitoring/base/kube-prometheus-stack/postgres-exporter/values-common.yaml new file mode 100644 index 0000000..872f0f4 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/postgres-exporter/values-common.yaml @@ -0,0 +1,6 @@ +serviceMonitor: + enabled: true + +config: + datasource: + port: "5432" \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/redis-exporter/application.yaml b/platform/monitoring/base/kube-prometheus-stack/redis-exporter/application.yaml new file mode 100644 index 0000000..6f7bc8c --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/redis-exporter/application.yaml @@ -0,0 +1,23 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: redis-exporter + namespace: argocd + +spec: + project: default + + source: + repoURL: https://prometheus-community.github.io/helm-charts + chart: prometheus-redis-exporter + targetRevision: 6.8.0 + + destination: + server: https://kubernetes.default.svc + namespace: monitoring + + syncPolicy: + automated: + prune: true + selfHeal: true \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/redis-exporter/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/redis-exporter/kustomization.yaml new file mode 100644 index 0000000..2322e3f --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/redis-exporter/kustomization.yaml @@ -0,0 +1,6 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - application.yaml + - values-common.yaml \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/redis-exporter/values-common.yaml b/platform/monitoring/base/kube-prometheus-stack/redis-exporter/values-common.yaml new file mode 100644 index 0000000..5ee83e6 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/redis-exporter/values-common.yaml @@ -0,0 +1,2 @@ +serviceMonitor: + enabled: true \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/aws-load-balancer-controller.yaml.yaml b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/aws-load-balancer-controller.yaml similarity index 100% rename from platform/monitoring/base/kube-prometheus-stack/servicemonitors/aws-load-balancer-controller.yaml.yaml rename to platform/monitoring/base/kube-prometheus-stack/servicemonitors/aws-load-balancer-controller.yaml diff --git a/platform/monitoring/base/kube-prometheus-stack/values.yaml b/platform/monitoring/base/kube-prometheus-stack/values-common.yaml similarity index 100% rename from platform/monitoring/base/kube-prometheus-stack/values.yaml rename to platform/monitoring/base/kube-prometheus-stack/values-common.yaml diff --git a/platform/monitoring/base/kustomization.yaml b/platform/monitoring/base/kustomization.yaml index f9f2ceb..c67aa35 100644 --- a/platform/monitoring/base/kustomization.yaml +++ b/platform/monitoring/base/kustomization.yaml @@ -1,6 +1,19 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization - resources: - - kube-prometheus-stack \ No newline at end of file + - alertmanager/ + - networkpolicies/ + - grafana/ + - postgres-exporter/ + - redis-exporter/ + - blackbox-exporter/ + - prometheusrules/ + - recording-rules/ + - servicemonitors/ + + - external-secret.yaml + - application.yaml + - kustomization.yaml + - values-common.yaml + \ No newline at end of file diff --git a/platform/monitoring/overlays/dev/kube-prometheus-stack-patch.yaml b/platform/monitoring/overlays/dev/kube-prometheus-stack-patch.yaml new file mode 100644 index 0000000..dd78a65 --- /dev/null +++ b/platform/monitoring/overlays/dev/kube-prometheus-stack-patch.yaml @@ -0,0 +1,12 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: kube-prometheus-stack + +spec: + source: + helm: + valueFiles: + - $values/platform/monitoring/base/kube-prometheus-stack/values-common.yaml + - $values/platform/monitoring/overlays/dev/values-dev.yaml \ No newline at end of file diff --git a/platform/monitoring/overlays/dev/kustomization.yaml b/platform/monitoring/overlays/dev/kustomization.yaml index 149da04..d787113 100644 --- a/platform/monitoring/overlays/dev/kustomization.yaml +++ b/platform/monitoring/overlays/dev/kustomization.yaml @@ -4,5 +4,16 @@ kind: Kustomization namespace: dev resources: + - ../../base - monitoring-namespace.yaml - - ../../base \ No newline at end of file + - kube-prometheus-stack-patch.yaml + - order/application.yaml + - payment/application.yaml + - product/application.yaml + - user/application.yaml + - postgres-exporter-patch.yaml + - values-dev.yaml + + +patches: + - path: kube-prometheus-stack-patch.yaml \ No newline at end of file diff --git a/platform/monitoring/overlays/dev/order/application.yaml b/platform/monitoring/overlays/dev/order/application.yaml new file mode 100644 index 0000000..86fde50 --- /dev/null +++ b/platform/monitoring/overlays/dev/order/application.yaml @@ -0,0 +1,34 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: product-postgres-exporter + namespace: argocd + +spec: + project: default + + source: + repoURL: https://prometheus-community.github.io/helm-charts + chart: prometheus-postgres-exporter + targetRevision: 6.8.0 + + helm: + valuesObject: + serviceMonitor: + enabled: true + + config: + datasource: + host: order-postgres.dev.svc.cluster.local + port: "5432" + database: orderdb + + destination: + server: https://kubernetes.default.svc + namespace: monitoring + + syncPolicy: + automated: + prune: true + selfHeal: true \ No newline at end of file diff --git a/platform/monitoring/overlays/dev/payment/application.yaml b/platform/monitoring/overlays/dev/payment/application.yaml new file mode 100644 index 0000000..8f9ef09 --- /dev/null +++ b/platform/monitoring/overlays/dev/payment/application.yaml @@ -0,0 +1,34 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: product-postgres-exporter + namespace: argocd + +spec: + project: default + + source: + repoURL: https://prometheus-community.github.io/helm-charts + chart: prometheus-postgres-exporter + targetRevision: 6.8.0 + + helm: + valuesObject: + serviceMonitor: + enabled: true + + config: + datasource: + host: order-postgres.dev.svc.cluster.local + port: "5432" + database: paymentdb + + destination: + server: https://kubernetes.default.svc + namespace: monitoring + + syncPolicy: + automated: + prune: true + selfHeal: true \ No newline at end of file diff --git a/platform/monitoring/overlays/dev/postgres-exporter-patch.yaml b/platform/monitoring/overlays/dev/postgres-exporter-patch.yaml new file mode 100644 index 0000000..9c836d4 --- /dev/null +++ b/platform/monitoring/overlays/dev/postgres-exporter-patch.yaml @@ -0,0 +1,12 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: postgres-exporter + +spec: + source: + helm: + valueFiles: + - $values/platform/monitoring/base/postgres-exporter/values-common.yaml + - $values/platform/monitoring/overlays/dev/postgres-values.yaml \ No newline at end of file diff --git a/platform/monitoring/overlays/dev/product/application.yaml b/platform/monitoring/overlays/dev/product/application.yaml new file mode 100644 index 0000000..1b4303e --- /dev/null +++ b/platform/monitoring/overlays/dev/product/application.yaml @@ -0,0 +1,34 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: product-postgres-exporter + namespace: argocd + +spec: + project: default + + source: + repoURL: https://prometheus-community.github.io/helm-charts + chart: prometheus-postgres-exporter + targetRevision: 6.8.0 + + helm: + valuesObject: + serviceMonitor: + enabled: true + + config: + datasource: + host: product-postgres.dev.svc.cluster.local + port: "5432" + database: productdb + + destination: + server: https://kubernetes.default.svc + namespace: monitoring + + syncPolicy: + automated: + prune: true + selfHeal: true \ No newline at end of file diff --git a/platform/monitoring/overlays/dev/user/application.yaml b/platform/monitoring/overlays/dev/user/application.yaml new file mode 100644 index 0000000..419c9db --- /dev/null +++ b/platform/monitoring/overlays/dev/user/application.yaml @@ -0,0 +1,34 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: product-postgres-exporter + namespace: argocd + +spec: + project: default + + source: + repoURL: https://prometheus-community.github.io/helm-charts + chart: prometheus-postgres-exporter + targetRevision: 6.8.0 + + helm: + valuesObject: + serviceMonitor: + enabled: true + + config: + datasource: + host: order-postgres.dev.svc.cluster.local + port: "5432" + database: userdb + + destination: + server: https://kubernetes.default.svc + namespace: monitoring + + syncPolicy: + automated: + prune: true + selfHeal: true \ No newline at end of file diff --git a/platform/monitoring/overlays/dev/values-dev.yaml b/platform/monitoring/overlays/dev/values-dev.yaml new file mode 100644 index 0000000..c891953 --- /dev/null +++ b/platform/monitoring/overlays/dev/values-dev.yaml @@ -0,0 +1,20 @@ +grafana: + persistence: + storageClassName: gp3 + size: 20Gi + +prometheus: + prometheusSpec: + retention: 30d + + storageSpec: + volumeClaimTemplate: + spec: + storageClassName: gp3 + +alertmanager: + alertmanagerSpec: + storage: + volumeClaimTemplate: + spec: + storageClassName: gp3 \ No newline at end of file From 190595f5bc9a8ea5eb99fe6b15eb8cf801b2cd3f Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Wed, 29 Jul 2026 23:18:09 +0200 Subject: [PATCH 028/122] modified the namespace --- platform/monitoring/base/kube-prometheus-stack/application.yaml | 1 - .../kube-prometheus-stack/postgres-exporter/application.yaml | 2 +- .../base/kube-prometheus-stack/redis-exporter/application.yaml | 1 - platform/monitoring/overlays/dev/order/application.yaml | 2 +- platform/monitoring/overlays/dev/payment/application.yaml | 2 +- platform/monitoring/overlays/dev/product/application.yaml | 2 +- platform/monitoring/overlays/dev/user/application.yaml | 2 +- 7 files changed, 5 insertions(+), 7 deletions(-) diff --git a/platform/monitoring/base/kube-prometheus-stack/application.yaml b/platform/monitoring/base/kube-prometheus-stack/application.yaml index d3b22b9..f7876ca 100644 --- a/platform/monitoring/base/kube-prometheus-stack/application.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/application.yaml @@ -15,7 +15,6 @@ spec: destination: server: https://kubernetes.default.svc - namespace: monitoring syncPolicy: automated: diff --git a/platform/monitoring/base/kube-prometheus-stack/postgres-exporter/application.yaml b/platform/monitoring/base/kube-prometheus-stack/postgres-exporter/application.yaml index 2bff4c1..4b4f6e8 100644 --- a/platform/monitoring/base/kube-prometheus-stack/postgres-exporter/application.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/postgres-exporter/application.yaml @@ -20,7 +20,7 @@ spec: destination: server: https://kubernetes.default.svc - namespace: monitoring + syncPolicy: automated: diff --git a/platform/monitoring/base/kube-prometheus-stack/redis-exporter/application.yaml b/platform/monitoring/base/kube-prometheus-stack/redis-exporter/application.yaml index 6f7bc8c..8f5c7c9 100644 --- a/platform/monitoring/base/kube-prometheus-stack/redis-exporter/application.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/redis-exporter/application.yaml @@ -15,7 +15,6 @@ spec: destination: server: https://kubernetes.default.svc - namespace: monitoring syncPolicy: automated: diff --git a/platform/monitoring/overlays/dev/order/application.yaml b/platform/monitoring/overlays/dev/order/application.yaml index 86fde50..3534ad8 100644 --- a/platform/monitoring/overlays/dev/order/application.yaml +++ b/platform/monitoring/overlays/dev/order/application.yaml @@ -26,7 +26,7 @@ spec: destination: server: https://kubernetes.default.svc - namespace: monitoring + namespace: dev syncPolicy: automated: diff --git a/platform/monitoring/overlays/dev/payment/application.yaml b/platform/monitoring/overlays/dev/payment/application.yaml index 8f9ef09..2309911 100644 --- a/platform/monitoring/overlays/dev/payment/application.yaml +++ b/platform/monitoring/overlays/dev/payment/application.yaml @@ -26,7 +26,7 @@ spec: destination: server: https://kubernetes.default.svc - namespace: monitoring + namespace: dev syncPolicy: automated: diff --git a/platform/monitoring/overlays/dev/product/application.yaml b/platform/monitoring/overlays/dev/product/application.yaml index 1b4303e..c12d383 100644 --- a/platform/monitoring/overlays/dev/product/application.yaml +++ b/platform/monitoring/overlays/dev/product/application.yaml @@ -26,7 +26,7 @@ spec: destination: server: https://kubernetes.default.svc - namespace: monitoring + namespace: dev syncPolicy: automated: diff --git a/platform/monitoring/overlays/dev/user/application.yaml b/platform/monitoring/overlays/dev/user/application.yaml index 419c9db..a2d13cd 100644 --- a/platform/monitoring/overlays/dev/user/application.yaml +++ b/platform/monitoring/overlays/dev/user/application.yaml @@ -26,7 +26,7 @@ spec: destination: server: https://kubernetes.default.svc - namespace: monitoring + namespace: dev syncPolicy: automated: From 0f025db5417a0021e950aed7e3cfddb1300d6112 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 00:07:04 +0200 Subject: [PATCH 029/122] Updated the networking platform --- .../base/gateway-api/application.yaml | 23 ++++++++++++++ .../base/gateway-api/kustomization.yaml | 2 +- .../base/gateway-api/standard-install.yaml | 0 .../base/metrics-server/application.yaml | 27 ++++++++++++++++ .../base/metrics-server/helm-release.yaml | 31 ------------------- .../base/metrics-server/helm-repository.yaml | 10 ------ .../base/metrics-server/kustomization.yaml | 12 ++----- .../{values.yaml => values-common.yaml} | 0 .../overlays/dev/application-patch.yaml | 5 +++ .../overlays/dev/kustomization.yaml | 6 +++- 10 files changed, 63 insertions(+), 53 deletions(-) create mode 100644 platform/networking/base/gateway-api/application.yaml delete mode 100644 platform/networking/base/gateway-api/standard-install.yaml create mode 100644 platform/networking/base/metrics-server/application.yaml delete mode 100644 platform/networking/base/metrics-server/helm-release.yaml delete mode 100644 platform/networking/base/metrics-server/helm-repository.yaml rename platform/networking/base/metrics-server/{values.yaml => values-common.yaml} (100%) create mode 100644 platform/networking/overlays/dev/application-patch.yaml diff --git a/platform/networking/base/gateway-api/application.yaml b/platform/networking/base/gateway-api/application.yaml new file mode 100644 index 0000000..00422a2 --- /dev/null +++ b/platform/networking/base/gateway-api/application.yaml @@ -0,0 +1,23 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: gateway-api + namespace: argocd + +spec: + project: default + + source: + repoURL: https://github.com/kubernetes-sigs/gateway-api + targetRevision: v1.2.1 + path: config/crd/standard + + destination: + server: https://kubernetes.default.svc + namespace: default + + syncPolicy: + automated: + prune: true + selfHeal: true \ No newline at end of file diff --git a/platform/networking/base/gateway-api/kustomization.yaml b/platform/networking/base/gateway-api/kustomization.yaml index cb54840..dcbd3b7 100644 --- a/platform/networking/base/gateway-api/kustomization.yaml +++ b/platform/networking/base/gateway-api/kustomization.yaml @@ -2,4 +2,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - standard-install.yaml \ No newline at end of file + - application.yaml \ No newline at end of file diff --git a/platform/networking/base/gateway-api/standard-install.yaml b/platform/networking/base/gateway-api/standard-install.yaml deleted file mode 100644 index e69de29..0000000 diff --git a/platform/networking/base/metrics-server/application.yaml b/platform/networking/base/metrics-server/application.yaml new file mode 100644 index 0000000..dedbedc --- /dev/null +++ b/platform/networking/base/metrics-server/application.yaml @@ -0,0 +1,27 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: metrics-server + namespace: argocd + +spec: + project: default + + source: + repoURL: https://kubernetes-sigs.github.io/metrics-server + chart: metrics-server + targetRevision: 3.13.0 + + helm: + valueFiles: + - values-common.yaml + + destination: + server: https://kubernetes.default.svc + namespace: kube-system + + syncPolicy: + automated: + prune: true + selfHeal: true \ No newline at end of file diff --git a/platform/networking/base/metrics-server/helm-release.yaml b/platform/networking/base/metrics-server/helm-release.yaml deleted file mode 100644 index 649e38d..0000000 --- a/platform/networking/base/metrics-server/helm-release.yaml +++ /dev/null @@ -1,31 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease - -metadata: - name: metrics-server - namespace: kube-system - -spec: - interval: 30m - - chart: - spec: - chart: metrics-server - version: "3.13.0" - sourceRef: - kind: HelmRepository - name: metrics-server - namespace: flux-system - - install: - remediation: - retries: 3 - - upgrade: - remediation: - retries: 3 - - valuesFrom: - - kind: ConfigMap - name: metrics-server-values - valuesKey: values.yaml \ No newline at end of file diff --git a/platform/networking/base/metrics-server/helm-repository.yaml b/platform/networking/base/metrics-server/helm-repository.yaml deleted file mode 100644 index 1a0b5cb..0000000 --- a/platform/networking/base/metrics-server/helm-repository.yaml +++ /dev/null @@ -1,10 +0,0 @@ -apiVersion: source.toolkit.fluxcd.io/v1 -kind: HelmRepository - -metadata: - name: metrics-server - namespace: flux-system - -spec: - interval: 24h - url: https://kubernetes-sigs.github.io/metrics-server \ No newline at end of file diff --git a/platform/networking/base/metrics-server/kustomization.yaml b/platform/networking/base/metrics-server/kustomization.yaml index 585a8b4..872397d 100644 --- a/platform/networking/base/metrics-server/kustomization.yaml +++ b/platform/networking/base/metrics-server/kustomization.yaml @@ -2,13 +2,5 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - helm-repository.yaml - - helm-release.yaml - -configMapGenerator: - - name: metrics-server-values - files: - - values.yaml - -generatorOptions: - disableNameSuffixHash: true \ No newline at end of file + - application.yaml + - values-common.yaml diff --git a/platform/networking/base/metrics-server/values.yaml b/platform/networking/base/metrics-server/values-common.yaml similarity index 100% rename from platform/networking/base/metrics-server/values.yaml rename to platform/networking/base/metrics-server/values-common.yaml diff --git a/platform/networking/overlays/dev/application-patch.yaml b/platform/networking/overlays/dev/application-patch.yaml new file mode 100644 index 0000000..9d8d485 --- /dev/null +++ b/platform/networking/overlays/dev/application-patch.yaml @@ -0,0 +1,5 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: metrics-server \ No newline at end of file diff --git a/platform/networking/overlays/dev/kustomization.yaml b/platform/networking/overlays/dev/kustomization.yaml index 681848f..557b706 100644 --- a/platform/networking/overlays/dev/kustomization.yaml +++ b/platform/networking/overlays/dev/kustomization.yaml @@ -2,4 +2,8 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - ../../base \ No newline at end of file + - ../../base + - application-patch.yaml + +patches: + - path: application-patch.yaml \ No newline at end of file From 8608090980e16384fab57db655c5476590aa448f Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 10:34:47 +0200 Subject: [PATCH 030/122] Updated the security platform --- .../base/kyverno-policies/application.yaml | 22 +++++++++++++ .../security/base/kyverno/application.yaml | 30 ++++++++++++++++++ .../security/base/kyverno/helm-release.yaml | 31 ------------------- .../base/kyverno/helm-repository.yaml | 10 ------ .../security/base/kyverno/kustomization.yaml | 12 ++----- .../{values.yaml => values-common.yaml} | 1 - .../base/policies/policy-exception.yaml | 2 +- .../overlays/dev/application-patch.yaml | 5 +++ .../security/overlays/dev/kustomization.yaml | 3 +- 9 files changed, 62 insertions(+), 54 deletions(-) create mode 100644 platform/security/base/kyverno-policies/application.yaml create mode 100644 platform/security/base/kyverno/application.yaml delete mode 100644 platform/security/base/kyverno/helm-release.yaml delete mode 100644 platform/security/base/kyverno/helm-repository.yaml rename platform/security/base/kyverno/{values.yaml => values-common.yaml} (99%) create mode 100644 platform/security/overlays/dev/application-patch.yaml diff --git a/platform/security/base/kyverno-policies/application.yaml b/platform/security/base/kyverno-policies/application.yaml new file mode 100644 index 0000000..6bdb258 --- /dev/null +++ b/platform/security/base/kyverno-policies/application.yaml @@ -0,0 +1,22 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: kyverno-policies + namespace: argocd + +spec: + project: default + + source: + repoURL: https://github.com/Emmy-github-webdev/Kubernetes-argocd.git + targetRevision: main + path: platform/policies/overlays/dev + + destination: + server: https://kubernetes.default.svc + + syncPolicy: + automated: + prune: true + selfHeal: true \ No newline at end of file diff --git a/platform/security/base/kyverno/application.yaml b/platform/security/base/kyverno/application.yaml new file mode 100644 index 0000000..a24ed2c --- /dev/null +++ b/platform/security/base/kyverno/application.yaml @@ -0,0 +1,30 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: kyverno + namespace: argocd + +spec: + project: default + + source: + repoURL: https://kyverno.github.io/kyverno + chart: kyverno + targetRevision: 3.3.7 + + helm: + valueFiles: + - values-common.yaml + + destination: + server: https://kubernetes.default.svc + namespace: kyverno + + syncPolicy: + automated: + prune: true + selfHeal: true + + syncOptions: + - CreateNamespace=true \ No newline at end of file diff --git a/platform/security/base/kyverno/helm-release.yaml b/platform/security/base/kyverno/helm-release.yaml deleted file mode 100644 index 8adbb81..0000000 --- a/platform/security/base/kyverno/helm-release.yaml +++ /dev/null @@ -1,31 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease - -metadata: - name: kyverno - namespace: security - -spec: - interval: 30m - - chart: - spec: - chart: kyverno - version: "3.3.7" - sourceRef: - kind: HelmRepository - name: kyverno - namespace: flux-system - - install: - remediation: - retries: 3 - - upgrade: - remediation: - retries: 3 - - valuesFrom: - - kind: ConfigMap - name: kyverno-values - valuesKey: values.yaml \ No newline at end of file diff --git a/platform/security/base/kyverno/helm-repository.yaml b/platform/security/base/kyverno/helm-repository.yaml deleted file mode 100644 index b8eac36..0000000 --- a/platform/security/base/kyverno/helm-repository.yaml +++ /dev/null @@ -1,10 +0,0 @@ -apiVersion: source.toolkit.fluxcd.io/v1 -kind: HelmRepository - -metadata: - name: kyverno - namespace: flux-system - -spec: - interval: 24h - url: https://kyverno.github.io/kyverno \ No newline at end of file diff --git a/platform/security/base/kyverno/kustomization.yaml b/platform/security/base/kyverno/kustomization.yaml index f8d6263..872397d 100644 --- a/platform/security/base/kyverno/kustomization.yaml +++ b/platform/security/base/kyverno/kustomization.yaml @@ -2,13 +2,5 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - helm-repository.yaml - - helm-release.yaml - -configMapGenerator: - - name: kyverno-values - files: - - values.yaml - -generatorOptions: - disableNameSuffixHash: true \ No newline at end of file + - application.yaml + - values-common.yaml diff --git a/platform/security/base/kyverno/values.yaml b/platform/security/base/kyverno/values-common.yaml similarity index 99% rename from platform/security/base/kyverno/values.yaml rename to platform/security/base/kyverno/values-common.yaml index b2f1a05..3d293b6 100644 --- a/platform/security/base/kyverno/values.yaml +++ b/platform/security/base/kyverno/values-common.yaml @@ -14,7 +14,6 @@ reportsController: serviceMonitor: enabled: true - additionalLabels: prometheus: kube-prometheus diff --git a/platform/security/base/policies/policy-exception.yaml b/platform/security/base/policies/policy-exception.yaml index 40f8db1..f2bf1c8 100644 --- a/platform/security/base/policies/policy-exception.yaml +++ b/platform/security/base/policies/policy-exception.yaml @@ -17,4 +17,4 @@ spec: namespaces: - kube-system - kyverno - - flux-system \ No newline at end of file + - argocd \ No newline at end of file diff --git a/platform/security/overlays/dev/application-patch.yaml b/platform/security/overlays/dev/application-patch.yaml new file mode 100644 index 0000000..82c5339 --- /dev/null +++ b/platform/security/overlays/dev/application-patch.yaml @@ -0,0 +1,5 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: kyverno \ No newline at end of file diff --git a/platform/security/overlays/dev/kustomization.yaml b/platform/security/overlays/dev/kustomization.yaml index 994cfb5..6d2696f 100644 --- a/platform/security/overlays/dev/kustomization.yaml +++ b/platform/security/overlays/dev/kustomization.yaml @@ -3,4 +3,5 @@ kind: Kustomization resources: - - ../../base/ \ No newline at end of file + - ../../base/ + - application-patch.yaml \ No newline at end of file From 94fe305343c07d7796ee41defa8588ca59f6b416 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 11:23:18 +0200 Subject: [PATCH 031/122] Modified the tracing --- apps/order-service/base/deployment.yaml | 8 +++ apps/payment-service/base/deployment.yaml | 8 +++ apps/product-service/base/deployment.yaml | 8 +++ apps/user-service/base/deployment.yaml | 8 +++ platform/security/base/kustomization.yaml | 1 + .../base/instrumentation/java-agent.yaml | 5 +- .../base/instrumentation/spring-boot.yaml | 22 +++----- .../opentelemetry-collector/application.yaml | 30 +++++++++++ .../opentelemetry-collector/helm-release.yaml | 29 ----------- .../helm-repository.yaml | 11 ---- .../kustomization.yaml | 6 +-- .../opentelemetry-collector/pipelines.yaml | 51 ------------------- .../{values.yaml => values-common.yaml} | 0 platform/tracing/base/tempo/application.yaml | 29 +++++++++++ platform/tracing/base/tempo/helm-release.yaml | 31 ----------- .../tracing/base/tempo/helm-repository.yaml | 10 ---- .../tracing/base/tempo/kustomization.yaml | 5 +- .../tempo/{values.yaml => values-common.yaml} | 0 18 files changed, 103 insertions(+), 159 deletions(-) create mode 100644 platform/tracing/base/opentelemetry-collector/application.yaml delete mode 100644 platform/tracing/base/opentelemetry-collector/helm-release.yaml delete mode 100644 platform/tracing/base/opentelemetry-collector/helm-repository.yaml delete mode 100644 platform/tracing/base/opentelemetry-collector/pipelines.yaml rename platform/tracing/base/opentelemetry-collector/{values.yaml => values-common.yaml} (100%) create mode 100644 platform/tracing/base/tempo/application.yaml delete mode 100644 platform/tracing/base/tempo/helm-release.yaml delete mode 100644 platform/tracing/base/tempo/helm-repository.yaml rename platform/tracing/base/tempo/{values.yaml => values-common.yaml} (100%) diff --git a/apps/order-service/base/deployment.yaml b/apps/order-service/base/deployment.yaml index aa1d27e..dd57db3 100644 --- a/apps/order-service/base/deployment.yaml +++ b/apps/order-service/base/deployment.yaml @@ -103,6 +103,14 @@ spec: - containerPort: 8083 env: + - name: OTEL_SERVICE_NAME + value: order-service + + - name: OTEL_RESOURCE_ATTRIBUTES + valueFrom: + fieldRef: + fieldPath: metadata.namespace + - name: DB_HOST valueFrom: secretKeyRef: diff --git a/apps/payment-service/base/deployment.yaml b/apps/payment-service/base/deployment.yaml index 8ca16dd..386bdd6 100644 --- a/apps/payment-service/base/deployment.yaml +++ b/apps/payment-service/base/deployment.yaml @@ -103,6 +103,14 @@ spec: - containerPort: 8084 env: + - name: OTEL_SERVICE_NAME + value: payment-service + + - name: OTEL_RESOURCE_ATTRIBUTES + valueFrom: + fieldRef: + fieldPath: metadata.namespace + - name: DB_HOST valueFrom: secretKeyRef: diff --git a/apps/product-service/base/deployment.yaml b/apps/product-service/base/deployment.yaml index 2b7649b..04a3ff1 100644 --- a/apps/product-service/base/deployment.yaml +++ b/apps/product-service/base/deployment.yaml @@ -103,6 +103,14 @@ spec: - containerPort: 8082 env: + - name: OTEL_SERVICE_NAME + value: product-service + + - name: OTEL_RESOURCE_ATTRIBUTES + valueFrom: + fieldRef: + fieldPath: metadata.namespace + - name: DB_HOST valueFrom: secretKeyRef: diff --git a/apps/user-service/base/deployment.yaml b/apps/user-service/base/deployment.yaml index 8060d2b..b6f4b58 100644 --- a/apps/user-service/base/deployment.yaml +++ b/apps/user-service/base/deployment.yaml @@ -103,6 +103,14 @@ spec: - containerPort: 8081 env: + - name: OTEL_SERVICE_NAME + value: user-service + + - name: OTEL_RESOURCE_ATTRIBUTES + valueFrom: + fieldRef: + fieldPath: metadata.namespace + - name: DB_HOST valueFrom: secretKeyRef: diff --git a/platform/security/base/kustomization.yaml b/platform/security/base/kustomization.yaml index cee4ab7..a14fe03 100644 --- a/platform/security/base/kustomization.yaml +++ b/platform/security/base/kustomization.yaml @@ -3,4 +3,5 @@ kind: Kustomization resources: - kyverno/ + - kyverno-policies/ - policies/ \ No newline at end of file diff --git a/platform/tracing/base/instrumentation/java-agent.yaml b/platform/tracing/base/instrumentation/java-agent.yaml index b5077fe..93191b7 100644 --- a/platform/tracing/base/instrumentation/java-agent.yaml +++ b/platform/tracing/base/instrumentation/java-agent.yaml @@ -12,9 +12,6 @@ data: -javaagent:/otel/opentelemetry-javaagent.jar - OTEL_SERVICE_NAME: order-service - - OTEL_EXPORTER_OTLP_ENDPOINT: >- http://opentelemetry-collector.tracing.svc.cluster.local:4317 @@ -32,4 +29,4 @@ data: OTEL_RESOURCE_ATTRIBUTES: >- - service.namespace=dev \ No newline at end of file + service.namespace=REPLACE_ME \ No newline at end of file diff --git a/platform/tracing/base/instrumentation/spring-boot.yaml b/platform/tracing/base/instrumentation/spring-boot.yaml index a0592c7..dfcef31 100644 --- a/platform/tracing/base/instrumentation/spring-boot.yaml +++ b/platform/tracing/base/instrumentation/spring-boot.yaml @@ -5,40 +5,30 @@ metadata: name: spring-boot-instrumentation spec: - exporter: - - endpoint: http://opentelemetry-collector.tracing.svc.cluster.local:4317 - + endpoint: http://opentelemetry-collector:4317 propagators: - - tracecontext - baggage - b3 - sampler: - type: parentbased_traceidratio - argument: "1.0" - java: - image: ghcr.io/open-telemetry/opentelemetry-operator/autoinstrumentation-java:latest env: - - - name: OTEL_LOGS_EXPORTER - value: none + - name: OTEL_TRACES_EXPORTER + value: otlp - name: OTEL_METRICS_EXPORTER value: none - - name: OTEL_TRACES_EXPORTER - value: otlp + - name: OTEL_LOGS_EXPORTER + value: none - name: OTEL_RESOURCE_ATTRIBUTES - value: service.namespace=dev \ No newline at end of file + value: service.namespace=REPLACE_ME \ No newline at end of file diff --git a/platform/tracing/base/opentelemetry-collector/application.yaml b/platform/tracing/base/opentelemetry-collector/application.yaml new file mode 100644 index 0000000..7f64a58 --- /dev/null +++ b/platform/tracing/base/opentelemetry-collector/application.yaml @@ -0,0 +1,30 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: opentelemetry-collector + namespace: argocd + +spec: + project: default + + source: + repoURL: https://open-telemetry.github.io/opentelemetry-helm-charts + chart: opentelemetry-collector + targetRevision: 0.113.0 + + helm: + valueFiles: + - values-common.yaml + + destination: + server: https://kubernetes.default.svc + + + syncPolicy: + automated: + prune: true + selfHeal: true + + syncOptions: + - CreateNamespace=true \ No newline at end of file diff --git a/platform/tracing/base/opentelemetry-collector/helm-release.yaml b/platform/tracing/base/opentelemetry-collector/helm-release.yaml deleted file mode 100644 index a67b969..0000000 --- a/platform/tracing/base/opentelemetry-collector/helm-release.yaml +++ /dev/null @@ -1,29 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease - -metadata: - name: opentelemetry-collector - - -spec: - - interval: 30m - - - chart: - spec: - chart: opentelemetry-collector - - version: "0.113.0" - - sourceRef: - kind: HelmRepository - name: open-telemetry - namespace: flux-system - - - valuesFrom: - - - kind: ConfigMap - name: otel-values - valuesKey: values.yaml \ No newline at end of file diff --git a/platform/tracing/base/opentelemetry-collector/helm-repository.yaml b/platform/tracing/base/opentelemetry-collector/helm-repository.yaml deleted file mode 100644 index 340129f..0000000 --- a/platform/tracing/base/opentelemetry-collector/helm-repository.yaml +++ /dev/null @@ -1,11 +0,0 @@ -apiVersion: source.toolkit.fluxcd.io/v1 -kind: HelmRepository - -metadata: - name: open-telemetry - namespace: flux-system - -spec: - interval: 24h - - url: https://open-telemetry.github.io/opentelemetry-helm-charts \ No newline at end of file diff --git a/platform/tracing/base/opentelemetry-collector/kustomization.yaml b/platform/tracing/base/opentelemetry-collector/kustomization.yaml index b7eeecc..33cf68b 100644 --- a/platform/tracing/base/opentelemetry-collector/kustomization.yaml +++ b/platform/tracing/base/opentelemetry-collector/kustomization.yaml @@ -3,7 +3,5 @@ kind: Kustomization resources: - - helm-release.yaml - - help-repository.yaml - - pipelines.yaml - - values.yaml \ No newline at end of file + - application.yaml + - values-common.yaml \ No newline at end of file diff --git a/platform/tracing/base/opentelemetry-collector/pipelines.yaml b/platform/tracing/base/opentelemetry-collector/pipelines.yaml deleted file mode 100644 index e096221..0000000 --- a/platform/tracing/base/opentelemetry-collector/pipelines.yaml +++ /dev/null @@ -1,51 +0,0 @@ -config: - - receivers: - - otlp: - - protocols: - - grpc: - - endpoint: 0.0.0.0:4317 - - http: - - endpoint: 0.0.0.0:4318 - - - processors: - - batch: - - - exporters: - - otlp/tempo: - - endpoint: - tempo.tracing.svc.cluster.local:4317 - - tls: - - insecure: true - - - service: - - pipelines: - - traces: - - receivers: - - - otlp - - processors: - - - batch - - exporters: - - - otlp/tempo \ No newline at end of file diff --git a/platform/tracing/base/opentelemetry-collector/values.yaml b/platform/tracing/base/opentelemetry-collector/values-common.yaml similarity index 100% rename from platform/tracing/base/opentelemetry-collector/values.yaml rename to platform/tracing/base/opentelemetry-collector/values-common.yaml diff --git a/platform/tracing/base/tempo/application.yaml b/platform/tracing/base/tempo/application.yaml new file mode 100644 index 0000000..3674510 --- /dev/null +++ b/platform/tracing/base/tempo/application.yaml @@ -0,0 +1,29 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: tempo + namespace: argocd + +spec: + project: default + + source: + repoURL: https://grafana.github.io/helm-charts + chart: tempo + targetRevision: 1.18.2 + + helm: + valueFiles: + - values-common.yaml + + destination: + server: https://kubernetes.default.svc + + syncPolicy: + automated: + prune: true + selfHeal: true + + syncOptions: + - CreateNamespace=true \ No newline at end of file diff --git a/platform/tracing/base/tempo/helm-release.yaml b/platform/tracing/base/tempo/helm-release.yaml deleted file mode 100644 index 763c576..0000000 --- a/platform/tracing/base/tempo/helm-release.yaml +++ /dev/null @@ -1,31 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease - -metadata: - name: tempo - -spec: - interval: 30m - - chart: - spec: - chart: tempo - version: "1.18.2" - - sourceRef: - kind: HelmRepository - name: grafana - namespace: flux-system - - install: - remediation: - retries: 3 - - upgrade: - remediation: - retries: 3 - - valuesFrom: - - kind: ConfigMap - name: tempo-values - valuesKey: values.yaml \ No newline at end of file diff --git a/platform/tracing/base/tempo/helm-repository.yaml b/platform/tracing/base/tempo/helm-repository.yaml deleted file mode 100644 index a10939e..0000000 --- a/platform/tracing/base/tempo/helm-repository.yaml +++ /dev/null @@ -1,10 +0,0 @@ -apiVersion: source.toolkit.fluxcd.io/v1 -kind: HelmRepository - -metadata: - name: grafana - namespace: flux-system - -spec: - interval: 24h - url: https://grafana.github.io/helm-charts \ No newline at end of file diff --git a/platform/tracing/base/tempo/kustomization.yaml b/platform/tracing/base/tempo/kustomization.yaml index 429d734..33cf68b 100644 --- a/platform/tracing/base/tempo/kustomization.yaml +++ b/platform/tracing/base/tempo/kustomization.yaml @@ -3,6 +3,5 @@ kind: Kustomization resources: - - helm-release.yaml - - help-repository.yaml - - values.yaml \ No newline at end of file + - application.yaml + - values-common.yaml \ No newline at end of file diff --git a/platform/tracing/base/tempo/values.yaml b/platform/tracing/base/tempo/values-common.yaml similarity index 100% rename from platform/tracing/base/tempo/values.yaml rename to platform/tracing/base/tempo/values-common.yaml From 9fc5515d04f4505b37c016f34ec4c3ced5df9531 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 14:33:50 +0200 Subject: [PATCH 032/122] Added storage platform for monitoring --- .../security/overlays/dev/kustomization.yaml | 5 +++- .../storage/base/backup/kustomization.yaml | 11 ++++++++ platform/storage/base/backup/schedules.yaml | 0 .../base/ebs-csi-driver/application.yaml | 27 +++++++++++++++++++ .../base/ebs-csi-driver/kustomization.yaml | 7 +++++ .../base/ebs-csi-driver/values-common.yaml | 12 +++++++++ .../base/efs-csi-driver/application.yaml | 27 +++++++++++++++++++ .../base/efs-csi-driver/kustomization.yaml | 7 +++++ .../base/efs-csi-driver/values-common.yaml | 6 +++++ platform/storage/base/kustomization.yaml | 0 .../storage/base/snapshots/kustomization.yaml | 5 ++++ .../base/snapshots/volume-snapshot-class.yaml | 9 +++++++ platform/storage/base/storageclasses/efs.yaml | 16 +++++++++++ platform/storage/base/storageclasses/gp3.yaml | 16 +++++++++++ platform/storage/base/storageclasses/io2.yaml | 16 +++++++++++ .../base/storageclasses/kustomization.yaml | 7 +++++ platform/storage/base/velero/application.yaml | 27 +++++++++++++++++++ .../storage/base/velero/kustomization.yaml | 7 +++++ .../storage/base/velero/values-common.yaml | 20 ++++++++++++++ .../overlays/dev/backup-schedule-patch.yaml | 10 +++++++ .../dev/ebs-csi-driver-application-patch.yaml | 5 ++++ .../storage/overlays/dev/kustomization.yaml | 11 ++++++++ .../dev/velero-application-patch.yaml | 0 23 files changed, 250 insertions(+), 1 deletion(-) create mode 100644 platform/storage/base/backup/kustomization.yaml create mode 100644 platform/storage/base/backup/schedules.yaml create mode 100644 platform/storage/base/ebs-csi-driver/application.yaml create mode 100644 platform/storage/base/ebs-csi-driver/kustomization.yaml create mode 100644 platform/storage/base/ebs-csi-driver/values-common.yaml create mode 100644 platform/storage/base/efs-csi-driver/application.yaml create mode 100644 platform/storage/base/efs-csi-driver/kustomization.yaml create mode 100644 platform/storage/base/efs-csi-driver/values-common.yaml create mode 100644 platform/storage/base/kustomization.yaml create mode 100644 platform/storage/base/snapshots/kustomization.yaml create mode 100644 platform/storage/base/snapshots/volume-snapshot-class.yaml create mode 100644 platform/storage/base/storageclasses/efs.yaml create mode 100644 platform/storage/base/storageclasses/gp3.yaml create mode 100644 platform/storage/base/storageclasses/io2.yaml create mode 100644 platform/storage/base/storageclasses/kustomization.yaml create mode 100644 platform/storage/base/velero/application.yaml create mode 100644 platform/storage/base/velero/kustomization.yaml create mode 100644 platform/storage/base/velero/values-common.yaml create mode 100644 platform/storage/overlays/dev/backup-schedule-patch.yaml create mode 100644 platform/storage/overlays/dev/ebs-csi-driver-application-patch.yaml create mode 100644 platform/storage/overlays/dev/kustomization.yaml create mode 100644 platform/storage/overlays/dev/velero-application-patch.yaml diff --git a/platform/security/overlays/dev/kustomization.yaml b/platform/security/overlays/dev/kustomization.yaml index 6d2696f..ea0f274 100644 --- a/platform/security/overlays/dev/kustomization.yaml +++ b/platform/security/overlays/dev/kustomization.yaml @@ -4,4 +4,7 @@ kind: Kustomization resources: - ../../base/ - - application-patch.yaml \ No newline at end of file + - application-patch.yaml + +patches: + - path: application-patch.yaml \ No newline at end of file diff --git a/platform/storage/base/backup/kustomization.yaml b/platform/storage/base/backup/kustomization.yaml new file mode 100644 index 0000000..b0f003a --- /dev/null +++ b/platform/storage/base/backup/kustomization.yaml @@ -0,0 +1,11 @@ +apiVersion: velero.io/v1 +kind: Schedule + +metadata: + name: daily-backup + +spec: + schedule: "0 2 * * *" + + template: + ttl: 168h \ No newline at end of file diff --git a/platform/storage/base/backup/schedules.yaml b/platform/storage/base/backup/schedules.yaml new file mode 100644 index 0000000..e69de29 diff --git a/platform/storage/base/ebs-csi-driver/application.yaml b/platform/storage/base/ebs-csi-driver/application.yaml new file mode 100644 index 0000000..5df89be --- /dev/null +++ b/platform/storage/base/ebs-csi-driver/application.yaml @@ -0,0 +1,27 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: ebs-csi-driver + namespace: argocd + +spec: + project: default + + source: + repoURL: https://kubernetes-sigs.github.io/aws-ebs-csi-driver + chart: aws-ebs-csi-driver + targetRevision: 2.44.0 + + helm: + valueFiles: + - values-common.yaml + + destination: + server: https://kubernetes.default.svc + namespace: kube-system + + syncPolicy: + automated: + prune: true + selfHeal: true \ No newline at end of file diff --git a/platform/storage/base/ebs-csi-driver/kustomization.yaml b/platform/storage/base/ebs-csi-driver/kustomization.yaml new file mode 100644 index 0000000..e76672a --- /dev/null +++ b/platform/storage/base/ebs-csi-driver/kustomization.yaml @@ -0,0 +1,7 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + + +resources: + - values.yaml + - application.yaml \ No newline at end of file diff --git a/platform/storage/base/ebs-csi-driver/values-common.yaml b/platform/storage/base/ebs-csi-driver/values-common.yaml new file mode 100644 index 0000000..2091590 --- /dev/null +++ b/platform/storage/base/ebs-csi-driver/values-common.yaml @@ -0,0 +1,12 @@ +controller: + replicaCount: 2 + +storageClasses: [] + +enableVolumeScheduling: true +enableVolumeResizing: true +enableVolumeSnapshot: true + +serviceAccount: + create: true + name: ebs-csi-controller-sa \ No newline at end of file diff --git a/platform/storage/base/efs-csi-driver/application.yaml b/platform/storage/base/efs-csi-driver/application.yaml new file mode 100644 index 0000000..6d53745 --- /dev/null +++ b/platform/storage/base/efs-csi-driver/application.yaml @@ -0,0 +1,27 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: efs-csi-driver + namespace: argocd + +spec: + project: default + + source: + repoURL: https://kubernetes-sigs.github.io/aws-efs-csi-driver + chart: aws-efs-csi-driver + targetRevision: 3.2.8 + + helm: + valueFiles: + - values-common.yaml + + destination: + server: https://kubernetes.default.svc + namespace: kube-system + + syncPolicy: + automated: + prune: true + selfHeal: true \ No newline at end of file diff --git a/platform/storage/base/efs-csi-driver/kustomization.yaml b/platform/storage/base/efs-csi-driver/kustomization.yaml new file mode 100644 index 0000000..e76672a --- /dev/null +++ b/platform/storage/base/efs-csi-driver/kustomization.yaml @@ -0,0 +1,7 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + + +resources: + - values.yaml + - application.yaml \ No newline at end of file diff --git a/platform/storage/base/efs-csi-driver/values-common.yaml b/platform/storage/base/efs-csi-driver/values-common.yaml new file mode 100644 index 0000000..7b25f3b --- /dev/null +++ b/platform/storage/base/efs-csi-driver/values-common.yaml @@ -0,0 +1,6 @@ +controller: + replicaCount: 2 + +serviceAccount: + create: true + name: efs-csi-controller-sa \ No newline at end of file diff --git a/platform/storage/base/kustomization.yaml b/platform/storage/base/kustomization.yaml new file mode 100644 index 0000000..e69de29 diff --git a/platform/storage/base/snapshots/kustomization.yaml b/platform/storage/base/snapshots/kustomization.yaml new file mode 100644 index 0000000..8c51cca --- /dev/null +++ b/platform/storage/base/snapshots/kustomization.yaml @@ -0,0 +1,5 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - volume-snapshot-class.yaml \ No newline at end of file diff --git a/platform/storage/base/snapshots/volume-snapshot-class.yaml b/platform/storage/base/snapshots/volume-snapshot-class.yaml new file mode 100644 index 0000000..205bac3 --- /dev/null +++ b/platform/storage/base/snapshots/volume-snapshot-class.yaml @@ -0,0 +1,9 @@ +apiVersion: snapshot.storage.k8s.io/v1 +kind: VolumeSnapshotClass + +metadata: + name: ebs-snapshot + +driver: ebs.csi.aws.com + +deletionPolicy: Delete \ No newline at end of file diff --git a/platform/storage/base/storageclasses/efs.yaml b/platform/storage/base/storageclasses/efs.yaml new file mode 100644 index 0000000..5ad2bb4 --- /dev/null +++ b/platform/storage/base/storageclasses/efs.yaml @@ -0,0 +1,16 @@ +apiVersion: storage.k8s.io/v1 +kind: StorageClass + +metadata: + name: efs + +provisioner: efs.csi.aws.com + +parameters: + provisioningMode: efs-ap + +directoryPerms: "700" + +reclaimPolicy: Delete + +volumeBindingMode: Immediate \ No newline at end of file diff --git a/platform/storage/base/storageclasses/gp3.yaml b/platform/storage/base/storageclasses/gp3.yaml new file mode 100644 index 0000000..67dedde --- /dev/null +++ b/platform/storage/base/storageclasses/gp3.yaml @@ -0,0 +1,16 @@ +apiVersion: storage.k8s.io/v1 +kind: StorageClass + +metadata: + name: gp3 + +provisioner: ebs.csi.aws.com + +allowVolumeExpansion: true + +volumeBindingMode: WaitForFirstConsumer + +parameters: + type: gp3 + +reclaimPolicy: Delete \ No newline at end of file diff --git a/platform/storage/base/storageclasses/io2.yaml b/platform/storage/base/storageclasses/io2.yaml new file mode 100644 index 0000000..e93043b --- /dev/null +++ b/platform/storage/base/storageclasses/io2.yaml @@ -0,0 +1,16 @@ +apiVersion: storage.k8s.io/v1 +kind: StorageClass + +metadata: + name: io2 + +provisioner: ebs.csi.aws.com + +allowVolumeExpansion: true + +volumeBindingMode: WaitForFirstConsumer + +parameters: + type: io2 + +reclaimPolicy: Delete \ No newline at end of file diff --git a/platform/storage/base/storageclasses/kustomization.yaml b/platform/storage/base/storageclasses/kustomization.yaml new file mode 100644 index 0000000..884d5ee --- /dev/null +++ b/platform/storage/base/storageclasses/kustomization.yaml @@ -0,0 +1,7 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - gp3.yaml + - io2.yaml + - efs.yaml \ No newline at end of file diff --git a/platform/storage/base/velero/application.yaml b/platform/storage/base/velero/application.yaml new file mode 100644 index 0000000..8a83c7e --- /dev/null +++ b/platform/storage/base/velero/application.yaml @@ -0,0 +1,27 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: velero + namespace: argocd + +spec: + project: default + + source: + repoURL: https://vmware-tanzu.github.io/helm-charts + chart: velero + targetRevision: 11.1.1 + + helm: + valueFiles: + - values-common.yaml + + destination: + server: https://kubernetes.default.svc + namespace: velero + + syncPolicy: + automated: + prune: true + selfHeal: true \ No newline at end of file diff --git a/platform/storage/base/velero/kustomization.yaml b/platform/storage/base/velero/kustomization.yaml new file mode 100644 index 0000000..e76672a --- /dev/null +++ b/platform/storage/base/velero/kustomization.yaml @@ -0,0 +1,7 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + + +resources: + - values.yaml + - application.yaml \ No newline at end of file diff --git a/platform/storage/base/velero/values-common.yaml b/platform/storage/base/velero/values-common.yaml new file mode 100644 index 0000000..95a24b5 --- /dev/null +++ b/platform/storage/base/velero/values-common.yaml @@ -0,0 +1,20 @@ +credentials: + useSecret: false + +initContainers: + - name: velero-plugin-for-aws + + image: velero/velero-plugin-for-aws:v1.11.0 + + volumeMounts: + - mountPath: /target + name: plugins + +configuration: + backupStorageLocation: [] + + volumeSnapshotLocation: [] + +snapshotsEnabled: true + +deployNodeAgent: true \ No newline at end of file diff --git a/platform/storage/overlays/dev/backup-schedule-patch.yaml b/platform/storage/overlays/dev/backup-schedule-patch.yaml new file mode 100644 index 0000000..08d3647 --- /dev/null +++ b/platform/storage/overlays/dev/backup-schedule-patch.yaml @@ -0,0 +1,10 @@ +apiVersion: velero.io/v1 +kind: Schedule + +metadata: + name: daily-backup + +spec: + template: + includedNamespaces: + - dev \ No newline at end of file diff --git a/platform/storage/overlays/dev/ebs-csi-driver-application-patch.yaml b/platform/storage/overlays/dev/ebs-csi-driver-application-patch.yaml new file mode 100644 index 0000000..1e4a640 --- /dev/null +++ b/platform/storage/overlays/dev/ebs-csi-driver-application-patch.yaml @@ -0,0 +1,5 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application + +metadata: + name: ebs-csi-driver \ No newline at end of file diff --git a/platform/storage/overlays/dev/kustomization.yaml b/platform/storage/overlays/dev/kustomization.yaml new file mode 100644 index 0000000..7417143 --- /dev/null +++ b/platform/storage/overlays/dev/kustomization.yaml @@ -0,0 +1,11 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - ../../base + + +patches: + - path: ebs-csi-driver-application-patch.yaml + - path: velero-application-patch.yaml + - path: backup-schedule-patch.yaml \ No newline at end of file diff --git a/platform/storage/overlays/dev/velero-application-patch.yaml b/platform/storage/overlays/dev/velero-application-patch.yaml new file mode 100644 index 0000000..e69de29 From 59c99ad8df0d355915f2524df0f8f7b3ed2b5f75 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 15:00:55 +0200 Subject: [PATCH 033/122] Added storage platform for monitoring --- platform/overlays/dev/kustomization.yaml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/platform/overlays/dev/kustomization.yaml b/platform/overlays/dev/kustomization.yaml index d76d8a8..85d3916 100644 --- a/platform/overlays/dev/kustomization.yaml +++ b/platform/overlays/dev/kustomization.yaml @@ -7,4 +7,5 @@ resources: - ../../monitoring/overlays/dev - ../../networking/overlays/dev - ../../security/overlays/dev - - ../../tracing/overlays/dev \ No newline at end of file + - ../../tracing/overlays/dev + - ../../storage/overlays/dev \ No newline at end of file From 13ea5551d04af106b525c0e505b73d38904b47ac Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 15:14:18 +0200 Subject: [PATCH 034/122] Added storage platform for monitoring --- infrastructure/overlay/dev/ingress.yaml | 2 +- .../overlays/dev/aws-load-balancer-controller-patch.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/infrastructure/overlay/dev/ingress.yaml b/infrastructure/overlay/dev/ingress.yaml index 4937212..dc8080b 100644 --- a/infrastructure/overlay/dev/ingress.yaml +++ b/infrastructure/overlay/dev/ingress.yaml @@ -11,7 +11,7 @@ metadata: # HTTPS configuration alb.ingress.kubernetes.io/listen-ports: '[{"HTTP":80},{"HTTPS":443}]' - alb.ingress.kubernetes.io/certificate-arn: arn:aws:acm:us-east-1:579871530627:certificate/dca3c1a0-b8ed-494c-b512-213630efd2dd + alb.ingress.kubernetes.io/certificate-arn: arn:aws:acm:us-east-1:579871530627:certificate/d0ddcc04-09b5-4ffe-9910-d01b165fdb26 # Redirect HTTP to HTTPS alb.ingress.kubernetes.io/ssl-redirect: '443' diff --git a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml index 14694a3..d68fcc7 100644 --- a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml +++ b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml @@ -10,7 +10,7 @@ spec: values: | clusterName: eks-dev-cluster region: us-east-1 - vpcId: vpc-0123456789abcdef + vpcId: vpc-0ed36055c1f322ad8 serviceAccount: create: true From 45f205a8d522a696ca19b3f680b2f6d761eda7db Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 15:29:26 +0200 Subject: [PATCH 035/122] Added storage platform for monitoring --- .../kube-prometheus-stack/alertmanager/external-secret.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/platform/monitoring/base/kube-prometheus-stack/alertmanager/external-secret.yaml b/platform/monitoring/base/kube-prometheus-stack/alertmanager/external-secret.yaml index d890a99..05d6627 100644 --- a/platform/monitoring/base/kube-prometheus-stack/alertmanager/external-secret.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/alertmanager/external-secret.yaml @@ -18,5 +18,5 @@ spec: data: - secretKey: slack-webhook remoteRef: - key: alertmanager/notifications + key: alertmanager/notification property: slack-webhook \ No newline at end of file From 459486d5ff8bef7e443e160ee214348de0b916cf Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Thu, 30 Jul 2026 13:37:07 +0000 Subject: [PATCH 036/122] Promote product-service to 60bd3c6d9e924a7309f3c54b87743ac562d6c6fc --- apps/product-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/product-service/overlays/dev/kustomization.yaml b/apps/product-service/overlays/dev/kustomization.yaml index ff3ed92..fd04cd8 100644 --- a/apps/product-service/overlays/dev/kustomization.yaml +++ b/apps/product-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service - newTag: cc4950da0f80d7c9c44c52192faec727123b8a98 + newTag: 60bd3c6d9e924a7309f3c54b87743ac562d6c6fc From 71bf61a5a81ca559253f6f2c7ab5e64a3efb84cf Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Thu, 30 Jul 2026 13:37:24 +0000 Subject: [PATCH 037/122] Promote user-service to 60bd3c6d9e924a7309f3c54b87743ac562d6c6fc --- apps/user-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/user-service/overlays/dev/kustomization.yaml b/apps/user-service/overlays/dev/kustomization.yaml index 8a5b92c..0c5856d 100644 --- a/apps/user-service/overlays/dev/kustomization.yaml +++ b/apps/user-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service - newTag: cc4950da0f80d7c9c44c52192faec727123b8a98 + newTag: 60bd3c6d9e924a7309f3c54b87743ac562d6c6fc From df3fc25e5fbb25e68db2788687b456982fd7f52f Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Thu, 30 Jul 2026 13:37:26 +0000 Subject: [PATCH 038/122] Promote order-service to 60bd3c6d9e924a7309f3c54b87743ac562d6c6fc --- apps/order-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/order-service/overlays/dev/kustomization.yaml b/apps/order-service/overlays/dev/kustomization.yaml index 99c7f4e..75728ae 100644 --- a/apps/order-service/overlays/dev/kustomization.yaml +++ b/apps/order-service/overlays/dev/kustomization.yaml @@ -10,7 +10,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service - newTag: cc4950da0f80d7c9c44c52192faec727123b8a98 + newTag: 60bd3c6d9e924a7309f3c54b87743ac562d6c6fc replicas: - count: 1 From c8d94e82f7e65dc9fcf4a204df23217efbc83448 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Thu, 30 Jul 2026 13:38:06 +0000 Subject: [PATCH 039/122] Promote payment-service to 60bd3c6d9e924a7309f3c54b87743ac562d6c6fc --- apps/payment-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/payment-service/overlays/dev/kustomization.yaml b/apps/payment-service/overlays/dev/kustomization.yaml index 06b67e9..925267b 100644 --- a/apps/payment-service/overlays/dev/kustomization.yaml +++ b/apps/payment-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service - newTag: cc4950da0f80d7c9c44c52192faec727123b8a98 + newTag: 60bd3c6d9e924a7309f3c54b87743ac562d6c6fc From 9a03904219e8a1272273c43968f5f7ecf58f2343 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 15:42:15 +0200 Subject: [PATCH 040/122] Updated the image tag --- argocd/dev/applicationset-apps.yaml | 3 ++- argocd/dev/applicationset-infra.yaml | 3 ++- argocd/dev/applicationset-monitoring.yaml | 3 ++- argocd/dev/kustomization.yaml | 3 ++- argocd/dev/root-app.yaml | 3 ++- 5 files changed, 10 insertions(+), 5 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 197f11e..a3d50bf 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,4 +36,5 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 232eda5..b37e134 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,4 +34,5 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 1d79556..a1c0e79 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,4 +32,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index c13e6f0..b6bb9ed 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml \ No newline at end of file + - applicationset-monitoring.yaml + \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 76495e1..7593413 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,4 +20,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file From 106bb4e0b642d7bb7d0738434b083966f285dd49 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 16:00:18 +0200 Subject: [PATCH 041/122] Updated the image tag --- argocd/dev/applicationset-apps.yaml | 3 +-- argocd/dev/applicationset-infra.yaml | 3 +-- argocd/dev/applicationset-monitoring.yaml | 3 +-- argocd/dev/kustomization.yaml | 3 +-- argocd/dev/root-app.yaml | 3 +-- platform/ingress/base/kustomization.yaml | 2 +- 6 files changed, 6 insertions(+), 11 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index a3d50bf..0fdca31 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,5 +36,4 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index b37e134..4aa88d0 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,5 +34,4 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index a1c0e79..320d9b4 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,5 +32,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index b6bb9ed..45bad5e 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,5 +4,4 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml - \ No newline at end of file + - applicationset-monitoring.yaml \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 7593413..8f0b387 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,5 +20,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/platform/ingress/base/kustomization.yaml b/platform/ingress/base/kustomization.yaml index 6cfd7fb..0c3856a 100644 --- a/platform/ingress/base/kustomization.yaml +++ b/platform/ingress/base/kustomization.yaml @@ -2,6 +2,6 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - aws-load-balancer-controller/ + - applications/ - external-dns/ - cert-manager/ \ No newline at end of file From d9aff9d4ac725e9d5194e46e827606e21fd9509d Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 16:07:53 +0200 Subject: [PATCH 042/122] Updated the image tag --- .../base/cert-manager/cert-manager.yaml | 38 +++++++++++-------- .../base/cert-manager/values-common.yaml | 11 ++++++ 2 files changed, 34 insertions(+), 15 deletions(-) create mode 100644 platform/ingress/base/cert-manager/values-common.yaml diff --git a/platform/ingress/base/cert-manager/cert-manager.yaml b/platform/ingress/base/cert-manager/cert-manager.yaml index 3a3e385..4370273 100644 --- a/platform/ingress/base/cert-manager/cert-manager.yaml +++ b/platform/ingress/base/cert-manager/cert-manager.yaml @@ -1,18 +1,26 @@ -source: - repoURL: https://charts.jetstack.io - chart: cert-manager - targetRevision: v1.18.2 +apiVersion: argoproj.io/v1alpha1 +kind: Application - helm: - values: | - crds: - enabled: true +metadata: + name: cert-manager + namespace: argocd - replicaCount: 2 +spec: + project: default - prometheus: - enabled: true - servicemonitor: - enabled: true - labels: - prometheus: kube-prometheus \ No newline at end of file + source: + repoURL: https://charts.jetstack.io + chart: cert-manager + targetRevision: v1.18.2 + + helm: + valueFiles: + - values-common.yaml + + destination: + server: https://kubernetes.default.svc + + syncPolicy: + automated: + prune: true + selfHeal: true \ No newline at end of file diff --git a/platform/ingress/base/cert-manager/values-common.yaml b/platform/ingress/base/cert-manager/values-common.yaml new file mode 100644 index 0000000..00d42be --- /dev/null +++ b/platform/ingress/base/cert-manager/values-common.yaml @@ -0,0 +1,11 @@ +crds: + enabled: true + +replicaCount: 2 + +prometheus: + enabled: true + servicemonitor: + enabled: true + labels: + prometheus: kube-prometheus \ No newline at end of file From aa1e31c1982abc1e96730629a4462e773a33fa2c Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 16:08:36 +0200 Subject: [PATCH 043/122] Updated the image tag --- argocd/dev/applicationset-apps.yaml | 3 ++- argocd/dev/applicationset-infra.yaml | 3 ++- argocd/dev/applicationset-monitoring.yaml | 3 ++- argocd/dev/kustomization.yaml | 3 ++- argocd/dev/root-app.yaml | 3 ++- 5 files changed, 10 insertions(+), 5 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 0fdca31..b27a3be 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,4 +36,5 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 4aa88d0..81aeafc 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,4 +34,5 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 320d9b4..a6e356c 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,4 +32,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 45bad5e..eac61f5 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml \ No newline at end of file + - applicationset-monitoring.yaml + \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 8f0b387..cfbc1dc 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,4 +20,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file From 542b57552cabfcecaa3a00e9241ee19bdeb9d331 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 16:14:52 +0200 Subject: [PATCH 044/122] Updated the image tag --- argocd/dev/applicationset-apps.yaml | 3 +-- argocd/dev/applicationset-infra.yaml | 3 +-- argocd/dev/applicationset-monitoring.yaml | 3 +-- argocd/dev/kustomization.yaml | 3 +-- argocd/dev/root-app.yaml | 3 +-- platform/ingress/overlays/dev/kustomization.yaml | 8 +++++--- 6 files changed, 10 insertions(+), 13 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index b27a3be..40470b1 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,5 +36,4 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 81aeafc..ed69051 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,5 +34,4 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index a6e356c..3da6d21 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,5 +32,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index eac61f5..75338bc 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,5 +4,4 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml - \ No newline at end of file + - applicationset-monitoring.yaml \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index cfbc1dc..7b607fe 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,5 +20,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/platform/ingress/overlays/dev/kustomization.yaml b/platform/ingress/overlays/dev/kustomization.yaml index d2d5617..c03f444 100644 --- a/platform/ingress/overlays/dev/kustomization.yaml +++ b/platform/ingress/overlays/dev/kustomization.yaml @@ -6,6 +6,8 @@ namespace: dev resources: - ../../base - ingress-namespace.yaml - - external-dns-patch.yaml - - aws-load-balancer-controller-patch.yaml - - letsencrypt-patch.yaml \ No newline at end of file + +patches: + - path: external-dns-patch.yaml + - path: aws-load-balancer-controller-patch.yaml + - path: letsencrypt-patch.yaml \ No newline at end of file From cfa7ed07a98298c93a6d6bc2c7040f57c6546b4b Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 16:36:36 +0200 Subject: [PATCH 045/122] Updated the image tag --- argocd/dev/applicationset-apps.yaml | 3 ++- argocd/dev/applicationset-infra.yaml | 3 ++- argocd/dev/applicationset-monitoring.yaml | 3 ++- argocd/dev/kustomization.yaml | 3 ++- argocd/dev/root-app.yaml | 3 ++- .../base/cert-manager/clusterissuers/kustomization.yaml | 5 +++++ .../base/cert-manager/clusterissuers/letsencrypt.yaml | 2 +- platform/ingress/base/cert-manager/kustomization.yaml | 2 +- .../overlays/dev/aws-load-balancer-controller-patch.yaml | 4 ++++ .../dev/{letsencrypt-patch.yaml => etsencrypt-patch.yaml} | 2 +- platform/ingress/overlays/dev/external-dns-patch.yaml | 3 +++ platform/ingress/overlays/dev/kustomization.yaml | 2 +- 12 files changed, 26 insertions(+), 9 deletions(-) create mode 100644 platform/ingress/base/cert-manager/clusterissuers/kustomization.yaml rename platform/ingress/overlays/dev/{letsencrypt-patch.yaml => etsencrypt-patch.yaml} (81%) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 40470b1..c1b2eb8 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,4 +36,5 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index ed69051..8e683d5 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,4 +34,5 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 3da6d21..42b6088 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,4 +32,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 75338bc..9ae89ab 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml \ No newline at end of file + - applicationset-monitoring.yaml + \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 7b607fe..832b080 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,4 +20,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/platform/ingress/base/cert-manager/clusterissuers/kustomization.yaml b/platform/ingress/base/cert-manager/clusterissuers/kustomization.yaml new file mode 100644 index 0000000..f056c8b --- /dev/null +++ b/platform/ingress/base/cert-manager/clusterissuers/kustomization.yaml @@ -0,0 +1,5 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - letsencrypt.yaml \ No newline at end of file diff --git a/platform/ingress/base/cert-manager/clusterissuers/letsencrypt.yaml b/platform/ingress/base/cert-manager/clusterissuers/letsencrypt.yaml index 1dea7e0..fe4a5da 100644 --- a/platform/ingress/base/cert-manager/clusterissuers/letsencrypt.yaml +++ b/platform/ingress/base/cert-manager/clusterissuers/letsencrypt.yaml @@ -11,7 +11,7 @@ spec: server: https://acme-v02.api.letsencrypt.org/directory privateKeySecretRef: - name: letsencrypt + name: letsencrypt-account-key solvers: - http01: diff --git a/platform/ingress/base/cert-manager/kustomization.yaml b/platform/ingress/base/cert-manager/kustomization.yaml index 89155d2..f4e4554 100644 --- a/platform/ingress/base/cert-manager/kustomization.yaml +++ b/platform/ingress/base/cert-manager/kustomization.yaml @@ -2,5 +2,5 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - clusterissuers/letsencrypt.yaml + - clusterissuers/ - cert-manager.yaml \ No newline at end of file diff --git a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml index d68fcc7..d6da8a7 100644 --- a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml +++ b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml @@ -3,8 +3,12 @@ kind: Application metadata: name: aws-load-balancer-controller + namespace: argocd spec: + destination: + namespace: dev + source: helm: values: | diff --git a/platform/ingress/overlays/dev/letsencrypt-patch.yaml b/platform/ingress/overlays/dev/etsencrypt-patch.yaml similarity index 81% rename from platform/ingress/overlays/dev/letsencrypt-patch.yaml rename to platform/ingress/overlays/dev/etsencrypt-patch.yaml index 6cf846e..252b939 100644 --- a/platform/ingress/overlays/dev/letsencrypt-patch.yaml +++ b/platform/ingress/overlays/dev/etsencrypt-patch.yaml @@ -2,7 +2,7 @@ apiVersion: cert-manager.io/v1 kind: ClusterIssuer metadata: - name: letsencrypt + name: etsencrypt.yaml spec: acme: diff --git a/platform/ingress/overlays/dev/external-dns-patch.yaml b/platform/ingress/overlays/dev/external-dns-patch.yaml index 785829d..86f9476 100644 --- a/platform/ingress/overlays/dev/external-dns-patch.yaml +++ b/platform/ingress/overlays/dev/external-dns-patch.yaml @@ -6,6 +6,9 @@ metadata: namespace: argocd spec: + destination: + namespace: dev + source: helm: values: | diff --git a/platform/ingress/overlays/dev/kustomization.yaml b/platform/ingress/overlays/dev/kustomization.yaml index c03f444..029d2ba 100644 --- a/platform/ingress/overlays/dev/kustomization.yaml +++ b/platform/ingress/overlays/dev/kustomization.yaml @@ -10,4 +10,4 @@ resources: patches: - path: external-dns-patch.yaml - path: aws-load-balancer-controller-patch.yaml - - path: letsencrypt-patch.yaml \ No newline at end of file + - path: etsencrypt-patch.yaml \ No newline at end of file From deaea77014acf7a0efe5a2ee5ba6f2d822804061 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 16:44:57 +0200 Subject: [PATCH 046/122] Updated the image tag --- argocd/dev/applicationset-apps.yaml | 3 +-- argocd/dev/applicationset-infra.yaml | 3 +-- argocd/dev/applicationset-monitoring.yaml | 3 +-- argocd/dev/kustomization.yaml | 3 +-- argocd/dev/root-app.yaml | 3 +-- ...rypt-patch.yaml => letsencrypt-patch.yaml} | 2 +- platform/ingress/overlays/dev/letsencrypt.txt | 19 +++++++++++++++++++ 7 files changed, 25 insertions(+), 11 deletions(-) rename platform/ingress/overlays/dev/{etsencrypt-patch.yaml => letsencrypt-patch.yaml} (81%) create mode 100644 platform/ingress/overlays/dev/letsencrypt.txt diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index c1b2eb8..48fbb59 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,5 +36,4 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 8e683d5..1e863c2 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,5 +34,4 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 42b6088..f92c092 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,5 +32,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 9ae89ab..75338bc 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,5 +4,4 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml - \ No newline at end of file + - applicationset-monitoring.yaml \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 832b080..92e60e2 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,5 +20,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/platform/ingress/overlays/dev/etsencrypt-patch.yaml b/platform/ingress/overlays/dev/letsencrypt-patch.yaml similarity index 81% rename from platform/ingress/overlays/dev/etsencrypt-patch.yaml rename to platform/ingress/overlays/dev/letsencrypt-patch.yaml index 252b939..6b9fac4 100644 --- a/platform/ingress/overlays/dev/etsencrypt-patch.yaml +++ b/platform/ingress/overlays/dev/letsencrypt-patch.yaml @@ -2,7 +2,7 @@ apiVersion: cert-manager.io/v1 kind: ClusterIssuer metadata: - name: etsencrypt.yaml + name: letsencrypt.yaml spec: acme: diff --git a/platform/ingress/overlays/dev/letsencrypt.txt b/platform/ingress/overlays/dev/letsencrypt.txt new file mode 100644 index 0000000..668023b --- /dev/null +++ b/platform/ingress/overlays/dev/letsencrypt.txt @@ -0,0 +1,19 @@ +apiVersion: cert-manager.io/v1 +kind: ClusterIssuer + +metadata: + name: letsencrypt + +spec: + acme: + email: admin@dev.example.com + + server: https://acme-v02.api.letsencrypt.org/directory + + privateKeySecretRef: + name: letsencrypt-account-key + + solvers: + - http01: + ingress: + ingressClassName: alb \ No newline at end of file From eb71bde9818ebceb8d3e91d8ab1829ef8024cbed Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 18:44:52 +0200 Subject: [PATCH 047/122] Updated the image tag --- .../clusterissuers/letsencrypt.yaml | 19 ---------------- .../base/cert-manager/kustomization.yaml | 1 - .../ingress/overlays/dev/kustomization.yaml | 4 ++-- .../overlays/dev/letsencrypt-patch.yaml | 9 -------- .../dev/{letsencrypt.txt => letsencrypt.yaml} | 0 .../logging/overlays/dev/kustomization.yaml | 4 ++-- .../kube-prometheus-stack/kustomization.yaml | 22 +++++++++---------- platform/monitoring/base/kustomization.yaml | 16 +------------- .../overlays/dev/kustomization.yaml | 5 ++--- .../base/metrics-server/kustomization.yaml | 1 - .../overlays/dev/kustomization.yaml | 1 - .../base/kyverno-policies}/kustomization.yaml | 2 +- .../security/base/kyverno/kustomization.yaml | 1 - .../security/overlays/dev/kustomization.yaml | 2 +- .../base/ebs-csi-driver/kustomization.yaml | 1 - .../base/efs-csi-driver/kustomization.yaml | 1 - .../storage/base/velero/kustomization.yaml | 1 - .../kustomization.yaml | 3 +-- .../tracing/base/tempo/kustomization.yaml | 3 +-- .../tracing/overlays/dev/kustomization.yaml | 3 ++- 20 files changed, 24 insertions(+), 75 deletions(-) delete mode 100644 platform/ingress/base/cert-manager/clusterissuers/letsencrypt.yaml delete mode 100644 platform/ingress/overlays/dev/letsencrypt-patch.yaml rename platform/ingress/overlays/dev/{letsencrypt.txt => letsencrypt.yaml} (100%) rename platform/{ingress/base/cert-manager/clusterissuers => security/base/kyverno-policies}/kustomization.yaml (78%) diff --git a/platform/ingress/base/cert-manager/clusterissuers/letsencrypt.yaml b/platform/ingress/base/cert-manager/clusterissuers/letsencrypt.yaml deleted file mode 100644 index fe4a5da..0000000 --- a/platform/ingress/base/cert-manager/clusterissuers/letsencrypt.yaml +++ /dev/null @@ -1,19 +0,0 @@ -apiVersion: cert-manager.io/v1 -kind: ClusterIssuer - -metadata: - name: letsencrypt - -spec: - acme: - email: REPLACE_ME - - server: https://acme-v02.api.letsencrypt.org/directory - - privateKeySecretRef: - name: letsencrypt-account-key - - solvers: - - http01: - ingress: - ingressClassName: alb \ No newline at end of file diff --git a/platform/ingress/base/cert-manager/kustomization.yaml b/platform/ingress/base/cert-manager/kustomization.yaml index f4e4554..9e5bf47 100644 --- a/platform/ingress/base/cert-manager/kustomization.yaml +++ b/platform/ingress/base/cert-manager/kustomization.yaml @@ -2,5 +2,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - clusterissuers/ - cert-manager.yaml \ No newline at end of file diff --git a/platform/ingress/overlays/dev/kustomization.yaml b/platform/ingress/overlays/dev/kustomization.yaml index 029d2ba..eed3428 100644 --- a/platform/ingress/overlays/dev/kustomization.yaml +++ b/platform/ingress/overlays/dev/kustomization.yaml @@ -5,9 +5,9 @@ namespace: dev resources: - ../../base + - letsencrypt.yaml - ingress-namespace.yaml patches: - path: external-dns-patch.yaml - - path: aws-load-balancer-controller-patch.yaml - - path: etsencrypt-patch.yaml \ No newline at end of file + - path: aws-load-balancer-controller-patch.yaml \ No newline at end of file diff --git a/platform/ingress/overlays/dev/letsencrypt-patch.yaml b/platform/ingress/overlays/dev/letsencrypt-patch.yaml deleted file mode 100644 index 6b9fac4..0000000 --- a/platform/ingress/overlays/dev/letsencrypt-patch.yaml +++ /dev/null @@ -1,9 +0,0 @@ -apiVersion: cert-manager.io/v1 -kind: ClusterIssuer - -metadata: - name: letsencrypt.yaml - -spec: - acme: - email: admin@dev.example.com \ No newline at end of file diff --git a/platform/ingress/overlays/dev/letsencrypt.txt b/platform/ingress/overlays/dev/letsencrypt.yaml similarity index 100% rename from platform/ingress/overlays/dev/letsencrypt.txt rename to platform/ingress/overlays/dev/letsencrypt.yaml diff --git a/platform/logging/overlays/dev/kustomization.yaml b/platform/logging/overlays/dev/kustomization.yaml index 7722e40..0edffb7 100644 --- a/platform/logging/overlays/dev/kustomization.yaml +++ b/platform/logging/overlays/dev/kustomization.yaml @@ -4,5 +4,5 @@ kind: Kustomization namespace: dev resources: - - logging-namespace.yaml - - ../../base \ No newline at end of file + - ../../base + - logging-namespace.yaml \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml index 5b41961..8385400 100644 --- a/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml @@ -2,16 +2,16 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - helm-repository.yaml - - helm-release.yaml - - exporters/ + - alertmanager/ + - blackbox-exporter/ + - grafana/ + - networkpolicies/ + - postgres-exporter/ - prometheusrules/ + - recording-rules/ + - redis-exporter/ - servicemonitors/ - -configMapGenerator: - - name: prometheus-stack-values - files: - - values.yaml - -generatorOptions: - disableNameSuffixHash: true \ No newline at end of file + - application.yaml + - external-secret.yaml + - values-common.yaml + \ No newline at end of file diff --git a/platform/monitoring/base/kustomization.yaml b/platform/monitoring/base/kustomization.yaml index c67aa35..b97675d 100644 --- a/platform/monitoring/base/kustomization.yaml +++ b/platform/monitoring/base/kustomization.yaml @@ -2,18 +2,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - alertmanager/ - - networkpolicies/ - - grafana/ - - postgres-exporter/ - - redis-exporter/ - - blackbox-exporter/ - - prometheusrules/ - - recording-rules/ - - servicemonitors/ - - - external-secret.yaml - - application.yaml - - kustomization.yaml - - values-common.yaml - \ No newline at end of file + - kube-prometheus-stack/ \ No newline at end of file diff --git a/platform/monitoring/overlays/dev/kustomization.yaml b/platform/monitoring/overlays/dev/kustomization.yaml index d787113..761c9f2 100644 --- a/platform/monitoring/overlays/dev/kustomization.yaml +++ b/platform/monitoring/overlays/dev/kustomization.yaml @@ -6,14 +6,13 @@ namespace: dev resources: - ../../base - monitoring-namespace.yaml - - kube-prometheus-stack-patch.yaml - order/application.yaml - payment/application.yaml - product/application.yaml - user/application.yaml - - postgres-exporter-patch.yaml - values-dev.yaml patches: - - path: kube-prometheus-stack-patch.yaml \ No newline at end of file + - path: kube-prometheus-stack-patch.yaml + - path: postgres-exporter-patch.yaml \ No newline at end of file diff --git a/platform/networking/base/metrics-server/kustomization.yaml b/platform/networking/base/metrics-server/kustomization.yaml index 872397d..04b2ef6 100644 --- a/platform/networking/base/metrics-server/kustomization.yaml +++ b/platform/networking/base/metrics-server/kustomization.yaml @@ -3,4 +3,3 @@ kind: Kustomization resources: - application.yaml - - values-common.yaml diff --git a/platform/networking/overlays/dev/kustomization.yaml b/platform/networking/overlays/dev/kustomization.yaml index 557b706..d64f20b 100644 --- a/platform/networking/overlays/dev/kustomization.yaml +++ b/platform/networking/overlays/dev/kustomization.yaml @@ -3,7 +3,6 @@ kind: Kustomization resources: - ../../base - - application-patch.yaml patches: - path: application-patch.yaml \ No newline at end of file diff --git a/platform/ingress/base/cert-manager/clusterissuers/kustomization.yaml b/platform/security/base/kyverno-policies/kustomization.yaml similarity index 78% rename from platform/ingress/base/cert-manager/clusterissuers/kustomization.yaml rename to platform/security/base/kyverno-policies/kustomization.yaml index f056c8b..04b2ef6 100644 --- a/platform/ingress/base/cert-manager/clusterissuers/kustomization.yaml +++ b/platform/security/base/kyverno-policies/kustomization.yaml @@ -2,4 +2,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - letsencrypt.yaml \ No newline at end of file + - application.yaml diff --git a/platform/security/base/kyverno/kustomization.yaml b/platform/security/base/kyverno/kustomization.yaml index 872397d..04b2ef6 100644 --- a/platform/security/base/kyverno/kustomization.yaml +++ b/platform/security/base/kyverno/kustomization.yaml @@ -3,4 +3,3 @@ kind: Kustomization resources: - application.yaml - - values-common.yaml diff --git a/platform/security/overlays/dev/kustomization.yaml b/platform/security/overlays/dev/kustomization.yaml index ea0f274..789d4e8 100644 --- a/platform/security/overlays/dev/kustomization.yaml +++ b/platform/security/overlays/dev/kustomization.yaml @@ -4,7 +4,7 @@ kind: Kustomization resources: - ../../base/ - - application-patch.yaml + - security-namespace.yaml patches: - path: application-patch.yaml \ No newline at end of file diff --git a/platform/storage/base/ebs-csi-driver/kustomization.yaml b/platform/storage/base/ebs-csi-driver/kustomization.yaml index e76672a..9f10ec9 100644 --- a/platform/storage/base/ebs-csi-driver/kustomization.yaml +++ b/platform/storage/base/ebs-csi-driver/kustomization.yaml @@ -3,5 +3,4 @@ kind: Kustomization resources: - - values.yaml - application.yaml \ No newline at end of file diff --git a/platform/storage/base/efs-csi-driver/kustomization.yaml b/platform/storage/base/efs-csi-driver/kustomization.yaml index e76672a..9f10ec9 100644 --- a/platform/storage/base/efs-csi-driver/kustomization.yaml +++ b/platform/storage/base/efs-csi-driver/kustomization.yaml @@ -3,5 +3,4 @@ kind: Kustomization resources: - - values.yaml - application.yaml \ No newline at end of file diff --git a/platform/storage/base/velero/kustomization.yaml b/platform/storage/base/velero/kustomization.yaml index e76672a..9f10ec9 100644 --- a/platform/storage/base/velero/kustomization.yaml +++ b/platform/storage/base/velero/kustomization.yaml @@ -3,5 +3,4 @@ kind: Kustomization resources: - - values.yaml - application.yaml \ No newline at end of file diff --git a/platform/tracing/base/opentelemetry-collector/kustomization.yaml b/platform/tracing/base/opentelemetry-collector/kustomization.yaml index 33cf68b..9f10ec9 100644 --- a/platform/tracing/base/opentelemetry-collector/kustomization.yaml +++ b/platform/tracing/base/opentelemetry-collector/kustomization.yaml @@ -3,5 +3,4 @@ kind: Kustomization resources: - - application.yaml - - values-common.yaml \ No newline at end of file + - application.yaml \ No newline at end of file diff --git a/platform/tracing/base/tempo/kustomization.yaml b/platform/tracing/base/tempo/kustomization.yaml index 33cf68b..9f10ec9 100644 --- a/platform/tracing/base/tempo/kustomization.yaml +++ b/platform/tracing/base/tempo/kustomization.yaml @@ -3,5 +3,4 @@ kind: Kustomization resources: - - application.yaml - - values-common.yaml \ No newline at end of file + - application.yaml \ No newline at end of file diff --git a/platform/tracing/overlays/dev/kustomization.yaml b/platform/tracing/overlays/dev/kustomization.yaml index c6ce0a9..682e005 100644 --- a/platform/tracing/overlays/dev/kustomization.yaml +++ b/platform/tracing/overlays/dev/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization namespace: dev resources: - - ../../base \ No newline at end of file + - ../../base + - tracing-namespace.yaml \ No newline at end of file From b30aba733c74999ea233214157328cf9cde03050 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 19:03:27 +0200 Subject: [PATCH 048/122] Updated the image tag --- infrastructure/overlay/dev/ingress.yaml | 2 +- .../overlays/dev/aws-load-balancer-controller-patch.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/infrastructure/overlay/dev/ingress.yaml b/infrastructure/overlay/dev/ingress.yaml index dc8080b..c574cfa 100644 --- a/infrastructure/overlay/dev/ingress.yaml +++ b/infrastructure/overlay/dev/ingress.yaml @@ -11,7 +11,7 @@ metadata: # HTTPS configuration alb.ingress.kubernetes.io/listen-ports: '[{"HTTP":80},{"HTTPS":443}]' - alb.ingress.kubernetes.io/certificate-arn: arn:aws:acm:us-east-1:579871530627:certificate/d0ddcc04-09b5-4ffe-9910-d01b165fdb26 + alb.ingress.kubernetes.io/certificate-arn: arn:aws:acm:us-east-1:579871530627:certificate/19fbd243-97dd-45ab-820a-624c69234df6 # Redirect HTTP to HTTPS alb.ingress.kubernetes.io/ssl-redirect: '443' diff --git a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml index d6da8a7..b16e264 100644 --- a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml +++ b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml @@ -14,7 +14,7 @@ spec: values: | clusterName: eks-dev-cluster region: us-east-1 - vpcId: vpc-0ed36055c1f322ad8 + vpcId: vpc-02b591d77e3006d01 serviceAccount: create: true From fcb10c5469a0be6b70f32cf62f5aaebdb278e3e9 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Thu, 30 Jul 2026 17:15:04 +0000 Subject: [PATCH 049/122] Promote payment-service to e47bd8c91bc39b8693acc38220fbfb86741253c8 --- apps/payment-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/payment-service/overlays/dev/kustomization.yaml b/apps/payment-service/overlays/dev/kustomization.yaml index 925267b..f46f375 100644 --- a/apps/payment-service/overlays/dev/kustomization.yaml +++ b/apps/payment-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service - newTag: 60bd3c6d9e924a7309f3c54b87743ac562d6c6fc + newTag: e47bd8c91bc39b8693acc38220fbfb86741253c8 From 8853b42978f57cf444228fc007763b8e7ac9f45a Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Thu, 30 Jul 2026 17:15:05 +0000 Subject: [PATCH 050/122] Promote order-service to e47bd8c91bc39b8693acc38220fbfb86741253c8 --- apps/order-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/order-service/overlays/dev/kustomization.yaml b/apps/order-service/overlays/dev/kustomization.yaml index 75728ae..2982c39 100644 --- a/apps/order-service/overlays/dev/kustomization.yaml +++ b/apps/order-service/overlays/dev/kustomization.yaml @@ -10,7 +10,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service - newTag: 60bd3c6d9e924a7309f3c54b87743ac562d6c6fc + newTag: e47bd8c91bc39b8693acc38220fbfb86741253c8 replicas: - count: 1 From 6890b8a69be6651ec862adb0c5c4108f821d1d0f Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Thu, 30 Jul 2026 17:15:06 +0000 Subject: [PATCH 051/122] Promote user-service to e47bd8c91bc39b8693acc38220fbfb86741253c8 --- apps/user-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/user-service/overlays/dev/kustomization.yaml b/apps/user-service/overlays/dev/kustomization.yaml index 0c5856d..dd0b5e8 100644 --- a/apps/user-service/overlays/dev/kustomization.yaml +++ b/apps/user-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service - newTag: 60bd3c6d9e924a7309f3c54b87743ac562d6c6fc + newTag: e47bd8c91bc39b8693acc38220fbfb86741253c8 From af942d5312b2977aa951c4187753887bfd356165 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Thu, 30 Jul 2026 17:15:40 +0000 Subject: [PATCH 052/122] Promote product-service to e47bd8c91bc39b8693acc38220fbfb86741253c8 --- apps/product-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/product-service/overlays/dev/kustomization.yaml b/apps/product-service/overlays/dev/kustomization.yaml index fd04cd8..a8c8f39 100644 --- a/apps/product-service/overlays/dev/kustomization.yaml +++ b/apps/product-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service - newTag: 60bd3c6d9e924a7309f3c54b87743ac562d6c6fc + newTag: e47bd8c91bc39b8693acc38220fbfb86741253c8 From 55b6cc7040df839a82c26895cb15a9b567ce8ac1 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 19:20:13 +0200 Subject: [PATCH 053/122] Troubleshooting the observability --- argocd/dev/applicationset-apps.yaml | 3 ++- argocd/dev/applicationset-infra.yaml | 3 ++- argocd/dev/applicationset-monitoring.yaml | 3 ++- argocd/dev/kustomization.yaml | 3 ++- argocd/dev/root-app.yaml | 3 ++- 5 files changed, 10 insertions(+), 5 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 48fbb59..7cd895f 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,4 +36,5 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 1e863c2..3c2e059 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,4 +34,5 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index f92c092..4764ba6 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,4 +32,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 75338bc..9c11cec 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml \ No newline at end of file + - applicationset-monitoring.yaml + \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 92e60e2..da0d76e 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,4 +20,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file From f4b8b40c39a15a95fabd0acacf7cf20f5d620324 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 19:38:27 +0200 Subject: [PATCH 054/122] Troubleshooting the observability --- argocd/dev/applicationset-apps.yaml | 2 +- argocd/dev/applicationset-infra.yaml | 3 +-- argocd/dev/applicationset-monitoring.yaml | 3 +-- argocd/dev/kustomization.yaml | 3 +-- argocd/dev/root-app.yaml | 3 +-- platform/ingress/overlays/dev/kustomization.yaml | 1 - platform/logging/overlays/dev/kustomization.yaml | 3 +-- platform/logging/overlays/dev/logging-namespace.yaml | 5 ----- platform/monitoring/overlays/dev/kustomization.yaml | 1 - platform/monitoring/overlays/dev/monitoring-namespace.yaml | 5 ----- platform/overlays/dev/kustomization.yaml | 3 ++- .../dev/platform-namespace.yaml} | 0 platform/security/overlays/dev/security-namespace.yaml | 5 ----- platform/tracing/overlays/dev/kustomization.yaml | 3 +-- platform/tracing/overlays/dev/tracing-namespace.yaml | 5 ----- 15 files changed, 9 insertions(+), 36 deletions(-) delete mode 100644 platform/logging/overlays/dev/logging-namespace.yaml delete mode 100644 platform/monitoring/overlays/dev/monitoring-namespace.yaml rename platform/{ingress/overlays/dev/ingress-namespace.yaml => overlays/dev/platform-namespace.yaml} (100%) delete mode 100644 platform/security/overlays/dev/security-namespace.yaml delete mode 100644 platform/tracing/overlays/dev/tracing-namespace.yaml diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 7cd895f..21ce9b8 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -37,4 +37,4 @@ spec: syncOptions: - CreateNamespace=true - \ No newline at end of file + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 3c2e059..ed7cb89 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,5 +34,4 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 4764ba6..6974483 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,5 +32,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 9c11cec..75338bc 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,5 +4,4 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml - \ No newline at end of file + - applicationset-monitoring.yaml \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index da0d76e..9e3688f 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,5 +20,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/platform/ingress/overlays/dev/kustomization.yaml b/platform/ingress/overlays/dev/kustomization.yaml index eed3428..b0c25b6 100644 --- a/platform/ingress/overlays/dev/kustomization.yaml +++ b/platform/ingress/overlays/dev/kustomization.yaml @@ -6,7 +6,6 @@ namespace: dev resources: - ../../base - letsencrypt.yaml - - ingress-namespace.yaml patches: - path: external-dns-patch.yaml diff --git a/platform/logging/overlays/dev/kustomization.yaml b/platform/logging/overlays/dev/kustomization.yaml index 0edffb7..c6ce0a9 100644 --- a/platform/logging/overlays/dev/kustomization.yaml +++ b/platform/logging/overlays/dev/kustomization.yaml @@ -4,5 +4,4 @@ kind: Kustomization namespace: dev resources: - - ../../base - - logging-namespace.yaml \ No newline at end of file + - ../../base \ No newline at end of file diff --git a/platform/logging/overlays/dev/logging-namespace.yaml b/platform/logging/overlays/dev/logging-namespace.yaml deleted file mode 100644 index 0b345a8..0000000 --- a/platform/logging/overlays/dev/logging-namespace.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v1 -kind: Namespace - -metadata: - name: dev \ No newline at end of file diff --git a/platform/monitoring/overlays/dev/kustomization.yaml b/platform/monitoring/overlays/dev/kustomization.yaml index 761c9f2..ddf108d 100644 --- a/platform/monitoring/overlays/dev/kustomization.yaml +++ b/platform/monitoring/overlays/dev/kustomization.yaml @@ -5,7 +5,6 @@ namespace: dev resources: - ../../base - - monitoring-namespace.yaml - order/application.yaml - payment/application.yaml - product/application.yaml diff --git a/platform/monitoring/overlays/dev/monitoring-namespace.yaml b/platform/monitoring/overlays/dev/monitoring-namespace.yaml deleted file mode 100644 index 0b345a8..0000000 --- a/platform/monitoring/overlays/dev/monitoring-namespace.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v1 -kind: Namespace - -metadata: - name: dev \ No newline at end of file diff --git a/platform/overlays/dev/kustomization.yaml b/platform/overlays/dev/kustomization.yaml index 85d3916..1d4ed90 100644 --- a/platform/overlays/dev/kustomization.yaml +++ b/platform/overlays/dev/kustomization.yaml @@ -8,4 +8,5 @@ resources: - ../../networking/overlays/dev - ../../security/overlays/dev - ../../tracing/overlays/dev - - ../../storage/overlays/dev \ No newline at end of file + - ../../storage/overlays/dev + - platform-namespace.yaml \ No newline at end of file diff --git a/platform/ingress/overlays/dev/ingress-namespace.yaml b/platform/overlays/dev/platform-namespace.yaml similarity index 100% rename from platform/ingress/overlays/dev/ingress-namespace.yaml rename to platform/overlays/dev/platform-namespace.yaml diff --git a/platform/security/overlays/dev/security-namespace.yaml b/platform/security/overlays/dev/security-namespace.yaml deleted file mode 100644 index 0b345a8..0000000 --- a/platform/security/overlays/dev/security-namespace.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v1 -kind: Namespace - -metadata: - name: dev \ No newline at end of file diff --git a/platform/tracing/overlays/dev/kustomization.yaml b/platform/tracing/overlays/dev/kustomization.yaml index 682e005..c6ce0a9 100644 --- a/platform/tracing/overlays/dev/kustomization.yaml +++ b/platform/tracing/overlays/dev/kustomization.yaml @@ -4,5 +4,4 @@ kind: Kustomization namespace: dev resources: - - ../../base - - tracing-namespace.yaml \ No newline at end of file + - ../../base \ No newline at end of file diff --git a/platform/tracing/overlays/dev/tracing-namespace.yaml b/platform/tracing/overlays/dev/tracing-namespace.yaml deleted file mode 100644 index 0b345a8..0000000 --- a/platform/tracing/overlays/dev/tracing-namespace.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v1 -kind: Namespace - -metadata: - name: dev \ No newline at end of file From fd975e5b69f5728ec514442ea989435e83445738 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 19:52:01 +0200 Subject: [PATCH 055/122] Troubleshooting the observability --- argocd/dev/applicationset-apps.yaml | 1 - argocd/dev/applicationset-infra.yaml | 3 ++- argocd/dev/applicationset-monitoring.yaml | 3 ++- argocd/dev/kustomization.yaml | 3 ++- argocd/dev/root-app.yaml | 3 ++- .../kube-prometheus-stack/alertmanager/kustomization.yaml | 5 +++++ 6 files changed, 13 insertions(+), 5 deletions(-) create mode 100644 platform/monitoring/base/kube-prometheus-stack/alertmanager/kustomization.yaml diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 21ce9b8..1c9e72f 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -37,4 +37,3 @@ spec: syncOptions: - CreateNamespace=true - \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index ed7cb89..dd92b7a 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,4 +34,5 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 6974483..3f6bc34 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,4 +32,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 75338bc..9c11cec 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml \ No newline at end of file + - applicationset-monitoring.yaml + \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 9e3688f..834d057 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,4 +20,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/alertmanager/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/alertmanager/kustomization.yaml new file mode 100644 index 0000000..f176a6a --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/alertmanager/kustomization.yaml @@ -0,0 +1,5 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - external-secret.yaml \ No newline at end of file From 94f1f74b69bc1dd3635f9791f0c6620a3eac868a Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 19:58:07 +0200 Subject: [PATCH 056/122] Troubleshooting the observability --- argocd/dev/applicationset-apps.yaml | 2 +- argocd/dev/applicationset-infra.yaml | 3 +-- argocd/dev/applicationset-monitoring.yaml | 3 +-- argocd/dev/kustomization.yaml | 3 +-- argocd/dev/root-app.yaml | 3 +-- .../kube-prometheus-stack/blackbox-exporter/kustomization.yaml | 3 +-- .../kube-prometheus-stack/postgres-exporter/kustomization.yaml | 3 +-- .../kube-prometheus-stack/redis-exporter/kustomization.yaml | 3 +-- 8 files changed, 8 insertions(+), 15 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 1c9e72f..33dade8 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,4 +36,4 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index dd92b7a..5ff42ba 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,5 +34,4 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 3f6bc34..cb15c92 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,5 +32,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 9c11cec..75338bc 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,5 +4,4 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml - \ No newline at end of file + - applicationset-monitoring.yaml \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 834d057..3bbbce0 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,5 +20,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/blackbox-exporter/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/blackbox-exporter/kustomization.yaml index 2322e3f..dcbd3b7 100644 --- a/platform/monitoring/base/kube-prometheus-stack/blackbox-exporter/kustomization.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/blackbox-exporter/kustomization.yaml @@ -2,5 +2,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - application.yaml - - values-common.yaml \ No newline at end of file + - application.yaml \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/postgres-exporter/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/postgres-exporter/kustomization.yaml index 2322e3f..dcbd3b7 100644 --- a/platform/monitoring/base/kube-prometheus-stack/postgres-exporter/kustomization.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/postgres-exporter/kustomization.yaml @@ -2,5 +2,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - application.yaml - - values-common.yaml \ No newline at end of file + - application.yaml \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/redis-exporter/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/redis-exporter/kustomization.yaml index 2322e3f..dcbd3b7 100644 --- a/platform/monitoring/base/kube-prometheus-stack/redis-exporter/kustomization.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/redis-exporter/kustomization.yaml @@ -2,5 +2,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - application.yaml - - values-common.yaml \ No newline at end of file + - application.yaml \ No newline at end of file From 4d1170f4a5fc9860240d97e738c6dbb7036288c7 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 20:07:20 +0200 Subject: [PATCH 057/122] Troubleshooting the observability --- argocd/dev/applicationset-apps.yaml | 3 ++- argocd/dev/applicationset-infra.yaml | 3 ++- argocd/dev/applicationset-monitoring.yaml | 3 ++- argocd/dev/kustomization.yaml | 3 ++- argocd/dev/root-app.yaml | 3 ++- .../grafana/dashboards/kustomization.yaml | 4 ++++ .../grafana/datasources/kustomization.yaml | 4 ++++ .../grafana/kustomization.yaml | 7 +++++++ .../grafana/networkpolicy.yaml | 21 +++++++++++++++++++ 9 files changed, 46 insertions(+), 5 deletions(-) create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/kustomization.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/datasources/kustomization.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/kustomization.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/networkpolicy.yaml diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 33dade8..dc7c2d3 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,4 +36,5 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 5ff42ba..7623978 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,4 +34,5 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index cb15c92..b747637 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,4 +32,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 75338bc..9c11cec 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml \ No newline at end of file + - applicationset-monitoring.yaml + \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 3bbbce0..2de90d3 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,4 +20,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/kustomization.yaml new file mode 100644 index 0000000..b1745d7 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/kustomization.yaml @@ -0,0 +1,4 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: [] \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/datasources/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/grafana/datasources/kustomization.yaml new file mode 100644 index 0000000..b1745d7 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/grafana/datasources/kustomization.yaml @@ -0,0 +1,4 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: [] \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/grafana/kustomization.yaml new file mode 100644 index 0000000..4a56067 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/grafana/kustomization.yaml @@ -0,0 +1,7 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - networkpolicy.yaml + - dashboards + - datasources \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/networkpolicy.yaml b/platform/monitoring/base/kube-prometheus-stack/grafana/networkpolicy.yaml new file mode 100644 index 0000000..d426e60 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/grafana/networkpolicy.yaml @@ -0,0 +1,21 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy + +metadata: + name: grafana + +spec: + podSelector: + matchLabels: + app.kubernetes.io/name: grafana + + policyTypes: + - Ingress + + ingress: + - from: + - namespaceSelector: {} + + ports: + - protocol: TCP + port: 3000 \ No newline at end of file From 1d97cc80ce7829c5d1ac21fda0d0befc932b10d2 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 20:14:23 +0200 Subject: [PATCH 058/122] Troubleshooting the observability --- argocd/dev/applicationset-apps.yaml | 3 +-- argocd/dev/applicationset-infra.yaml | 3 +-- argocd/dev/applicationset-monitoring.yaml | 3 +-- argocd/dev/kustomization.yaml | 3 +-- argocd/dev/root-app.yaml | 3 +-- .../monitoring/base/kube-prometheus-stack/kustomization.yaml | 2 +- 6 files changed, 6 insertions(+), 11 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index dc7c2d3..600ebf1 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,5 +36,4 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 7623978..05983d5 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,5 +34,4 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index b747637..a035051 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,5 +32,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 9c11cec..c13e6f0 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,5 +4,4 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml - \ No newline at end of file + - applicationset-monitoring.yaml \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 2de90d3..76495e1 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,5 +20,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml index 8385400..b339eb1 100644 --- a/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml @@ -11,7 +11,7 @@ resources: - recording-rules/ - redis-exporter/ - servicemonitors/ - - application.yaml + - application.yaml - external-secret.yaml - values-common.yaml \ No newline at end of file From bc891fb1dfdc0e16a64b108adb54666fc5b8b1f9 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 20:23:16 +0200 Subject: [PATCH 059/122] Troubleshooting the observability --- argocd/dev/applicationset-apps.yaml | 3 ++- argocd/dev/applicationset-infra.yaml | 3 ++- argocd/dev/applicationset-monitoring.yaml | 3 ++- argocd/dev/kustomization.yaml | 3 ++- argocd/dev/root-app.yaml | 3 ++- .../kube-prometheus-stack/kustomization.yaml | 1 - .../overlays/dev/kustomization.yaml | 1 - .../monitoring/overlays/dev/values-dev.yaml | 20 ------------------- 8 files changed, 10 insertions(+), 27 deletions(-) delete mode 100644 platform/monitoring/overlays/dev/values-dev.yaml diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 600ebf1..034b031 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,4 +36,5 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 05983d5..e4523c8 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,4 +34,5 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index a035051..cefced0 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,4 +32,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index c13e6f0..b6bb9ed 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml \ No newline at end of file + - applicationset-monitoring.yaml + \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 76495e1..f39e934 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,4 +20,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml index b339eb1..91db6fd 100644 --- a/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/kustomization.yaml @@ -13,5 +13,4 @@ resources: - servicemonitors/ - application.yaml - external-secret.yaml - - values-common.yaml \ No newline at end of file diff --git a/platform/monitoring/overlays/dev/kustomization.yaml b/platform/monitoring/overlays/dev/kustomization.yaml index ddf108d..cc71c7a 100644 --- a/platform/monitoring/overlays/dev/kustomization.yaml +++ b/platform/monitoring/overlays/dev/kustomization.yaml @@ -9,7 +9,6 @@ resources: - payment/application.yaml - product/application.yaml - user/application.yaml - - values-dev.yaml patches: diff --git a/platform/monitoring/overlays/dev/values-dev.yaml b/platform/monitoring/overlays/dev/values-dev.yaml deleted file mode 100644 index c891953..0000000 --- a/platform/monitoring/overlays/dev/values-dev.yaml +++ /dev/null @@ -1,20 +0,0 @@ -grafana: - persistence: - storageClassName: gp3 - size: 20Gi - -prometheus: - prometheusSpec: - retention: 30d - - storageSpec: - volumeClaimTemplate: - spec: - storageClassName: gp3 - -alertmanager: - alertmanagerSpec: - storage: - volumeClaimTemplate: - spec: - storageClassName: gp3 \ No newline at end of file From 09a7c653dc6d959995f1a2ea6418b6f2c2275be4 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Thu, 30 Jul 2026 20:33:25 +0200 Subject: [PATCH 060/122] Troubleshooting the observability --- argocd/dev/applicationset-apps.yaml | 3 +-- argocd/dev/applicationset-infra.yaml | 3 +-- argocd/dev/applicationset-monitoring.yaml | 3 +-- argocd/dev/kustomization.yaml | 3 +-- argocd/dev/root-app.yaml | 3 +-- platform/monitoring/overlays/dev/order/application.yaml | 2 +- platform/monitoring/overlays/dev/payment/application.yaml | 4 ++-- platform/monitoring/overlays/dev/user/application.yaml | 4 ++-- 8 files changed, 10 insertions(+), 15 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 034b031..d96dd17 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,5 +36,4 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index e4523c8..67c7754 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,5 +34,4 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index cefced0..cca6f2c 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,5 +32,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index b6bb9ed..ad82c3b 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,5 +4,4 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml - \ No newline at end of file + - applicationset-monitoring.yaml \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index f39e934..165c45f 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,5 +20,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/platform/monitoring/overlays/dev/order/application.yaml b/platform/monitoring/overlays/dev/order/application.yaml index 3534ad8..3fff134 100644 --- a/platform/monitoring/overlays/dev/order/application.yaml +++ b/platform/monitoring/overlays/dev/order/application.yaml @@ -2,7 +2,7 @@ apiVersion: argoproj.io/v1alpha1 kind: Application metadata: - name: product-postgres-exporter + name: order-postgres-exporter namespace: argocd spec: diff --git a/platform/monitoring/overlays/dev/payment/application.yaml b/platform/monitoring/overlays/dev/payment/application.yaml index 2309911..61ef22a 100644 --- a/platform/monitoring/overlays/dev/payment/application.yaml +++ b/platform/monitoring/overlays/dev/payment/application.yaml @@ -2,7 +2,7 @@ apiVersion: argoproj.io/v1alpha1 kind: Application metadata: - name: product-postgres-exporter + name: payment-postgres-exporter namespace: argocd spec: @@ -20,7 +20,7 @@ spec: config: datasource: - host: order-postgres.dev.svc.cluster.local + host: payment-postgres.dev.svc.cluster.local port: "5432" database: paymentdb diff --git a/platform/monitoring/overlays/dev/user/application.yaml b/platform/monitoring/overlays/dev/user/application.yaml index a2d13cd..3006ed6 100644 --- a/platform/monitoring/overlays/dev/user/application.yaml +++ b/platform/monitoring/overlays/dev/user/application.yaml @@ -2,7 +2,7 @@ apiVersion: argoproj.io/v1alpha1 kind: Application metadata: - name: product-postgres-exporter + name: user-postgres-exporter namespace: argocd spec: @@ -20,7 +20,7 @@ spec: config: datasource: - host: order-postgres.dev.svc.cluster.local + host: user-postgres.dev.svc.cluster.local port: "5432" database: userdb From d2b34542e0b4292a92ef5f7bcf757d81e23c6829 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Fri, 31 Jul 2026 11:53:30 +0200 Subject: [PATCH 061/122] Updated the vpc ans acm arn --- infrastructure/overlay/dev/ingress.yaml | 2 +- .../aws-load-balancer-controller-patch.yaml | 2 +- .../grafana/dashboards/README.md | 17 ---------------- .../dev/kube-prometheus-stack-patch.yaml | 1 + .../monitoring/overlays/dev/values-dev.yaml | 20 +++++++++++++++++++ 5 files changed, 23 insertions(+), 19 deletions(-) delete mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/README.md create mode 100644 platform/monitoring/overlays/dev/values-dev.yaml diff --git a/infrastructure/overlay/dev/ingress.yaml b/infrastructure/overlay/dev/ingress.yaml index c574cfa..54b0e43 100644 --- a/infrastructure/overlay/dev/ingress.yaml +++ b/infrastructure/overlay/dev/ingress.yaml @@ -11,7 +11,7 @@ metadata: # HTTPS configuration alb.ingress.kubernetes.io/listen-ports: '[{"HTTP":80},{"HTTPS":443}]' - alb.ingress.kubernetes.io/certificate-arn: arn:aws:acm:us-east-1:579871530627:certificate/19fbd243-97dd-45ab-820a-624c69234df6 + alb.ingress.kubernetes.io/certificate-arn: arn:aws:acm:us-east-1:579871530627:certificate/dd52e2cd-1df9-461f-b02a-15cc953f5b8d # Redirect HTTP to HTTPS alb.ingress.kubernetes.io/ssl-redirect: '443' diff --git a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml index b16e264..5293ce7 100644 --- a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml +++ b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml @@ -14,7 +14,7 @@ spec: values: | clusterName: eks-dev-cluster region: us-east-1 - vpcId: vpc-02b591d77e3006d01 + vpcId: vpc-004244308de39a801 serviceAccount: create: true diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/README.md b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/README.md deleted file mode 100644 index 1539e2c..0000000 --- a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/README.md +++ /dev/null @@ -1,17 +0,0 @@ -# Grafana Dashboards - -This directory contains custom Grafana dashboards provisioned through -the kube-prometheus-stack Grafana sidecar. - -## Dashboards - -- kubernetes.json -- nodes.json -- ingress-nginx.json -- springboot.json -- jvm.json -- postgres.json -- redis.json - -Each dashboard is packaged into a ConfigMap by Kustomize and -automatically imported into Grafana. \ No newline at end of file diff --git a/platform/monitoring/overlays/dev/kube-prometheus-stack-patch.yaml b/platform/monitoring/overlays/dev/kube-prometheus-stack-patch.yaml index dd78a65..f035646 100644 --- a/platform/monitoring/overlays/dev/kube-prometheus-stack-patch.yaml +++ b/platform/monitoring/overlays/dev/kube-prometheus-stack-patch.yaml @@ -3,6 +3,7 @@ kind: Application metadata: name: kube-prometheus-stack + namespace: argocd spec: source: diff --git a/platform/monitoring/overlays/dev/values-dev.yaml b/platform/monitoring/overlays/dev/values-dev.yaml new file mode 100644 index 0000000..c891953 --- /dev/null +++ b/platform/monitoring/overlays/dev/values-dev.yaml @@ -0,0 +1,20 @@ +grafana: + persistence: + storageClassName: gp3 + size: 20Gi + +prometheus: + prometheusSpec: + retention: 30d + + storageSpec: + volumeClaimTemplate: + spec: + storageClassName: gp3 + +alertmanager: + alertmanagerSpec: + storage: + volumeClaimTemplate: + spec: + storageClassName: gp3 \ No newline at end of file From feb14de74337c44613e850990be2be10ee4d3de0 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Fri, 31 Jul 2026 10:02:48 +0000 Subject: [PATCH 062/122] Promote order-service to 7cb4e11b6a5c1ed06f957e4dcf0ab12adb771f9e --- apps/order-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/order-service/overlays/dev/kustomization.yaml b/apps/order-service/overlays/dev/kustomization.yaml index 2982c39..9fba4ad 100644 --- a/apps/order-service/overlays/dev/kustomization.yaml +++ b/apps/order-service/overlays/dev/kustomization.yaml @@ -10,7 +10,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service - newTag: e47bd8c91bc39b8693acc38220fbfb86741253c8 + newTag: 7cb4e11b6a5c1ed06f957e4dcf0ab12adb771f9e replicas: - count: 1 From 1f670f68a81eda1a7af73d2a7fd0892be2ec4114 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Fri, 31 Jul 2026 10:02:50 +0000 Subject: [PATCH 063/122] Promote payment-service to 7cb4e11b6a5c1ed06f957e4dcf0ab12adb771f9e --- apps/payment-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/payment-service/overlays/dev/kustomization.yaml b/apps/payment-service/overlays/dev/kustomization.yaml index f46f375..5004cde 100644 --- a/apps/payment-service/overlays/dev/kustomization.yaml +++ b/apps/payment-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service - newTag: e47bd8c91bc39b8693acc38220fbfb86741253c8 + newTag: 7cb4e11b6a5c1ed06f957e4dcf0ab12adb771f9e From d9ffeb741df108f639e12cd6481602543b58f8ef Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Fri, 31 Jul 2026 10:03:12 +0000 Subject: [PATCH 064/122] Promote product-service to 7cb4e11b6a5c1ed06f957e4dcf0ab12adb771f9e --- apps/product-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/product-service/overlays/dev/kustomization.yaml b/apps/product-service/overlays/dev/kustomization.yaml index a8c8f39..ed2d461 100644 --- a/apps/product-service/overlays/dev/kustomization.yaml +++ b/apps/product-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service - newTag: e47bd8c91bc39b8693acc38220fbfb86741253c8 + newTag: 7cb4e11b6a5c1ed06f957e4dcf0ab12adb771f9e From 796a9690d55f825f60483b57aab12afe1846e8bb Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Fri, 31 Jul 2026 10:03:41 +0000 Subject: [PATCH 065/122] Promote user-service to 7cb4e11b6a5c1ed06f957e4dcf0ab12adb771f9e --- apps/user-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/user-service/overlays/dev/kustomization.yaml b/apps/user-service/overlays/dev/kustomization.yaml index dd0b5e8..df83f9d 100644 --- a/apps/user-service/overlays/dev/kustomization.yaml +++ b/apps/user-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service - newTag: e47bd8c91bc39b8693acc38220fbfb86741253c8 + newTag: 7cb4e11b6a5c1ed06f957e4dcf0ab12adb771f9e From fe8d0458416a4679aa79460925e0233b7349df28 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Fri, 31 Jul 2026 12:08:13 +0200 Subject: [PATCH 066/122] recreate the root app --- argocd/dev/applicationset-apps.yaml | 3 ++- argocd/dev/applicationset-infra.yaml | 3 ++- argocd/dev/applicationset-monitoring.yaml | 3 ++- argocd/dev/kustomization.yaml | 3 ++- argocd/dev/root-app.yaml | 3 ++- 5 files changed, 10 insertions(+), 5 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index d96dd17..24da842 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,4 +36,5 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 67c7754..cc48ce8 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,4 +34,5 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index cca6f2c..8a250fc 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,4 +32,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index ad82c3b..a211cfe 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml \ No newline at end of file + - applicationset-monitoring.yaml + \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 165c45f..2bb6cd3 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,4 +20,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file From c4ba189560535f6345066131c47cddd2128bc0f8 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Fri, 31 Jul 2026 12:27:46 +0200 Subject: [PATCH 067/122] recreate the root app --- argocd/dev/applicationset-apps.yaml | 3 +-- argocd/dev/applicationset-infra.yaml | 3 +-- argocd/dev/applicationset-monitoring.yaml | 3 +-- argocd/dev/kustomization.yaml | 3 +-- argocd/dev/root-app.yaml | 3 +-- platform/monitoring/overlays/dev/postgres-exporter-patch.yaml | 1 + 6 files changed, 6 insertions(+), 10 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 24da842..23aab3b 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,5 +36,4 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index cc48ce8..15bb579 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,5 +34,4 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 8a250fc..174892c 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,5 +32,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index a211cfe..7c3c8e7 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,5 +4,4 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml - \ No newline at end of file + - applicationset-monitoring.yaml \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 2bb6cd3..e34fa7b 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,5 +20,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/platform/monitoring/overlays/dev/postgres-exporter-patch.yaml b/platform/monitoring/overlays/dev/postgres-exporter-patch.yaml index 9c836d4..12b53a3 100644 --- a/platform/monitoring/overlays/dev/postgres-exporter-patch.yaml +++ b/platform/monitoring/overlays/dev/postgres-exporter-patch.yaml @@ -3,6 +3,7 @@ kind: Application metadata: name: postgres-exporter + namespace: argocd spec: source: From 926f153a9dd4fdd835ada6c38f5e8dc049f4516c Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Fri, 31 Jul 2026 12:56:33 +0200 Subject: [PATCH 068/122] Fixed patch errors --- argocd/dev/applicationset-apps.yaml | 3 ++- argocd/dev/applicationset-infra.yaml | 3 ++- argocd/dev/applicationset-monitoring.yaml | 3 ++- argocd/dev/kustomization.yaml | 3 ++- argocd/dev/root-app.yaml | 3 ++- .../networking/overlays/dev/application-patch.yaml | 3 ++- .../security/overlays/dev/application-patch.yaml | 3 ++- platform/storage/base/backup/kustomization.yaml | 13 ++++--------- platform/storage/base/backup/schedules.yaml | 14 ++++++++++++++ .../overlays/dev/backup-schedule-patch.yaml | 1 + .../dev/ebs-csi-driver-application-patch.yaml | 3 ++- platform/storage/overlays/dev/kustomization.yaml | 1 - .../overlays/dev/velero-application-patch.yaml | 0 13 files changed, 35 insertions(+), 18 deletions(-) delete mode 100644 platform/storage/overlays/dev/velero-application-patch.yaml diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 23aab3b..e799628 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,4 +36,5 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 15bb579..1f3e71e 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,4 +34,5 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 174892c..7b1a5be 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,4 +32,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 7c3c8e7..0845a24 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml \ No newline at end of file + - applicationset-monitoring.yaml + \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index e34fa7b..dea5c81 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,4 +20,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/platform/networking/overlays/dev/application-patch.yaml b/platform/networking/overlays/dev/application-patch.yaml index 9d8d485..5ba522f 100644 --- a/platform/networking/overlays/dev/application-patch.yaml +++ b/platform/networking/overlays/dev/application-patch.yaml @@ -2,4 +2,5 @@ apiVersion: argoproj.io/v1alpha1 kind: Application metadata: - name: metrics-server \ No newline at end of file + name: metrics-server + namespace: argocd \ No newline at end of file diff --git a/platform/security/overlays/dev/application-patch.yaml b/platform/security/overlays/dev/application-patch.yaml index 82c5339..25880c1 100644 --- a/platform/security/overlays/dev/application-patch.yaml +++ b/platform/security/overlays/dev/application-patch.yaml @@ -2,4 +2,5 @@ apiVersion: argoproj.io/v1alpha1 kind: Application metadata: - name: kyverno \ No newline at end of file + name: kyverno + namespace: argocd \ No newline at end of file diff --git a/platform/storage/base/backup/kustomization.yaml b/platform/storage/base/backup/kustomization.yaml index b0f003a..2f7ed70 100644 --- a/platform/storage/base/backup/kustomization.yaml +++ b/platform/storage/base/backup/kustomization.yaml @@ -1,11 +1,6 @@ -apiVersion: velero.io/v1 -kind: Schedule +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization -metadata: - name: daily-backup -spec: - schedule: "0 2 * * *" - - template: - ttl: 168h \ No newline at end of file +resources: + - schedules.yaml \ No newline at end of file diff --git a/platform/storage/base/backup/schedules.yaml b/platform/storage/base/backup/schedules.yaml index e69de29..67c6f00 100644 --- a/platform/storage/base/backup/schedules.yaml +++ b/platform/storage/base/backup/schedules.yaml @@ -0,0 +1,14 @@ +apiVersion: velero.io/v1 +kind: Schedule + +metadata: + name: daily-backup + namespace: argocd + +spec: + schedule: "0 2 * * *" + + template: + ttl: 168h + includedNamespaces: + - default \ No newline at end of file diff --git a/platform/storage/overlays/dev/backup-schedule-patch.yaml b/platform/storage/overlays/dev/backup-schedule-patch.yaml index 08d3647..7f42976 100644 --- a/platform/storage/overlays/dev/backup-schedule-patch.yaml +++ b/platform/storage/overlays/dev/backup-schedule-patch.yaml @@ -3,6 +3,7 @@ kind: Schedule metadata: name: daily-backup + namespace: argocd spec: template: diff --git a/platform/storage/overlays/dev/ebs-csi-driver-application-patch.yaml b/platform/storage/overlays/dev/ebs-csi-driver-application-patch.yaml index 1e4a640..2b4a216 100644 --- a/platform/storage/overlays/dev/ebs-csi-driver-application-patch.yaml +++ b/platform/storage/overlays/dev/ebs-csi-driver-application-patch.yaml @@ -2,4 +2,5 @@ apiVersion: argoproj.io/v1alpha1 kind: Application metadata: - name: ebs-csi-driver \ No newline at end of file + name: ebs-csi-driver + namespace: argocd \ No newline at end of file diff --git a/platform/storage/overlays/dev/kustomization.yaml b/platform/storage/overlays/dev/kustomization.yaml index 7417143..1e705e3 100644 --- a/platform/storage/overlays/dev/kustomization.yaml +++ b/platform/storage/overlays/dev/kustomization.yaml @@ -7,5 +7,4 @@ resources: patches: - path: ebs-csi-driver-application-patch.yaml - - path: velero-application-patch.yaml - path: backup-schedule-patch.yaml \ No newline at end of file diff --git a/platform/storage/overlays/dev/velero-application-patch.yaml b/platform/storage/overlays/dev/velero-application-patch.yaml deleted file mode 100644 index e69de29..0000000 From fe1f0267c741f2f300b3cc2e5266451215e8d412 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Fri, 31 Jul 2026 13:01:36 +0200 Subject: [PATCH 069/122] Fixed patch errors --- argocd/dev/applicationset-apps.yaml | 3 +-- argocd/dev/applicationset-infra.yaml | 3 +-- argocd/dev/applicationset-monitoring.yaml | 3 +-- argocd/dev/kustomization.yaml | 3 +-- argocd/dev/root-app.yaml | 3 +-- platform/security/overlays/dev/kustomization.yaml | 1 - 6 files changed, 5 insertions(+), 11 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index e799628..b778315 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,5 +36,4 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 1f3e71e..ecf7596 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,5 +34,4 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 7b1a5be..591aa03 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,5 +32,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 0845a24..58c4c33 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,5 +4,4 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml - \ No newline at end of file + - applicationset-monitoring.yaml \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index dea5c81..296f3c1 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,5 +20,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/platform/security/overlays/dev/kustomization.yaml b/platform/security/overlays/dev/kustomization.yaml index 789d4e8..306e06d 100644 --- a/platform/security/overlays/dev/kustomization.yaml +++ b/platform/security/overlays/dev/kustomization.yaml @@ -4,7 +4,6 @@ kind: Kustomization resources: - ../../base/ - - security-namespace.yaml patches: - path: application-patch.yaml \ No newline at end of file From de8418fd264027db11d1af61432b70b73b05376e Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Fri, 31 Jul 2026 13:11:16 +0200 Subject: [PATCH 070/122] Fixed patch errors --- argocd/dev/applicationset-apps.yaml | 3 ++- argocd/dev/applicationset-infra.yaml | 3 ++- argocd/dev/applicationset-monitoring.yaml | 3 ++- argocd/dev/kustomization.yaml | 3 ++- argocd/dev/root-app.yaml | 3 ++- platform/tracing/base/kustomization.yaml | 1 - 6 files changed, 10 insertions(+), 6 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index b778315..482710a 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,4 +36,5 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index ecf7596..9f2b2f3 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,4 +34,5 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 591aa03..afea90f 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,4 +32,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 58c4c33..883a598 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml \ No newline at end of file + - applicationset-monitoring.yaml + \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 296f3c1..8600d7b 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,4 +20,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/platform/tracing/base/kustomization.yaml b/platform/tracing/base/kustomization.yaml index 4a8f26d..8a071e3 100644 --- a/platform/tracing/base/kustomization.yaml +++ b/platform/tracing/base/kustomization.yaml @@ -2,7 +2,6 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - tracing-namespace.yaml - tempo/ - opentelemetry-collector/ - networkpolicy/ \ No newline at end of file From f6eea8bf1d48a1cf203ea2d8501f8907ca94b9c9 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Fri, 31 Jul 2026 13:19:08 +0200 Subject: [PATCH 071/122] Fixed patch errors --- argocd/dev/applicationset-apps.yaml | 3 +-- argocd/dev/applicationset-infra.yaml | 3 +-- argocd/dev/applicationset-monitoring.yaml | 3 +-- argocd/dev/kustomization.yaml | 3 +-- argocd/dev/root-app.yaml | 3 +-- platform/storage/base/kustomization.yaml | 10 ++++++++++ 6 files changed, 15 insertions(+), 10 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 482710a..7f57dac 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,5 +36,4 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 9f2b2f3..541c770 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,5 +34,4 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index afea90f..254f3ac 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,5 +32,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 883a598..19f481f 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,5 +4,4 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml - \ No newline at end of file + - applicationset-monitoring.yaml \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 8600d7b..df9260c 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,5 +20,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/platform/storage/base/kustomization.yaml b/platform/storage/base/kustomization.yaml index e69de29..cd001cd 100644 --- a/platform/storage/base/kustomization.yaml +++ b/platform/storage/base/kustomization.yaml @@ -0,0 +1,10 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - backup/ + - ebs-csi-driver/ + - efs-csi-driver/ + - snapshots/ + - storageclasses/ + - velero/ \ No newline at end of file From 23d828752f6531e3591ad789bcdd91f82257c251 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Fri, 31 Jul 2026 14:38:57 +0200 Subject: [PATCH 072/122] Added wave sync --- platform/ingress/base/cert-manager/cert-manager.yaml | 2 ++ platform/ingress/overlays/dev/letsencrypt.yaml | 2 ++ .../monitoring/base/kube-prometheus-stack/application.yaml | 3 ++- .../kube-prometheus-stack/prometheusrules/applications.yaml | 3 +++ .../base/kube-prometheus-stack/servicemonitors/order.yaml | 2 ++ .../base/kube-prometheus-stack/servicemonitors/payment.yaml | 4 +++- .../base/kube-prometheus-stack/servicemonitors/product.yaml | 2 ++ .../base/kube-prometheus-stack/servicemonitors/redis.yaml | 2 ++ .../base/kube-prometheus-stack/servicemonitors/user.yaml | 2 ++ platform/networking/base/metrics-server/application.yaml | 2 ++ platform/security/base/kyverno/application.yaml | 2 ++ platform/security/base/policies/disallow-hostpath.yaml | 2 ++ platform/security/base/policies/disallow-latest-tag.yaml | 2 ++ platform/security/base/policies/disallow-privileged.yaml | 2 ++ platform/security/base/policies/policy-exception.yaml | 3 ++- platform/security/base/policies/require-labels.yaml | 3 ++- platform/security/base/policies/require-limits.yaml | 4 +++- platform/security/base/policies/require-networkpolicy.yaml | 4 +++- platform/security/base/policies/require-non-root.yaml | 4 +++- platform/security/base/policies/require-pdb.yaml | 4 +++- platform/security/base/policies/require-probes.yaml | 4 +++- platform/security/base/policies/require-readonly-rootfs.yaml | 4 +++- platform/storage/base/backup/schedules.yaml | 2 ++ platform/storage/base/velero/application.yaml | 2 ++ 24 files changed, 56 insertions(+), 10 deletions(-) diff --git a/platform/ingress/base/cert-manager/cert-manager.yaml b/platform/ingress/base/cert-manager/cert-manager.yaml index 4370273..a71ce42 100644 --- a/platform/ingress/base/cert-manager/cert-manager.yaml +++ b/platform/ingress/base/cert-manager/cert-manager.yaml @@ -4,6 +4,8 @@ kind: Application metadata: name: cert-manager namespace: argocd + annotations: + argocd.argoproj.io/sync-wave: "-2" spec: project: default diff --git a/platform/ingress/overlays/dev/letsencrypt.yaml b/platform/ingress/overlays/dev/letsencrypt.yaml index 668023b..f244dd8 100644 --- a/platform/ingress/overlays/dev/letsencrypt.yaml +++ b/platform/ingress/overlays/dev/letsencrypt.yaml @@ -3,6 +3,8 @@ kind: ClusterIssuer metadata: name: letsencrypt + annotations: + argocd.argoproj.io/sync-wave: "0" spec: acme: diff --git a/platform/monitoring/base/kube-prometheus-stack/application.yaml b/platform/monitoring/base/kube-prometheus-stack/application.yaml index f7876ca..c9ac5aa 100644 --- a/platform/monitoring/base/kube-prometheus-stack/application.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/application.yaml @@ -4,7 +4,8 @@ kind: Application metadata: name: kube-prometheus-stack namespace: argocd - + annotations: + argocd.argoproj.io/sync-wave: "-2" spec: project: default diff --git a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/applications.yaml b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/applications.yaml index 2b7b4cf..17b0f96 100644 --- a/platform/monitoring/base/kube-prometheus-stack/prometheusrules/applications.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/prometheusrules/applications.yaml @@ -3,6 +3,9 @@ kind: PrometheusRule metadata: name: application-alerts + namespace: argocd + annotations: + argocd.argoproj.io/sync-wave: "0" labels: prometheus: kube-prometheus diff --git a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/order.yaml b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/order.yaml index 00dfd2b..825b3b5 100644 --- a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/order.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/order.yaml @@ -3,6 +3,8 @@ kind: ServiceMonitor metadata: name: order-service + annotations: + argocd.argoproj.io/sync-wave: "0" labels: prometheus: kube-prometheus diff --git a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/payment.yaml b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/payment.yaml index c779c08..74f7c14 100644 --- a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/payment.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/payment.yaml @@ -3,7 +3,9 @@ kind: ServiceMonitor metadata: name: payment-service - + annotations: + argocd.argoproj.io/sync-wave: "0" + labels: prometheus: kube-prometheus diff --git a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/product.yaml b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/product.yaml index 57369e5..ca8483d 100644 --- a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/product.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/product.yaml @@ -3,6 +3,8 @@ kind: ServiceMonitor metadata: name: product-service + annotations: + argocd.argoproj.io/sync-wave: "0" labels: prometheus: kube-prometheus diff --git a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/redis.yaml b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/redis.yaml index 2e02e0e..364f368 100644 --- a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/redis.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/redis.yaml @@ -3,6 +3,8 @@ kind: ServiceMonitor metadata: name: redis + annotations: + argocd.argoproj.io/sync-wave: "0" labels: prometheus: kube-prometheus diff --git a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/user.yaml b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/user.yaml index 63b3906..c642dbe 100644 --- a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/user.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/user.yaml @@ -3,6 +3,8 @@ kind: ServiceMonitor metadata: name: user-service + annotations: + argocd.argoproj.io/sync-wave: "0" labels: prometheus: kube-prometheus diff --git a/platform/networking/base/metrics-server/application.yaml b/platform/networking/base/metrics-server/application.yaml index dedbedc..4e80b43 100644 --- a/platform/networking/base/metrics-server/application.yaml +++ b/platform/networking/base/metrics-server/application.yaml @@ -4,6 +4,8 @@ kind: Application metadata: name: metrics-server namespace: argocd + annotations: + argocd.argoproj.io/sync-wave: "-2" spec: project: default diff --git a/platform/security/base/kyverno/application.yaml b/platform/security/base/kyverno/application.yaml index a24ed2c..552448f 100644 --- a/platform/security/base/kyverno/application.yaml +++ b/platform/security/base/kyverno/application.yaml @@ -4,6 +4,8 @@ kind: Application metadata: name: kyverno namespace: argocd + annotations: + argocd.argoproj.io/sync-wave: "-2" spec: project: default diff --git a/platform/security/base/policies/disallow-hostpath.yaml b/platform/security/base/policies/disallow-hostpath.yaml index bb1f7bb..d30a41c 100644 --- a/platform/security/base/policies/disallow-hostpath.yaml +++ b/platform/security/base/policies/disallow-hostpath.yaml @@ -3,6 +3,8 @@ kind: ClusterPolicy metadata: name: disallow-hostpath + annotations: + argocd.argoproj.io/sync-wave: "0" spec: validationFailureAction: Audit diff --git a/platform/security/base/policies/disallow-latest-tag.yaml b/platform/security/base/policies/disallow-latest-tag.yaml index 74b292a..a1d5f3f 100644 --- a/platform/security/base/policies/disallow-latest-tag.yaml +++ b/platform/security/base/policies/disallow-latest-tag.yaml @@ -3,6 +3,8 @@ kind: ClusterPolicy metadata: name: disallow-latest-tag + annotations: + argocd.argoproj.io/sync-wave: "0" spec: validationFailureAction: Audit diff --git a/platform/security/base/policies/disallow-privileged.yaml b/platform/security/base/policies/disallow-privileged.yaml index b48dcda..044ddbb 100644 --- a/platform/security/base/policies/disallow-privileged.yaml +++ b/platform/security/base/policies/disallow-privileged.yaml @@ -3,6 +3,8 @@ kind: ClusterPolicy metadata: name: disallow-privileged + annotations: + argocd.argoproj.io/sync-wave: "0" spec: validationFailureAction: Audit diff --git a/platform/security/base/policies/policy-exception.yaml b/platform/security/base/policies/policy-exception.yaml index f2bf1c8..7854c7a 100644 --- a/platform/security/base/policies/policy-exception.yaml +++ b/platform/security/base/policies/policy-exception.yaml @@ -3,7 +3,8 @@ kind: PolicyException metadata: name: system-namespaces-exception - namespace: kyverno + annotations: + argocd.argoproj.io/sync-wave: "0" spec: exceptions: diff --git a/platform/security/base/policies/require-labels.yaml b/platform/security/base/policies/require-labels.yaml index 1f867eb..bc32e32 100644 --- a/platform/security/base/policies/require-labels.yaml +++ b/platform/security/base/policies/require-labels.yaml @@ -3,7 +3,8 @@ kind: ClusterPolicy metadata: name: require-labels - + annotations: + argocd.argoproj.io/sync-wave: "0" spec: validationFailureAction: Audit diff --git a/platform/security/base/policies/require-limits.yaml b/platform/security/base/policies/require-limits.yaml index 6b1884f..3d4b339 100644 --- a/platform/security/base/policies/require-limits.yaml +++ b/platform/security/base/policies/require-limits.yaml @@ -3,7 +3,9 @@ kind: ClusterPolicy metadata: name: require-resource-limits - + annotations: + argocd.argoproj.io/sync-wave: "0" + spec: validationFailureAction: Audit diff --git a/platform/security/base/policies/require-networkpolicy.yaml b/platform/security/base/policies/require-networkpolicy.yaml index 16d6187..b62f3ee 100644 --- a/platform/security/base/policies/require-networkpolicy.yaml +++ b/platform/security/base/policies/require-networkpolicy.yaml @@ -3,7 +3,9 @@ kind: ClusterPolicy metadata: name: require-networkpolicy - + annotations: + argocd.argoproj.io/sync-wave: "0" + spec: validationFailureAction: Audit diff --git a/platform/security/base/policies/require-non-root.yaml b/platform/security/base/policies/require-non-root.yaml index 7d1093b..7d15771 100644 --- a/platform/security/base/policies/require-non-root.yaml +++ b/platform/security/base/policies/require-non-root.yaml @@ -3,7 +3,9 @@ kind: ClusterPolicy metadata: name: require-non-root - + annotations: + argocd.argoproj.io/sync-wave: "0" + spec: validationFailureAction: Audit diff --git a/platform/security/base/policies/require-pdb.yaml b/platform/security/base/policies/require-pdb.yaml index 26c1215..9d212ab 100644 --- a/platform/security/base/policies/require-pdb.yaml +++ b/platform/security/base/policies/require-pdb.yaml @@ -3,7 +3,9 @@ kind: ClusterPolicy metadata: name: require-pdb - + annotations: + argocd.argoproj.io/sync-wave: "0" + spec: validationFailureAction: Audit diff --git a/platform/security/base/policies/require-probes.yaml b/platform/security/base/policies/require-probes.yaml index b1ca1a3..696eae3 100644 --- a/platform/security/base/policies/require-probes.yaml +++ b/platform/security/base/policies/require-probes.yaml @@ -3,7 +3,9 @@ kind: ClusterPolicy metadata: name: require-probes - + annotations: + argocd.argoproj.io/sync-wave: "0" + spec: validationFailureAction: Audit diff --git a/platform/security/base/policies/require-readonly-rootfs.yaml b/platform/security/base/policies/require-readonly-rootfs.yaml index efa6fd0..fbd3327 100644 --- a/platform/security/base/policies/require-readonly-rootfs.yaml +++ b/platform/security/base/policies/require-readonly-rootfs.yaml @@ -3,7 +3,9 @@ kind: ClusterPolicy metadata: name: require-readonly-rootfs - + annotations: + argocd.argoproj.io/sync-wave: "0" + spec: validationFailureAction: Audit diff --git a/platform/storage/base/backup/schedules.yaml b/platform/storage/base/backup/schedules.yaml index 67c6f00..dc5b776 100644 --- a/platform/storage/base/backup/schedules.yaml +++ b/platform/storage/base/backup/schedules.yaml @@ -4,6 +4,8 @@ kind: Schedule metadata: name: daily-backup namespace: argocd + annotations: + argocd.argoproj.io/sync-wave: "0" spec: schedule: "0 2 * * *" diff --git a/platform/storage/base/velero/application.yaml b/platform/storage/base/velero/application.yaml index 8a83c7e..e47091b 100644 --- a/platform/storage/base/velero/application.yaml +++ b/platform/storage/base/velero/application.yaml @@ -4,6 +4,8 @@ kind: Application metadata: name: velero namespace: argocd + annotations: + argocd.argoproj.io/sync-wave: "-2" spec: project: default From 2d70220e498b4ca9ef3a4b96afc3759b759acb9b Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Fri, 31 Jul 2026 13:56:13 +0000 Subject: [PATCH 073/122] Promote payment-service to e2bab85bf8a0e4f650228147471ae175a246cc09 --- apps/payment-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/payment-service/overlays/dev/kustomization.yaml b/apps/payment-service/overlays/dev/kustomization.yaml index 5004cde..3700d6f 100644 --- a/apps/payment-service/overlays/dev/kustomization.yaml +++ b/apps/payment-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service - newTag: 7cb4e11b6a5c1ed06f957e4dcf0ab12adb771f9e + newTag: e2bab85bf8a0e4f650228147471ae175a246cc09 From 9ee95855413835ffcdc752ce5c5d0f69dd99a263 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Fri, 31 Jul 2026 13:56:35 +0000 Subject: [PATCH 074/122] Promote product-service to e2bab85bf8a0e4f650228147471ae175a246cc09 --- apps/product-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/product-service/overlays/dev/kustomization.yaml b/apps/product-service/overlays/dev/kustomization.yaml index ed2d461..9c57c81 100644 --- a/apps/product-service/overlays/dev/kustomization.yaml +++ b/apps/product-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service - newTag: 7cb4e11b6a5c1ed06f957e4dcf0ab12adb771f9e + newTag: e2bab85bf8a0e4f650228147471ae175a246cc09 From 0cbae90a4a678a068187db2ef60f39fd54ab860b Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Fri, 31 Jul 2026 13:56:39 +0000 Subject: [PATCH 075/122] Promote order-service to e2bab85bf8a0e4f650228147471ae175a246cc09 --- apps/order-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/order-service/overlays/dev/kustomization.yaml b/apps/order-service/overlays/dev/kustomization.yaml index 9fba4ad..47c010f 100644 --- a/apps/order-service/overlays/dev/kustomization.yaml +++ b/apps/order-service/overlays/dev/kustomization.yaml @@ -10,7 +10,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service - newTag: 7cb4e11b6a5c1ed06f957e4dcf0ab12adb771f9e + newTag: e2bab85bf8a0e4f650228147471ae175a246cc09 replicas: - count: 1 From 5d15a320f513d780372a7319ec1b300cbbe905c1 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Fri, 31 Jul 2026 13:56:49 +0000 Subject: [PATCH 076/122] Promote user-service to e2bab85bf8a0e4f650228147471ae175a246cc09 --- apps/user-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/user-service/overlays/dev/kustomization.yaml b/apps/user-service/overlays/dev/kustomization.yaml index df83f9d..ff9a938 100644 --- a/apps/user-service/overlays/dev/kustomization.yaml +++ b/apps/user-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service - newTag: 7cb4e11b6a5c1ed06f957e4dcf0ab12adb771f9e + newTag: e2bab85bf8a0e4f650228147471ae175a246cc09 From 709544a8dea3a6af7d910648afa09665bd035a63 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Fri, 31 Jul 2026 17:14:28 +0200 Subject: [PATCH 077/122] Added wave sync --- infrastructure/overlay/dev/ingress.yaml | 2 +- .../overlays/dev/aws-load-balancer-controller-patch.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/infrastructure/overlay/dev/ingress.yaml b/infrastructure/overlay/dev/ingress.yaml index 54b0e43..e2f3aa1 100644 --- a/infrastructure/overlay/dev/ingress.yaml +++ b/infrastructure/overlay/dev/ingress.yaml @@ -11,7 +11,7 @@ metadata: # HTTPS configuration alb.ingress.kubernetes.io/listen-ports: '[{"HTTP":80},{"HTTPS":443}]' - alb.ingress.kubernetes.io/certificate-arn: arn:aws:acm:us-east-1:579871530627:certificate/dd52e2cd-1df9-461f-b02a-15cc953f5b8d + alb.ingress.kubernetes.io/certificate-arn: arn:aws:acm:us-east-1:579871530627:certificate/c9a99640-7bab-45c5-8cdc-6014bb1be22b # Redirect HTTP to HTTPS alb.ingress.kubernetes.io/ssl-redirect: '443' diff --git a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml index 5293ce7..cce4889 100644 --- a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml +++ b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml @@ -14,7 +14,7 @@ spec: values: | clusterName: eks-dev-cluster region: us-east-1 - vpcId: vpc-004244308de39a801 + vpcId: vpc-053e3dd8d20eacdb1 serviceAccount: create: true From 50799cb9599a07f7d2c5de3c11d93778f86520b6 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Fri, 31 Jul 2026 17:15:39 +0200 Subject: [PATCH 078/122] Added wave sync --- argocd/dev/applicationset-apps.yaml | 3 ++- argocd/dev/applicationset-infra.yaml | 3 ++- argocd/dev/applicationset-monitoring.yaml | 3 ++- argocd/dev/kustomization.yaml | 3 ++- argocd/dev/root-app.yaml | 3 ++- 5 files changed, 10 insertions(+), 5 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 7f57dac..f57a256 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,4 +36,5 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 541c770..20af478 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,4 +34,5 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 254f3ac..d43e417 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,4 +32,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 19f481f..3145684 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml \ No newline at end of file + - applicationset-monitoring.yaml + \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index df9260c..d4becc1 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,4 +20,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file From b732cec0f1ac9ab5cc896ef5184572f986de4216 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Mon, 3 Aug 2026 12:01:05 +0000 Subject: [PATCH 079/122] Promote payment-service to 785d1fc5fdc4821c56c5ebc49d7c71191130dcb0 --- apps/payment-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/payment-service/overlays/dev/kustomization.yaml b/apps/payment-service/overlays/dev/kustomization.yaml index 3700d6f..e6a8c2d 100644 --- a/apps/payment-service/overlays/dev/kustomization.yaml +++ b/apps/payment-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service - newTag: e2bab85bf8a0e4f650228147471ae175a246cc09 + newTag: 785d1fc5fdc4821c56c5ebc49d7c71191130dcb0 From adbb9c236ea6b21e6d6313cf955d173479eb93db Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Mon, 3 Aug 2026 12:01:05 +0000 Subject: [PATCH 080/122] Promote order-service to 785d1fc5fdc4821c56c5ebc49d7c71191130dcb0 --- apps/order-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/order-service/overlays/dev/kustomization.yaml b/apps/order-service/overlays/dev/kustomization.yaml index 47c010f..c40ae73 100644 --- a/apps/order-service/overlays/dev/kustomization.yaml +++ b/apps/order-service/overlays/dev/kustomization.yaml @@ -10,7 +10,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service - newTag: e2bab85bf8a0e4f650228147471ae175a246cc09 + newTag: 785d1fc5fdc4821c56c5ebc49d7c71191130dcb0 replicas: - count: 1 From 0e54f75d6d83c22e2b6e36b58b8d10207a2d244f Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Mon, 3 Aug 2026 12:01:06 +0000 Subject: [PATCH 081/122] Promote user-service to 785d1fc5fdc4821c56c5ebc49d7c71191130dcb0 --- apps/user-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/user-service/overlays/dev/kustomization.yaml b/apps/user-service/overlays/dev/kustomization.yaml index ff9a938..1f778de 100644 --- a/apps/user-service/overlays/dev/kustomization.yaml +++ b/apps/user-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service - newTag: e2bab85bf8a0e4f650228147471ae175a246cc09 + newTag: 785d1fc5fdc4821c56c5ebc49d7c71191130dcb0 From 2944ff05933e85e11fac1770fb8d8e7801232884 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Mon, 3 Aug 2026 12:01:35 +0000 Subject: [PATCH 082/122] Promote product-service to 785d1fc5fdc4821c56c5ebc49d7c71191130dcb0 --- apps/product-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/product-service/overlays/dev/kustomization.yaml b/apps/product-service/overlays/dev/kustomization.yaml index 9c57c81..e59954f 100644 --- a/apps/product-service/overlays/dev/kustomization.yaml +++ b/apps/product-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service - newTag: e2bab85bf8a0e4f650228147471ae175a246cc09 + newTag: 785d1fc5fdc4821c56c5ebc49d7c71191130dcb0 From 8de3ba07c4c0e6e41d6071991881ac3ca3273486 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Mon, 3 Aug 2026 14:20:55 +0200 Subject: [PATCH 083/122] Updated the ACM arn and VPC --- argocd/dev/applicationset-apps.yaml | 3 +-- argocd/dev/applicationset-infra.yaml | 3 +-- argocd/dev/applicationset-monitoring.yaml | 3 +-- argocd/dev/kustomization.yaml | 3 +-- argocd/dev/root-app.yaml | 3 +-- infrastructure/overlay/dev/ingress.yaml | 2 +- .../overlays/dev/aws-load-balancer-controller-patch.yaml | 2 +- 7 files changed, 7 insertions(+), 12 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index f57a256..7f57dac 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,5 +36,4 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 20af478..9fb2948 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,5 +34,4 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index d43e417..dc3e947 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,5 +32,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 3145684..cf43fd9 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,5 +4,4 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml - \ No newline at end of file + - applicationset-monitoring.yaml \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index d4becc1..8f7d805 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,5 +20,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/infrastructure/overlay/dev/ingress.yaml b/infrastructure/overlay/dev/ingress.yaml index e2f3aa1..ef52349 100644 --- a/infrastructure/overlay/dev/ingress.yaml +++ b/infrastructure/overlay/dev/ingress.yaml @@ -11,7 +11,7 @@ metadata: # HTTPS configuration alb.ingress.kubernetes.io/listen-ports: '[{"HTTP":80},{"HTTPS":443}]' - alb.ingress.kubernetes.io/certificate-arn: arn:aws:acm:us-east-1:579871530627:certificate/c9a99640-7bab-45c5-8cdc-6014bb1be22b + alb.ingress.kubernetes.io/certificate-arn: arn:aws:acm:us-east-1:579871530627:certificate/10b939a7-cb20-44cb-9b8c-f6ddbb85adf7 # Redirect HTTP to HTTPS alb.ingress.kubernetes.io/ssl-redirect: '443' diff --git a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml index cce4889..457d7ad 100644 --- a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml +++ b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml @@ -14,7 +14,7 @@ spec: values: | clusterName: eks-dev-cluster region: us-east-1 - vpcId: vpc-053e3dd8d20eacdb1 + vpcId: vpc-07b173866ae81b30b serviceAccount: create: true From 8ff0f006a859c81b1f7a7d014519eac1f72a6b3b Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Mon, 3 Aug 2026 14:56:39 +0200 Subject: [PATCH 084/122] Updated the ACM arn and VPC --- argocd/dev/applicationset-apps.yaml | 3 ++- argocd/dev/applicationset-infra.yaml | 3 ++- argocd/dev/applicationset-monitoring.yaml | 3 ++- argocd/dev/kustomization.yaml | 3 ++- argocd/dev/root-app.yaml | 3 ++- .../monitoring/overlays/dev/order/application.yaml | 10 +++++----- .../monitoring/overlays/dev/payment/application.yaml | 10 +++++----- platform/monitoring/overlays/dev/user/application.yaml | 10 +++++----- 8 files changed, 25 insertions(+), 20 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 7f57dac..3aa31cc 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,4 +36,5 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 9fb2948..9dd00a3 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,4 +34,5 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index dc3e947..cd55190 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,4 +32,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index cf43fd9..02ebc41 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml \ No newline at end of file + - applicationset-monitoring.yaml + \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 8f7d805..d3451fe 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,4 +20,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/platform/monitoring/overlays/dev/order/application.yaml b/platform/monitoring/overlays/dev/order/application.yaml index 3fff134..e50ea4b 100644 --- a/platform/monitoring/overlays/dev/order/application.yaml +++ b/platform/monitoring/overlays/dev/order/application.yaml @@ -18,11 +18,11 @@ spec: serviceMonitor: enabled: true - config: - datasource: - host: order-postgres.dev.svc.cluster.local - port: "5432" - database: orderdb + config: + datasource: + host: order-postgres.dev.svc.cluster.local + port: "5432" + database: orderdb destination: server: https://kubernetes.default.svc diff --git a/platform/monitoring/overlays/dev/payment/application.yaml b/platform/monitoring/overlays/dev/payment/application.yaml index 61ef22a..d35c555 100644 --- a/platform/monitoring/overlays/dev/payment/application.yaml +++ b/platform/monitoring/overlays/dev/payment/application.yaml @@ -18,11 +18,11 @@ spec: serviceMonitor: enabled: true - config: - datasource: - host: payment-postgres.dev.svc.cluster.local - port: "5432" - database: paymentdb + config: + datasource: + host: payment-postgres.dev.svc.cluster.local + port: "5432" + database: paymentdb destination: server: https://kubernetes.default.svc diff --git a/platform/monitoring/overlays/dev/user/application.yaml b/platform/monitoring/overlays/dev/user/application.yaml index 3006ed6..ceaf052 100644 --- a/platform/monitoring/overlays/dev/user/application.yaml +++ b/platform/monitoring/overlays/dev/user/application.yaml @@ -18,11 +18,11 @@ spec: serviceMonitor: enabled: true - config: - datasource: - host: user-postgres.dev.svc.cluster.local - port: "5432" - database: userdb + config: + datasource: + host: user-postgres.dev.svc.cluster.local + port: "5432" + database: userdb destination: server: https://kubernetes.default.svc From 5e90656419f091d1fb8e3b927b52b32e211069ae Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Mon, 3 Aug 2026 15:17:10 +0200 Subject: [PATCH 085/122] Removed namespace from platform overlay --- argocd/dev/applicationset-apps.yaml | 3 +-- argocd/dev/applicationset-infra.yaml | 3 +-- argocd/dev/applicationset-monitoring.yaml | 3 +-- argocd/dev/kustomization.yaml | 3 +-- argocd/dev/root-app.yaml | 3 +-- platform/overlays/dev/kustomization.yaml | 3 +-- platform/overlays/dev/platform-namespace.yaml | 5 ----- 7 files changed, 6 insertions(+), 17 deletions(-) delete mode 100644 platform/overlays/dev/platform-namespace.yaml diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 3aa31cc..065cce8 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,5 +36,4 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 9dd00a3..40a8cfc 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,5 +34,4 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index cd55190..3b93721 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,5 +32,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 02ebc41..19f481f 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,5 +4,4 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml - \ No newline at end of file + - applicationset-monitoring.yaml \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index d3451fe..447bb3c 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,5 +20,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/platform/overlays/dev/kustomization.yaml b/platform/overlays/dev/kustomization.yaml index 1d4ed90..541da90 100644 --- a/platform/overlays/dev/kustomization.yaml +++ b/platform/overlays/dev/kustomization.yaml @@ -8,5 +8,4 @@ resources: - ../../networking/overlays/dev - ../../security/overlays/dev - ../../tracing/overlays/dev - - ../../storage/overlays/dev - - platform-namespace.yaml \ No newline at end of file + - ../../storage/overlays/dev \ No newline at end of file diff --git a/platform/overlays/dev/platform-namespace.yaml b/platform/overlays/dev/platform-namespace.yaml deleted file mode 100644 index 0b345a8..0000000 --- a/platform/overlays/dev/platform-namespace.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v1 -kind: Namespace - -metadata: - name: dev \ No newline at end of file From 04622345ba5b1cf0cdbad76c747ec016f48b0ce9 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Mon, 3 Aug 2026 15:43:15 +0200 Subject: [PATCH 086/122] Removed namespace from platform overlay --- argocd/dev/applicationset-apps.yaml | 3 ++- argocd/dev/applicationset-infra.yaml | 3 ++- argocd/dev/applicationset-monitoring.yaml | 3 ++- argocd/dev/kustomization.yaml | 3 ++- argocd/dev/root-app.yaml | 3 ++- .../servicemonitors/aws-load-balancer-controller.yaml | 9 ++++----- 6 files changed, 14 insertions(+), 10 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 065cce8..e1f3339 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,4 +36,5 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 40a8cfc..162acb8 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,4 +34,5 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 3b93721..59e2e54 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,4 +32,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 19f481f..cb3d011 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml \ No newline at end of file + - applicationset-monitoring.yaml + \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 447bb3c..b50bd78 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,4 +20,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/aws-load-balancer-controller.yaml b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/aws-load-balancer-controller.yaml index 62a4311..cd39c75 100644 --- a/platform/monitoring/base/kube-prometheus-stack/servicemonitors/aws-load-balancer-controller.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/servicemonitors/aws-load-balancer-controller.yaml @@ -3,20 +3,19 @@ kind: ServiceMonitor metadata: name: aws-load-balancer-controller - namespace: kube-system labels: prometheus: kube-prometheus spec: + namespaceSelector: + matchNames: + - kube-system + selector: matchLabels: app.kubernetes.io/name: aws-load-balancer-controller - namespaceSelector: - matchNames: - - kube-system - endpoints: - port: metrics interval: 30s \ No newline at end of file From d8692d699404351a18247324d28c4662c54e561e Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Mon, 3 Aug 2026 16:03:30 +0200 Subject: [PATCH 087/122] Fix EFS StorageClass directoryPerms parameter --- argocd/dev/applicationset-apps.yaml | 3 +-- argocd/dev/applicationset-infra.yaml | 3 +-- argocd/dev/applicationset-monitoring.yaml | 3 +-- argocd/dev/kustomization.yaml | 3 +-- argocd/dev/root-app.yaml | 3 +-- platform/overlays/dev/platform-namespace.yaml | 5 +++++ platform/storage/base/storageclasses/efs.yaml | 3 +-- 7 files changed, 11 insertions(+), 12 deletions(-) create mode 100644 platform/overlays/dev/platform-namespace.yaml diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index e1f3339..49e3e37 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,5 +36,4 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 162acb8..08bac5e 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,5 +34,4 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 59e2e54..24b0ae4 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,5 +32,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index cb3d011..e63013f 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,5 +4,4 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml - \ No newline at end of file + - applicationset-monitoring.yaml \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index b50bd78..5a5f5d7 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,5 +20,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/platform/overlays/dev/platform-namespace.yaml b/platform/overlays/dev/platform-namespace.yaml new file mode 100644 index 0000000..0b345a8 --- /dev/null +++ b/platform/overlays/dev/platform-namespace.yaml @@ -0,0 +1,5 @@ +apiVersion: v1 +kind: Namespace + +metadata: + name: dev \ No newline at end of file diff --git a/platform/storage/base/storageclasses/efs.yaml b/platform/storage/base/storageclasses/efs.yaml index 5ad2bb4..96a0eff 100644 --- a/platform/storage/base/storageclasses/efs.yaml +++ b/platform/storage/base/storageclasses/efs.yaml @@ -8,8 +8,7 @@ provisioner: efs.csi.aws.com parameters: provisioningMode: efs-ap - -directoryPerms: "700" + directoryPerms: "700" reclaimPolicy: Delete From e51ae3eaf12b602aecb480c23c3026fcdb018551 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 4 Aug 2026 07:59:33 +0000 Subject: [PATCH 088/122] Promote product-service to 09456fa8825fd5fb40f4736109f5e1115bbb816e --- apps/product-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/product-service/overlays/dev/kustomization.yaml b/apps/product-service/overlays/dev/kustomization.yaml index e59954f..5209d0c 100644 --- a/apps/product-service/overlays/dev/kustomization.yaml +++ b/apps/product-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service - newTag: 785d1fc5fdc4821c56c5ebc49d7c71191130dcb0 + newTag: 09456fa8825fd5fb40f4736109f5e1115bbb816e From d8a165f57131f829c5486867d04d4eba56a0031b Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 4 Aug 2026 07:59:47 +0000 Subject: [PATCH 089/122] Promote user-service to 09456fa8825fd5fb40f4736109f5e1115bbb816e --- apps/user-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/user-service/overlays/dev/kustomization.yaml b/apps/user-service/overlays/dev/kustomization.yaml index 1f778de..7616773 100644 --- a/apps/user-service/overlays/dev/kustomization.yaml +++ b/apps/user-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service - newTag: 785d1fc5fdc4821c56c5ebc49d7c71191130dcb0 + newTag: 09456fa8825fd5fb40f4736109f5e1115bbb816e From e2c676ff52a87065da0713b4644805a609471ed3 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 4 Aug 2026 08:00:10 +0000 Subject: [PATCH 090/122] Promote order-service to 09456fa8825fd5fb40f4736109f5e1115bbb816e --- apps/order-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/order-service/overlays/dev/kustomization.yaml b/apps/order-service/overlays/dev/kustomization.yaml index c40ae73..149a23b 100644 --- a/apps/order-service/overlays/dev/kustomization.yaml +++ b/apps/order-service/overlays/dev/kustomization.yaml @@ -10,7 +10,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service - newTag: 785d1fc5fdc4821c56c5ebc49d7c71191130dcb0 + newTag: 09456fa8825fd5fb40f4736109f5e1115bbb816e replicas: - count: 1 From 0f8fac72f5002fd5ae2afd5aa809f92de681203e Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 4 Aug 2026 08:00:19 +0000 Subject: [PATCH 091/122] Promote payment-service to 09456fa8825fd5fb40f4736109f5e1115bbb816e --- apps/payment-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/payment-service/overlays/dev/kustomization.yaml b/apps/payment-service/overlays/dev/kustomization.yaml index e6a8c2d..743f698 100644 --- a/apps/payment-service/overlays/dev/kustomization.yaml +++ b/apps/payment-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service - newTag: 785d1fc5fdc4821c56c5ebc49d7c71191130dcb0 + newTag: 09456fa8825fd5fb40f4736109f5e1115bbb816e From 6c9454d8f95139b2399a9d94400c75bc8b8b08b6 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 4 Aug 2026 10:03:53 +0200 Subject: [PATCH 092/122] Troubleshooting monitoring --- argocd/dev/applicationset-apps.yaml | 3 ++- argocd/dev/applicationset-infra.yaml | 3 ++- argocd/dev/applicationset-monitoring.yaml | 3 ++- argocd/dev/kustomization.yaml | 3 ++- argocd/dev/root-app.yaml | 3 ++- 5 files changed, 10 insertions(+), 5 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 49e3e37..45a86cf 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,4 +36,5 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 08bac5e..dcf2c79 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,4 +34,5 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 24b0ae4..b0dbdd4 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,4 +32,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index e63013f..7c79629 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml \ No newline at end of file + - applicationset-monitoring.yaml + \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 5a5f5d7..402b839 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,4 +20,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file From ac9ee307008e16c6e526ec6156216c2885f21274 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 4 Aug 2026 10:38:47 +0200 Subject: [PATCH 093/122] Troubleshooting --- argocd/dev/applicationset-apps.yaml | 3 +-- argocd/dev/applicationset-infra.yaml | 3 +-- argocd/dev/applicationset-monitoring.yaml | 3 +-- argocd/dev/kustomization.yaml | 3 +-- argocd/dev/root-app.yaml | 3 +-- infrastructure/overlay/dev/kustomization.yaml | 4 ---- .../overlay/dev/{order-db-secret.yaml => order-db-secret.txt} | 0 .../dev/{payment-db-secret.yaml => payment-db-secret.txt} | 0 .../dev/{product-db-secret.yaml => product-db-secret.txt} | 0 .../overlay/dev/{user-db-secret.yaml => user-db-secret.txt} | 0 10 files changed, 5 insertions(+), 14 deletions(-) rename infrastructure/overlay/dev/{order-db-secret.yaml => order-db-secret.txt} (100%) rename infrastructure/overlay/dev/{payment-db-secret.yaml => payment-db-secret.txt} (100%) rename infrastructure/overlay/dev/{product-db-secret.yaml => product-db-secret.txt} (100%) rename infrastructure/overlay/dev/{user-db-secret.yaml => user-db-secret.txt} (100%) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 45a86cf..2e0b5f2 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,5 +36,4 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index dcf2c79..b3acfd8 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,5 +34,4 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index b0dbdd4..49af982 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,5 +32,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 7c79629..c919834 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,5 +4,4 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml - \ No newline at end of file + - applicationset-monitoring.yaml \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 402b839..861570b 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,5 +20,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/infrastructure/overlay/dev/kustomization.yaml b/infrastructure/overlay/dev/kustomization.yaml index 02644f2..9b6e3cc 100644 --- a/infrastructure/overlay/dev/kustomization.yaml +++ b/infrastructure/overlay/dev/kustomization.yaml @@ -7,11 +7,7 @@ resources: - cluster-secret-store.yaml - ingress.yaml - namespace-infra.yaml - - order-db-secret.yaml - - payment-db-secret.yaml - postgres-master-secret.yaml - - product-db-secret.yaml - - user-db-secret.yaml - external-secrets-sa.yaml - redis-secret.yaml - job.yaml \ No newline at end of file diff --git a/infrastructure/overlay/dev/order-db-secret.yaml b/infrastructure/overlay/dev/order-db-secret.txt similarity index 100% rename from infrastructure/overlay/dev/order-db-secret.yaml rename to infrastructure/overlay/dev/order-db-secret.txt diff --git a/infrastructure/overlay/dev/payment-db-secret.yaml b/infrastructure/overlay/dev/payment-db-secret.txt similarity index 100% rename from infrastructure/overlay/dev/payment-db-secret.yaml rename to infrastructure/overlay/dev/payment-db-secret.txt diff --git a/infrastructure/overlay/dev/product-db-secret.yaml b/infrastructure/overlay/dev/product-db-secret.txt similarity index 100% rename from infrastructure/overlay/dev/product-db-secret.yaml rename to infrastructure/overlay/dev/product-db-secret.txt diff --git a/infrastructure/overlay/dev/user-db-secret.yaml b/infrastructure/overlay/dev/user-db-secret.txt similarity index 100% rename from infrastructure/overlay/dev/user-db-secret.yaml rename to infrastructure/overlay/dev/user-db-secret.txt From 83c282c7de29b33079765328ba555628326388cc Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 4 Aug 2026 11:55:10 +0000 Subject: [PATCH 094/122] Promote payment-service to b9defe149c5815910598b23715451f70ca25baac --- apps/payment-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/payment-service/overlays/dev/kustomization.yaml b/apps/payment-service/overlays/dev/kustomization.yaml index 743f698..04d29b2 100644 --- a/apps/payment-service/overlays/dev/kustomization.yaml +++ b/apps/payment-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service - newTag: 09456fa8825fd5fb40f4736109f5e1115bbb816e + newTag: b9defe149c5815910598b23715451f70ca25baac From f962035a3b9970a438d0b41a5aa7aecfd7c6b724 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 4 Aug 2026 11:55:23 +0000 Subject: [PATCH 095/122] Promote product-service to b9defe149c5815910598b23715451f70ca25baac --- apps/product-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/product-service/overlays/dev/kustomization.yaml b/apps/product-service/overlays/dev/kustomization.yaml index 5209d0c..e9237ee 100644 --- a/apps/product-service/overlays/dev/kustomization.yaml +++ b/apps/product-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service - newTag: 09456fa8825fd5fb40f4736109f5e1115bbb816e + newTag: b9defe149c5815910598b23715451f70ca25baac From aadfda98e753322439f4ae0fb2e47d5fee315c19 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 4 Aug 2026 11:55:28 +0000 Subject: [PATCH 096/122] Promote order-service to b9defe149c5815910598b23715451f70ca25baac --- apps/order-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/order-service/overlays/dev/kustomization.yaml b/apps/order-service/overlays/dev/kustomization.yaml index 149a23b..8c56aa3 100644 --- a/apps/order-service/overlays/dev/kustomization.yaml +++ b/apps/order-service/overlays/dev/kustomization.yaml @@ -10,7 +10,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service - newTag: 09456fa8825fd5fb40f4736109f5e1115bbb816e + newTag: b9defe149c5815910598b23715451f70ca25baac replicas: - count: 1 From acc46e16ab6dcf0d23330b317558819a1ceb95fb Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 4 Aug 2026 11:56:03 +0000 Subject: [PATCH 097/122] Promote user-service to b9defe149c5815910598b23715451f70ca25baac --- apps/user-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/user-service/overlays/dev/kustomization.yaml b/apps/user-service/overlays/dev/kustomization.yaml index 7616773..6de6739 100644 --- a/apps/user-service/overlays/dev/kustomization.yaml +++ b/apps/user-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service - newTag: 09456fa8825fd5fb40f4736109f5e1115bbb816e + newTag: b9defe149c5815910598b23715451f70ca25baac From 22ad002c0134bcc95191a323cae19141f006047d Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 4 Aug 2026 13:59:45 +0200 Subject: [PATCH 098/122] Reaaded service secrets --- infrastructure/overlay/dev/kustomization.yaml | 2 ++ .../overlay/dev/{order-db-secret.txt => order-db-secret.yaml} | 0 .../dev/{payment-db-secret.txt => payment-db-secret.yaml} | 0 .../dev/{product-db-secret.txt => product-db-secret.yaml} | 0 .../overlay/dev/{user-db-secret.txt => user-db-secret.yaml} | 0 5 files changed, 2 insertions(+) rename infrastructure/overlay/dev/{order-db-secret.txt => order-db-secret.yaml} (100%) rename infrastructure/overlay/dev/{payment-db-secret.txt => payment-db-secret.yaml} (100%) rename infrastructure/overlay/dev/{product-db-secret.txt => product-db-secret.yaml} (100%) rename infrastructure/overlay/dev/{user-db-secret.txt => user-db-secret.yaml} (100%) diff --git a/infrastructure/overlay/dev/kustomization.yaml b/infrastructure/overlay/dev/kustomization.yaml index 9b6e3cc..b63b382 100644 --- a/infrastructure/overlay/dev/kustomization.yaml +++ b/infrastructure/overlay/dev/kustomization.yaml @@ -7,6 +7,8 @@ resources: - cluster-secret-store.yaml - ingress.yaml - namespace-infra.yaml + - order-db-secret.yaml + - payment-db-secret.yaml - postgres-master-secret.yaml - external-secrets-sa.yaml - redis-secret.yaml diff --git a/infrastructure/overlay/dev/order-db-secret.txt b/infrastructure/overlay/dev/order-db-secret.yaml similarity index 100% rename from infrastructure/overlay/dev/order-db-secret.txt rename to infrastructure/overlay/dev/order-db-secret.yaml diff --git a/infrastructure/overlay/dev/payment-db-secret.txt b/infrastructure/overlay/dev/payment-db-secret.yaml similarity index 100% rename from infrastructure/overlay/dev/payment-db-secret.txt rename to infrastructure/overlay/dev/payment-db-secret.yaml diff --git a/infrastructure/overlay/dev/product-db-secret.txt b/infrastructure/overlay/dev/product-db-secret.yaml similarity index 100% rename from infrastructure/overlay/dev/product-db-secret.txt rename to infrastructure/overlay/dev/product-db-secret.yaml diff --git a/infrastructure/overlay/dev/user-db-secret.txt b/infrastructure/overlay/dev/user-db-secret.yaml similarity index 100% rename from infrastructure/overlay/dev/user-db-secret.txt rename to infrastructure/overlay/dev/user-db-secret.yaml From 721e9d4562abea9ce209c1a11df73af942a57fce Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 4 Aug 2026 14:01:32 +0200 Subject: [PATCH 099/122] Reaaded service secrets --- argocd/dev/applicationset-apps.yaml | 3 ++- argocd/dev/applicationset-infra.yaml | 3 ++- argocd/dev/applicationset-monitoring.yaml | 3 ++- argocd/dev/kustomization.yaml | 3 ++- argocd/dev/root-app.yaml | 3 ++- 5 files changed, 10 insertions(+), 5 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index 2e0b5f2..b294a82 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,4 +36,5 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index b3acfd8..5b7526d 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,4 +34,5 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 49af982..4bbf3b9 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,4 +32,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index c919834..71a3ada 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml \ No newline at end of file + - applicationset-monitoring.yaml + \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 861570b..1ca7598 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,4 +20,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file From 022ba69217f6f91243f36713e86f6e158ed8ab39 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 4 Aug 2026 14:21:18 +0200 Subject: [PATCH 100/122] Added VPC ID and ACM ARN --- argocd/dev/applicationset-apps.yaml | 3 +-- argocd/dev/applicationset-infra.yaml | 3 +-- argocd/dev/applicationset-monitoring.yaml | 3 +-- argocd/dev/kustomization.yaml | 3 +-- argocd/dev/root-app.yaml | 3 +-- infrastructure/overlay/dev/ingress.yaml | 2 +- .../overlays/dev/aws-load-balancer-controller-patch.yaml | 2 +- 7 files changed, 7 insertions(+), 12 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index b294a82..f57ba90 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,5 +36,4 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 5b7526d..24340f7 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,5 +34,4 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 4bbf3b9..dddedee 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,5 +32,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 71a3ada..7853594 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,5 +4,4 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml - \ No newline at end of file + - applicationset-monitoring.yaml \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 1ca7598..91670e8 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,5 +20,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/infrastructure/overlay/dev/ingress.yaml b/infrastructure/overlay/dev/ingress.yaml index ef52349..556dca5 100644 --- a/infrastructure/overlay/dev/ingress.yaml +++ b/infrastructure/overlay/dev/ingress.yaml @@ -11,7 +11,7 @@ metadata: # HTTPS configuration alb.ingress.kubernetes.io/listen-ports: '[{"HTTP":80},{"HTTPS":443}]' - alb.ingress.kubernetes.io/certificate-arn: arn:aws:acm:us-east-1:579871530627:certificate/10b939a7-cb20-44cb-9b8c-f6ddbb85adf7 + alb.ingress.kubernetes.io/certificate-arn: arn:aws:acm:us-east-1:579871530627:certificate/01cf2a66-d964-4a73-a331-09d53ad7bfdc # Redirect HTTP to HTTPS alb.ingress.kubernetes.io/ssl-redirect: '443' diff --git a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml index 457d7ad..e912465 100644 --- a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml +++ b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml @@ -14,7 +14,7 @@ spec: values: | clusterName: eks-dev-cluster region: us-east-1 - vpcId: vpc-07b173866ae81b30b + vpcId: vpc-068d485a36c94f6c1 serviceAccount: create: true From db182ce92fbe460a315507beafe59a1dadcd5920 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 4 Aug 2026 14:52:00 +0200 Subject: [PATCH 101/122] Added VPC ID and ACM ARN --- argocd/dev/applicationset-apps.yaml | 3 ++- argocd/dev/applicationset-infra.yaml | 3 ++- argocd/dev/applicationset-monitoring.yaml | 3 ++- argocd/dev/kustomization.yaml | 3 ++- argocd/dev/root-app.yaml | 2 +- 5 files changed, 9 insertions(+), 5 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index f57ba90..b1dec3a 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,4 +36,5 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 24340f7..620dfe6 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,4 +34,5 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true \ No newline at end of file + - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index dddedee..c00d453 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,4 +32,5 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index 7853594..bc462ba 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,4 +4,5 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml \ No newline at end of file + - applicationset-monitoring.yaml + \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 91670e8..63dee02 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,4 +20,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true \ No newline at end of file From f7863ffc5ca9fed2311b7842299a54c30edbd498 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 4 Aug 2026 15:25:17 +0200 Subject: [PATCH 102/122] Added VPC ID and ACM ARN --- infrastructure/overlay/dev/ingress.yaml | 2 +- .../overlays/dev/aws-load-balancer-controller-patch.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/infrastructure/overlay/dev/ingress.yaml b/infrastructure/overlay/dev/ingress.yaml index 556dca5..8c50892 100644 --- a/infrastructure/overlay/dev/ingress.yaml +++ b/infrastructure/overlay/dev/ingress.yaml @@ -11,7 +11,7 @@ metadata: # HTTPS configuration alb.ingress.kubernetes.io/listen-ports: '[{"HTTP":80},{"HTTPS":443}]' - alb.ingress.kubernetes.io/certificate-arn: arn:aws:acm:us-east-1:579871530627:certificate/01cf2a66-d964-4a73-a331-09d53ad7bfdc + alb.ingress.kubernetes.io/certificate-arn: arn:aws:acm:us-east-1:579871530627:certificate/9b85dde6-b1b3-4c11-b2bf-7d9fc7cb61dc # Redirect HTTP to HTTPS alb.ingress.kubernetes.io/ssl-redirect: '443' diff --git a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml index e912465..8def9f5 100644 --- a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml +++ b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml @@ -14,7 +14,7 @@ spec: values: | clusterName: eks-dev-cluster region: us-east-1 - vpcId: vpc-068d485a36c94f6c1 + vpcId: vpc-04114a98c8e561e35 serviceAccount: create: true From f6c60ccc6f0d27d9990158de003c1b0f6e0da62a Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 4 Aug 2026 13:55:32 +0000 Subject: [PATCH 103/122] Promote payment-service to b7a932f6a5e446298584d5714485c2ae392e3956 --- apps/payment-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/payment-service/overlays/dev/kustomization.yaml b/apps/payment-service/overlays/dev/kustomization.yaml index 04d29b2..e72b15b 100644 --- a/apps/payment-service/overlays/dev/kustomization.yaml +++ b/apps/payment-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service - newTag: b9defe149c5815910598b23715451f70ca25baac + newTag: b7a932f6a5e446298584d5714485c2ae392e3956 From 2eef1a66a3669d0020664440a1881dd74f9ce7c0 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 4 Aug 2026 13:55:36 +0000 Subject: [PATCH 104/122] Promote order-service to b7a932f6a5e446298584d5714485c2ae392e3956 --- apps/order-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/order-service/overlays/dev/kustomization.yaml b/apps/order-service/overlays/dev/kustomization.yaml index 8c56aa3..774aaf1 100644 --- a/apps/order-service/overlays/dev/kustomization.yaml +++ b/apps/order-service/overlays/dev/kustomization.yaml @@ -10,7 +10,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service - newTag: b9defe149c5815910598b23715451f70ca25baac + newTag: b7a932f6a5e446298584d5714485c2ae392e3956 replicas: - count: 1 From 3789c221ebfa2405454e1bffe9874d3eae3166a2 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 4 Aug 2026 13:55:50 +0000 Subject: [PATCH 105/122] Promote user-service to b7a932f6a5e446298584d5714485c2ae392e3956 --- apps/user-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/user-service/overlays/dev/kustomization.yaml b/apps/user-service/overlays/dev/kustomization.yaml index 6de6739..9328872 100644 --- a/apps/user-service/overlays/dev/kustomization.yaml +++ b/apps/user-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service - newTag: b9defe149c5815910598b23715451f70ca25baac + newTag: b7a932f6a5e446298584d5714485c2ae392e3956 From 8f7806a057537c277b76ae0b1f374dcadb80303e Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 4 Aug 2026 13:56:03 +0000 Subject: [PATCH 106/122] Promote product-service to b7a932f6a5e446298584d5714485c2ae392e3956 --- apps/product-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/product-service/overlays/dev/kustomization.yaml b/apps/product-service/overlays/dev/kustomization.yaml index e9237ee..70eee0c 100644 --- a/apps/product-service/overlays/dev/kustomization.yaml +++ b/apps/product-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service - newTag: b9defe149c5815910598b23715451f70ca25baac + newTag: b7a932f6a5e446298584d5714485c2ae392e3956 From e57d2613f51bfaad75ff17b278b4d95a258d055f Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 4 Aug 2026 15:59:27 +0200 Subject: [PATCH 107/122] Added VPC ID and ACM ARN --- argocd/dev/applicationset-apps.yaml | 1 + argocd/dev/applicationset-infra.yaml | 1 + argocd/dev/applicationset-monitoring.yaml | 1 + argocd/dev/kustomization.yaml | 1 + argocd/dev/root-app.yaml | 4 +++- 5 files changed, 7 insertions(+), 1 deletion(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index b1dec3a..f76630e 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -37,4 +37,5 @@ spec: syncOptions: - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 620dfe6..4cd31d7 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -35,4 +35,5 @@ spec: selfHeal: true syncOptions: - CreateNamespace=true + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index c00d453..080e0db 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -33,4 +33,5 @@ spec: automated: prune: true selfHeal: true + \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index bc462ba..cd59cd5 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -5,4 +5,5 @@ resources: - applicationset-apps.yaml - applicationset-infra.yaml - applicationset-monitoring.yaml + \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 63dee02..9d88c8b 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,4 +20,6 @@ spec: syncPolicy: automated: prune: true - selfHeal: true \ No newline at end of file + selfHeal: true + + \ No newline at end of file From 962540c46f92ace4452cfb3a04ca93c440ea9663 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 4 Aug 2026 22:11:45 +0200 Subject: [PATCH 108/122] Added VPC ID and ACM ARN --- infrastructure/overlay/dev/ingress.yaml | 2 +- .../overlays/dev/aws-load-balancer-controller-patch.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/infrastructure/overlay/dev/ingress.yaml b/infrastructure/overlay/dev/ingress.yaml index 8c50892..b2ffdfd 100644 --- a/infrastructure/overlay/dev/ingress.yaml +++ b/infrastructure/overlay/dev/ingress.yaml @@ -11,7 +11,7 @@ metadata: # HTTPS configuration alb.ingress.kubernetes.io/listen-ports: '[{"HTTP":80},{"HTTPS":443}]' - alb.ingress.kubernetes.io/certificate-arn: arn:aws:acm:us-east-1:579871530627:certificate/9b85dde6-b1b3-4c11-b2bf-7d9fc7cb61dc + alb.ingress.kubernetes.io/certificate-arn: arn:aws:acm:us-east-1:579871530627:certificate/77c8e69f-b53a-446c-84d6-98eb1ff8a36c # Redirect HTTP to HTTPS alb.ingress.kubernetes.io/ssl-redirect: '443' diff --git a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml index 8def9f5..54ef86f 100644 --- a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml +++ b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml @@ -14,7 +14,7 @@ spec: values: | clusterName: eks-dev-cluster region: us-east-1 - vpcId: vpc-04114a98c8e561e35 + vpcId: vpc-0195ddfde2538cf9a serviceAccount: create: true From aa4a89a276d21e7bda92f65bd4bbe57a28c10d1f Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 4 Aug 2026 20:30:46 +0000 Subject: [PATCH 109/122] Promote product-service to 556f5d948568e14edc2d380274c0127628db58bf --- apps/product-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/product-service/overlays/dev/kustomization.yaml b/apps/product-service/overlays/dev/kustomization.yaml index 70eee0c..767cb09 100644 --- a/apps/product-service/overlays/dev/kustomization.yaml +++ b/apps/product-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service - newTag: b7a932f6a5e446298584d5714485c2ae392e3956 + newTag: 556f5d948568e14edc2d380274c0127628db58bf From 142ccc97b884c5915d5efc53f8fff8676519c449 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 4 Aug 2026 20:30:55 +0000 Subject: [PATCH 110/122] Promote payment-service to 556f5d948568e14edc2d380274c0127628db58bf --- apps/payment-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/payment-service/overlays/dev/kustomization.yaml b/apps/payment-service/overlays/dev/kustomization.yaml index e72b15b..4345c35 100644 --- a/apps/payment-service/overlays/dev/kustomization.yaml +++ b/apps/payment-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service - newTag: b7a932f6a5e446298584d5714485c2ae392e3956 + newTag: 556f5d948568e14edc2d380274c0127628db58bf From fb6705143a078fc7bf640b13f722766b72db2fe4 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 4 Aug 2026 20:31:56 +0000 Subject: [PATCH 111/122] Promote user-service to 556f5d948568e14edc2d380274c0127628db58bf --- apps/user-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/user-service/overlays/dev/kustomization.yaml b/apps/user-service/overlays/dev/kustomization.yaml index 9328872..c617ae3 100644 --- a/apps/user-service/overlays/dev/kustomization.yaml +++ b/apps/user-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service - newTag: b7a932f6a5e446298584d5714485c2ae392e3956 + newTag: 556f5d948568e14edc2d380274c0127628db58bf From 9d92b44dea1db493cd0919dd32c715ae06e4e675 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Tue, 4 Aug 2026 20:33:34 +0000 Subject: [PATCH 112/122] Promote order-service to 556f5d948568e14edc2d380274c0127628db58bf --- apps/order-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/order-service/overlays/dev/kustomization.yaml b/apps/order-service/overlays/dev/kustomization.yaml index 774aaf1..2e118c2 100644 --- a/apps/order-service/overlays/dev/kustomization.yaml +++ b/apps/order-service/overlays/dev/kustomization.yaml @@ -10,7 +10,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service - newTag: b7a932f6a5e446298584d5714485c2ae392e3956 + newTag: 556f5d948568e14edc2d380274c0127628db58bf replicas: - count: 1 From c9ff878d9e399ba5bdd53d3292703202818ac1cb Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Tue, 4 Aug 2026 22:38:19 +0200 Subject: [PATCH 113/122] Added VPC ID and ACM ARN --- argocd/dev/applicationset-apps.yaml | 3 +-- argocd/dev/applicationset-infra.yaml | 3 +-- argocd/dev/applicationset-monitoring.yaml | 3 +-- argocd/dev/kustomization.yaml | 3 +-- argocd/dev/root-app.yaml | 3 +-- 5 files changed, 5 insertions(+), 10 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index f76630e..f419b61 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -37,5 +37,4 @@ spec: syncOptions: - CreateNamespace=true - - \ No newline at end of file + \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index 4cd31d7..d7bdda9 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -35,5 +35,4 @@ spec: selfHeal: true syncOptions: - CreateNamespace=true - - \ No newline at end of file + \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 080e0db..77fb7e8 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -33,5 +33,4 @@ spec: automated: prune: true selfHeal: true - - \ No newline at end of file + \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index cd59cd5..c032462 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -5,5 +5,4 @@ resources: - applicationset-apps.yaml - applicationset-infra.yaml - applicationset-monitoring.yaml - - \ No newline at end of file + \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 9d88c8b..7e9ea16 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -21,5 +21,4 @@ spec: automated: prune: true selfHeal: true - - \ No newline at end of file + \ No newline at end of file From dd9c2d074761192a733a32561e2bc621e40a4cc8 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Fri, 7 Aug 2026 15:14:30 +0200 Subject: [PATCH 114/122] Customized the dashboard --- .../applications/ingress-nginx.json | 0 .../dashboards/applications/kafka.json | 0 .../applications/kustomization.yaml | 21 ++++++ .../dashboards/applications/nginx.json | 0 .../dashboards/applications/postgresql.json | 0 .../dashboards/applications/redis.json | 0 .../dashboards/applications/springboot.json | 0 .../dashboards/dashboard-provider.yaml | 39 +++++++++++ .../dashboards/infrastructure/api-server.json | 0 .../infrastructure/cluster-capacity.json | 0 .../infrastructure/controller-manager.json | 0 .../dashboards/infrastructure/etcd.json | 0 .../infrastructure/kubernetes-cluster.json | 0 .../infrastructure/kubernetes-overview.json | 0 .../infrastructure/kustomization.yaml | 23 +++++++ .../dashboards/infrastructure/namespaces.json | 0 .../dashboards/infrastructure/nodes.json | 0 .../dashboards/infrastructure/pods.json | 0 .../dashboards/infrastructure/scheduler.json | 0 .../grafana/dashboards/kustomization.yaml | 6 +- .../grafana/dashboards/sre/alerts.json | 0 .../grafana/dashboards/sre/api-latency.json | 0 .../grafana/dashboards/sre/availability.json | 0 .../dashboards/sre/capacity-planning.json | 0 .../grafana/dashboards/sre/error-budget.json | 0 .../grafana/dashboards/sre/kustomization.yaml | 20 ++++++ .../grafana/dashboards/sre/slo.json | 0 .../grafana/datasources/kustomization.yaml | 5 +- .../grafana/datasources/loki.yaml | 25 +++++++ .../grafana/datasources/prometheus.yaml | 27 ++++++++ .../grafana/datasources/tempo.yaml | 26 +++++++ .../kube-prometheus-stack/values-common.yaml | 67 +++++-------------- 32 files changed, 207 insertions(+), 52 deletions(-) create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/ingress-nginx.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/kafka.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/kustomization.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/nginx.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/postgresql.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/redis.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/springboot.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/dashboard-provider.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/api-server.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/cluster-capacity.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/controller-manager.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/etcd.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/kubernetes-cluster.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/kubernetes-overview.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/kustomization.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/namespaces.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/nodes.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/pods.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/scheduler.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/alerts.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/api-latency.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/availability.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/capacity-planning.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/error-budget.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/kustomization.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/slo.json create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/datasources/loki.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/datasources/prometheus.yaml create mode 100644 platform/monitoring/base/kube-prometheus-stack/grafana/datasources/tempo.yaml diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/ingress-nginx.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/ingress-nginx.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/kafka.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/kafka.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/kustomization.yaml new file mode 100644 index 0000000..3f88f61 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/kustomization.yaml @@ -0,0 +1,21 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +configMapGenerator: + +- name: grafana-dashboard-applications + + files: + - springboot.json + - nginx.json + - redis.json + - postgresql.json + - kafka.json + - ingress-nginx.json + + +generatorOptions: + disableNameSuffixHash: true + +commonLabels: + grafana_dashboard: "1" \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/nginx.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/nginx.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/postgresql.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/postgresql.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/redis.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/redis.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/springboot.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/applications/springboot.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/dashboard-provider.yaml b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/dashboard-provider.yaml new file mode 100644 index 0000000..7de3247 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/dashboard-provider.yaml @@ -0,0 +1,39 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: grafana-dashboard-provider + labels: + grafana_dashboard: "1" + +data: + provider.yaml: | + apiVersion: 1 + + providers: + + - name: infrastructure + orgId: 1 + folder: Infrastructure + type: file + disableDeletion: false + editable: false + options: + path: /var/lib/grafana/dashboards/infrastructure + + - name: applications + orgId: 1 + folder: Applications + type: file + disableDeletion: false + editable: false + options: + path: /var/lib/grafana/dashboards/applications + + - name: sre + orgId: 1 + folder: SRE + type: file + disableDeletion: false + editable: false + options: + path: /var/lib/grafana/dashboards/sre \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/api-server.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/api-server.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/cluster-capacity.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/cluster-capacity.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/controller-manager.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/controller-manager.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/etcd.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/etcd.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/kubernetes-cluster.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/kubernetes-cluster.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/kubernetes-overview.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/kubernetes-overview.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/kustomization.yaml new file mode 100644 index 0000000..0bb82b2 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/kustomization.yaml @@ -0,0 +1,23 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +configMapGenerator: + +- name: grafana-dashboard-infrastructure + files: + - kubernetes-cluster.json + - nodes.json + - etcd.json + - kubernetes-overview.json + - cluster-capacity.json + - namespaces.json + - pods.json + - api-server.json + - scheduler.json + - controller-manager.json + +generatorOptions: + disableNameSuffixHash: true + +commonLabels: + grafana_dashboard: "1" \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/namespaces.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/namespaces.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/nodes.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/nodes.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/pods.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/pods.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/scheduler.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/infrastructure/scheduler.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/kustomization.yaml index b1745d7..a70fdac 100644 --- a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/kustomization.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/kustomization.yaml @@ -1,4 +1,8 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization -resources: [] \ No newline at end of file +resources: + - dashboard-provider.yaml + - infrastructure + - applications + - sre \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/alerts.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/alerts.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/api-latency.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/api-latency.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/availability.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/availability.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/capacity-planning.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/capacity-planning.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/error-budget.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/error-budget.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/kustomization.yaml new file mode 100644 index 0000000..5b60396 --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/kustomization.yaml @@ -0,0 +1,20 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +configMapGenerator: + +- name: grafana-dashboard-sre + + files: + - slo.json + - api-latency.json + - alerts.json + - availability.json + - error-budget.json + - capacity-planning.json + +generatorOptions: + disableNameSuffixHash: true + +commonLabels: + grafana_dashboard: "1" \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/slo.json b/platform/monitoring/base/kube-prometheus-stack/grafana/dashboards/sre/slo.json new file mode 100644 index 0000000..e69de29 diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/datasources/kustomization.yaml b/platform/monitoring/base/kube-prometheus-stack/grafana/datasources/kustomization.yaml index b1745d7..d285a06 100644 --- a/platform/monitoring/base/kube-prometheus-stack/grafana/datasources/kustomization.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/grafana/datasources/kustomization.yaml @@ -1,4 +1,7 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization -resources: [] \ No newline at end of file +resources: + - prometheus.yaml + - loki.yaml + - tempo.yaml \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/datasources/loki.yaml b/platform/monitoring/base/kube-prometheus-stack/grafana/datasources/loki.yaml new file mode 100644 index 0000000..361d8ec --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/grafana/datasources/loki.yaml @@ -0,0 +1,25 @@ +apiVersion: v1 +kind: ConfigMap + +metadata: + name: grafana-datasource-loki + + labels: + grafana_datasource: "1" + +data: + loki.yaml: | + apiVersion: 1 + + datasources: + + - name: Loki + uid: loki + + type: loki + + access: proxy + + url: http://loki.monitoring.svc.cluster.local:3100 + + editable: false \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/datasources/prometheus.yaml b/platform/monitoring/base/kube-prometheus-stack/grafana/datasources/prometheus.yaml new file mode 100644 index 0000000..f9c7bfe --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/grafana/datasources/prometheus.yaml @@ -0,0 +1,27 @@ +apiVersion: v1 +kind: ConfigMap + +metadata: + name: grafana-datasource-prometheus + + labels: + grafana_datasource: "1" + +data: + prometheus.yaml: | + apiVersion: 1 + + datasources: + + - name: Prometheus + uid: prometheus + + type: prometheus + + access: proxy + + url: http://kube-prometheus-stack-prometheus.monitoring.svc.cluster.local:9090 + + isDefault: true + + editable: false \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/grafana/datasources/tempo.yaml b/platform/monitoring/base/kube-prometheus-stack/grafana/datasources/tempo.yaml new file mode 100644 index 0000000..014c55d --- /dev/null +++ b/platform/monitoring/base/kube-prometheus-stack/grafana/datasources/tempo.yaml @@ -0,0 +1,26 @@ +apiVersion: v1 +kind: ConfigMap + +metadata: + name: grafana-datasource-tempo + + labels: + grafana_datasource: "1" + +data: + tempo.yaml: | + apiVersion: 1 + + datasources: + + - name: Tempo + + uid: tempo + + type: tempo + + access: proxy + + url: http://tempo.monitoring.svc.cluster.local:3200 + + editable: false \ No newline at end of file diff --git a/platform/monitoring/base/kube-prometheus-stack/values-common.yaml b/platform/monitoring/base/kube-prometheus-stack/values-common.yaml index 7b72927..42af4dd 100644 --- a/platform/monitoring/base/kube-prometheus-stack/values-common.yaml +++ b/platform/monitoring/base/kube-prometheus-stack/values-common.yaml @@ -14,58 +14,30 @@ grafana: storageClassName: gp3 size: 20Gi - additionalDataSources: - - name: Loki - type: loki - access: proxy - url: http://loki.logging.svc.cluster.local:3100 - - defaultDashboardsEnabled: true + # Disable the dashboards bundled with kube-prometheus-stack. + # Dashboards are provisioned from Git via ConfigMaps. + defaultDashboardsEnabled: false sidecar: dashboards: enabled: true searchNamespace: ALL + # Watch ConfigMaps with this label. + label: grafana_dashboard + + # Keep the default label value. + labelValue: "1" + + # Automatically update dashboards when ConfigMaps change. + watchMethod: WATCH + datasources: enabled: true - dashboards: - default: - kubernetes-cluster: - gnetId: 15757 - revision: 42 - datasource: Prometheus - - node-exporter: - gnetId: 1860 - revision: 37 - datasource: Prometheus - - ingress-nginx: - gnetId: 9614 - revision: 1 - datasource: Prometheus - - spring-boot: - gnetId: 12900 - revision: 1 - datasource: Prometheus - - jvm: - gnetId: 4701 - revision: 10 - datasource: Prometheus - - postgres: - gnetId: 9628 - revision: 7 - datasource: Prometheus - - redis: - gnetId: 11835 - revision: 1 - datasource: Prometheus + # Watch datasource ConfigMaps. + label: grafana_datasource + labelValue: "1" prometheus: prometheusSpec: @@ -99,6 +71,7 @@ alertmanager: alertmanagerSpec: retention: 120h + storage: volumeClaimTemplate: spec: @@ -109,11 +82,9 @@ alertmanager: requests: storage: 10Gi - # Use Kubernetes secret for credentials secrets: - alertmanager-notification-secret - config: global: resolve_timeout: 5m @@ -135,7 +106,6 @@ alertmanager: receiver: slack-critical receivers: - - name: default-receiver - name: slack-critical @@ -143,8 +113,7 @@ alertmanager: - api_url_file: /etc/alertmanager/secrets/alertmanager-notification-secret/slack-webhook channel: "#alerts" send_resolved: true - title: >- - {{ .CommonAnnotations.summary }} + title: "{{ .CommonAnnotations.summary }}" - name: email-alerts email_configs: @@ -154,7 +123,6 @@ alertmanager: auth_username: alertmanager@example.com auth_password_file: /etc/alertmanager/secrets/alertmanager-email-secret/password - inhibit_rules: - source_matchers: - severity="critical" @@ -166,7 +134,6 @@ alertmanager: - namespace - alertname - kubeStateMetrics: enabled: true From ff74c9056262f44a4526e5c0b611ca2f76555e41 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Fri, 7 Aug 2026 22:22:28 +0200 Subject: [PATCH 115/122] Updated the README file --- README.md | 738 +++++++++++++++++++++-------------------------------- README1.md | 458 +++++++++++++++++++++++++++++++++ 2 files changed, 746 insertions(+), 450 deletions(-) create mode 100644 README1.md diff --git a/README.md b/README.md index 43c9445..e206ef9 100644 --- a/README.md +++ b/README.md @@ -1,458 +1,296 @@ -# Kubernetes-argocd +# Kubernetes ArgoCD Platform -Building it this way will help you understand not only Kubernetes, but also how production platforms are assembled: GitOps, observability, security, networking, and application instrumentation. +

+ + GitHub Actions Build Status + + ArgoCD GitOps + Kubernetes + AWS EKS + Multi-environment +

-### Architecture +A production-oriented GitOps control plane for deploying, governing, and operating the Ja-Mics application platform across multiple Kubernetes environments. This repository defines the ArgoCD application manifests, environment overlays, and platform services required to reconcile application workloads and shared infrastructure in a secure, repeatable, and auditable way. +This repo works in conjunction with: -### Action Runner Controller (ARC) - Self hosted runner +- Application source code: [ja-mics-ap](https://github.com/Emmy-github-webdev/ja-mics-ap) +- Infrastructure repository: internal enterprise infrastructure platform (AWS/EKS and supporting cloud resources) +- This GitOps repository: [Kubernetes-argocd](https://github.com/Emmy-github-webdev/Kubernetes-argocd) +--- + +## Why this repository exists + +This repository exists to provide a declarative, version-controlled delivery model for enterprise workloads. Instead of applying Kubernetes manifests manually, teams commit desired state into Git, and ArgoCD continuously reconciles the live cluster to match that state. + +This approach improves: + +- Deployment consistency across environments +- Auditability and change traceability +- Faster rollback and recovery +- Security and policy enforcement through Git-based review workflows +- Standardized platform operations for multiple services + +The repository is designed for a multi-service architecture with shared platform components such as ingress, monitoring, logging, tracing, networking, storage, and security policy enforcement. + +--- + +## Drawbacks and considerations + +While GitOps is powerful, it is not without trade-offs: + +- Requires strong Git and CI/CD governance to prevent drift or misconfiguration +- Cluster access and secrets management must be tightly controlled +- ArgoCD introduces another operational dependency in the platform stack +- Multi-environment drift can occur if overlays are not reviewed carefully +- Platform changes can affect many teams if shared components are modified broadly + +These are manageable by using review policies, environment isolation, RBAC controls, and structured platform ownership. + +--- + +## Architecture + +The platform follows a GitOps-first operational model where application manifests and platform definitions are stored in Git and applied by ArgoCD to the target cluster. + +```mermaid +flowchart LR + A[GitHub Repositories] --> B[Infrastructure Repo] + A --> C[ja-mics-ap Source Repo] + A --> D[Kubernetes-argocd GitOps Repo] + + D --> E[ArgoCD ApplicationSets] + E --> F[Dev Cluster] + E --> G[Staging Cluster] + E --> H[Prod Cluster] + + C --> I[Container Image Build] + I --> J[Amazon ECR] + J --> F + J --> G + J --> H + + B --> K[AWS EKS / Networking / Security / Storage] + K --> F + K --> G + K --> H + + F --> L[Applications: user-service, order-service, payment-service, product-service] + G --> L + H --> L + + L --> M[Monitoring / Logging / Tracing / Ingress / Policy] +``` + +### Repository layout + +```text +Kubernetes-argocd/ +├── apps/ +│ ├── user-service/ +│ ├── order-service/ +│ ├── payment-service/ +│ └── product-service/ +├── argocd/ +│ ├── dev/ +│ ├── staging/ +│ └── prod/ +├── infrastructure/ +├── platform/ +│ ├── ingress/ +│ ├── monitoring/ +│ ├── logging/ +│ ├── tracing/ +│ ├── networking/ +│ ├── security/ +│ └── storage/ +├── .github/ +│ └── workflows/ +├── README.md +└── LICENSE (if added for production compliance) ``` - GitHub - │ - │ Workflow Dispatch - ▼ - Actions Runner Controller - (EKS) - │ - Creates ephemeral runner Pods - │ - ▼ - GitHub Runner Pod - (private subnet) - │ - ┌─────────────────┴─────────────────┐ - │ │ - ▼ ▼ -Terraform AWS Provider PostgreSQL Provider - │ │ - ▼ ▼ - AWS APIs Private RDS (5432) + +### Included platform capabilities + +- Kubernetes application deployment via ArgoCD +- Multi-environment overlays for dev, staging, and prod +- Shared ingress and service exposure patterns +- Monitoring with Prometheus and Grafana +- Logging with Loki / Fluent Bit / Promtail +- Distributed tracing with Tempo and OpenTelemetry +- Policy enforcement with Kyverno +- Storage and CSI integrations for AWS-backed workloads +- Network security and ingress governance + +--- + +## Project status + +

+ Status + CI + Deploy + Environments +

+ +- Build status: [GitHub Actions](https://github.com/Emmy-github-webdev/Kubernetes-argocd/actions) +- Coverage: tracked as part of the application CI and release pipeline in the application repository +- Deployment model: GitOps with ArgoCD and Kustomize-based overlays + +--- + +## Quick start guide + +### Prerequisites + +Before deploying or modifying this platform, ensure you have the following: + +- Access to an AWS EKS cluster or equivalent Kubernetes cluster +- ArgoCD installed and bootstrapped in the target cluster +- kubectl configured for cluster access +- GitHub access to the repository and deployment workflows +- AWS credentials with permissions to manage EKS and supporting resources +- A working understanding of Kubernetes, Kustomize, and GitOps workflow practices +- A running application image registry such as Amazon ECR + +### Installation + +1. Clone the repository: + +```bash +git clone https://github.com/Emmy-github-webdev/Kubernetes-argocd.git +cd Kubernetes-argocd +``` + +2. Review the ArgoCD bootstrap definitions under the [argocd](argocd) folder. + +3. Apply the root ArgoCD application for the target environment: + +```bash +kubectl apply -f argocd/dev/root-app.yaml +``` + +4. Validate ArgoCD resources: + +```bash +kubectl get applications -n argocd +kubectl get applicationsets -n argocd ``` -### Steps - -1. Create a GitHub App -- Go to settings -- Developer settings -- GitHub Apps -- New GitHub App -- Permissions - - Repository - - Actions - read/Write - - Contents - Read - - Metadata - Read - - - Organization - - Self-hosted runners - - Read/Write -- Download private-key.pem after creation - private-key.pem. You will need - - App ID - - Installation ID - - Private Key - -2. Create namespace - - -Source Repo -├── user-service -├── order-service -├── payment-service -└── product-service - -↓ - -GitHub Actions - -↓ - -ECR - -↓ - -Kubernetes-argocd Repo -├── apps -│ ├── user-service -│ │ ├── base -| │ | ├── deployment.yaml -| │ | ├── kustomization.yaml -| │ | └── poddistruption.yaml -| │ | └── service.yaml -│ │ └── overlays -| │ | ├── dev -| | | | ├── external-secret-patch.yaml -| | | | ├── Image-patch.yaml -| | | | ├── kustomization.yaml -| │ | ├── staging -| │ | └── prod -│ ├── order-service -│ ├── payment-service -│ └── product-service -| -├── platform - │ - ├── monitoring - │ ├── base - │ │ ├── namespace.yaml - │ │ ├── kustomization.yaml - | │ ├── grafana/ - │ | │ ├── datasources.yaml - │ │ | ├── dashboardproviders.yaml - │ │ | └── dashboards/ - │ │ | ├── kubernetes.json - │ │ | ├── nodes.json - │ │ | ├── ingress-nginx.json - │ │ | ├── springboot.json - │ │ | ├── jvm.json - │ │ | ├── postgres.json - │ │ | └── redis.json - │ │ | - │ | | ├── alertmanager/ - │ │ | | ├── config.yaml - │ │ | | ├── receivers.yaml - │ │ | | ├── routes.yaml - │ │ | | ├── inhibit-rules.yaml - │ │ | └── templates/ - │ │ ├── slack.tmpl - │ │ └── email.tmpl - │ │ ├── servicemonitors/ - │ │ │ ├── order.yaml - │ │ │ ├── user.yaml - │ │ │ ├── payment.yaml - │ │ │ ├── ingress-nginx.yaml - │ │ │ ├── postgres.yaml - │ │ │ ├── redis.yaml - │ │ │ └── product.yaml - │ │ │ - │ │ └── prometheusrules/ - │ │ ├── high-cpu.yaml - │ │ ├── high-memory.yaml - │ │ ├── pod-restarts.yaml - │ │ ├── node-health.yaml - │ │ ├── api-errors.yaml - │ │ ├── latency.yaml - │ │ ├── disk-space.yaml - │ │ ├── application-latency.yaml - │ │ ├── disk-pressure.yaml - │ │ ├── ingress-5xx.yaml - │ │ ├── node-not-ready.yaml - │ │ ├── pod-crashloop.yaml - │ │ ├── postgres-connections.yaml - │ │ ├── redis.yaml - │ │ ├── deployment-unavailable.yaml - │ │ └── database-down.yaml - │ │ ├── recording-rules/ - │ │ │ ├── cluster.yaml - │ │ │ ├── nodes.yaml - │ │ │ ├── workloads.yaml - │ │ │ └── applications.yaml - │ │ ├── exporters/ - │ │ │ ├── blackbox-exporter.yaml - │ │ │ ├── postgres-exporter.yaml - │ │ │ ├── Redis-exporter.yaml - │ │ │ └── jmx-exporter.yaml - │ │ ├── exporters/ - │ │ │ └── allow-prometheus.yaml - │ │ - │ └── overlays - │ ├── dev - │ │ ├── kustomization.yaml - │ │ └── values-patch.yaml - │ │ - │ ├── staging - │ └── prod -│ - logging/ - ├── base/ - │ ├── namespace.yaml - │ ├── kustomization.yaml - │ │ - │ ├── loki/ - │ │ ├── helm-release.yaml - │ │ └── values.yaml - │ │ - │ ├── promtail/ - │ │ ├── helm-release.yaml - │ │ └── values.yaml - │ │ - │ ├── fluent-bit/ - │ │ ├── helm-release.yaml - │ │ └── values.yaml - │ │ - │ ├── log-retention/ - │ │ └── retention.yaml - │ │ - │ └── networkpolicy/ - │ └── allow-logging.yaml - │ - └── overlays/ - ├── dev/ - ├── staging/ - └── prod/ -| -| - tracing/ - ├── base/ - │ ├── namespace.yaml - │ ├── kustomization.yaml - │ │ - │ ├── tempo/ - │ │ ├── helm-release.yaml - │ │ └── values.yaml - │ │ - │ ├── opentelemetry-collector/ - │ │ ├── helm-release.yaml - │ │ ├── values.yaml - │ │ └── pipelines.yaml - │ │ - │ └── networkpolicy/ - │ └── allow-tracing.yaml - │ - └── overlays/ - ├── dev/ - ├── staging/ - └── prod/ -| -| - ingress/ - ├── base/ - │ ├── namespace.yaml - │ ├── kustomization.yaml - │ │ - │ ├── aws-load-balancer-controller/ - │ │ ├── helm-release.yaml - │ │ └── values.yaml - │ │ - │ ├── ingress-nginx/ - │ │ ├── helm-release.yaml - │ │ └── values.yaml - │ │ - │ ├── external-dns/ - │ │ ├── helm-release.yaml - │ │ └── values.yaml - │ │ - │ └── cert-manager/ - │ ├── helm-release.yaml - │ ├── values.yaml - │ └── clusterissuers/ - │ ├── letsencrypt-prod.yaml - │ └── letsencrypt-staging.yaml - │ - └── overlays/ - ├── dev/ - ├── staging/ - └── prod/ -| - security/ - ├── base/ - │ ├── namespace.yaml - │ ├── kustomization.yaml - │ │ - │ ├── kyverno/ - │ │ ├── helm-release.yaml - │ │ └── values.yaml - │ │ - │ ├── external-secrets/ - │ │ ├── helm-release.yaml - │ │ └── values.yaml - │ │ - │ ├── sealed-secrets/ - │ │ ├── helm-release.yaml - │ │ └── values.yaml - │ │ - │ ├── networkpolicies/ - │ │ - │ ├── podsecurity/ - │ │ - │ └── policies/ - │ ├── restrict-privileged.yaml - │ ├── require-limits.yaml - │ ├── require-probes.yaml - │ └── disallow-latest-tag.yaml - │ - └── overlays/ - ├── dev/ - ├── staging/ - └── prod/ -| -| - networking/ - ├── base/ - │ ├── namespace.yaml - │ ├── kustomization.yaml - │ │ - │ ├── cni/ - │ │ - │ ├── metrics-server/ - │ │ ├── helm-release.yaml - │ │ └── values.yaml - │ │ - │ ├── gateway-api/ - │ │ - │ ├── networkpolicies/ - │ │ - │ └── dns/ - │ └── coredns-patch.yaml - │ - └── overlays/ - ├── dev/ - ├── staging/ - └── prod/ -| -| -storage/ -├── base/ -│ ├── namespace.yaml -│ ├── kustomization.yaml -│ │ -│ ├── ebs-csi-driver/ -│ │ ├── helm-release.yaml -│ │ └── values.yaml -│ │ -│ ├── efs-csi-driver/ -│ │ ├── helm-release.yaml -│ │ └── values.yaml -│ │ -│ ├── storageclasses/ -│ │ ├── gp3.yaml -│ │ ├── efs.yaml -│ │ └── io2.yaml -│ │ -│ ├── volume-snapshots/ -│ │ ├── snapshotclass.yaml -│ │ └── schedules.yaml -│ │ -│ └── backup/ -│ ├── velero/ -│ │ ├── helm-release.yaml -│ │ └── values.yaml -│ └── backup-schedules.yaml -│ -└── overlays/ - ├── dev/ - ├── staging/ - └── prod/ -| -|___argocd -│ ├── dev -│ | ├── applicationset-apps.yaml -| | ├── applicationset-infra.yaml -| | ├── applicationset-monitoring.yaml -│ | └── root-app.yaml -| | -│ ├── prod -| | -│ ├── staging -| -|___infrastructure -│ | ├── dev -│ | | ├── postgres-master-secret.yaml -│ | | ├── order-db-secret.yaml -│ | | ├── user-db-secret.yaml -│ | | ├── payment-db-secret.yaml -│ | | ├── product-db-secret.yaml -│ | | └── postgres-bootstrap-job.yaml -│ | | ├── cluster-secret-store.yaml -│ | | ├── ingress.yaml -│ | | └── namespace-database.yaml -│ | ├── prod -│ | | -│ | ├── staging - - -↓ - -EKS -### App Repo GitHub Action - -name: Build - -on: - push: - branches: - - main - -jobs: - - build: -9949494944994/C runs-on: ubuntu-latest - - permissions: - id-token: write - contents: read - - steps: - - uses: actions/checkout@v4 - - - uses: aws-actions/configure-aws-credentials@v4 - with: - role-to-assume: arn:aws:iam:::role/github-ecr-push - aws-region: us-east-1 - - - uses: aws-actions/amazon-ecr-login@v2 - - - run: | - docker build -t my-app:${GITHUB_SHA} . - docker tag my-app:${GITHUB_SHA} $ECR_REPO:${GITHUB_SHA} - docker push $ECR_REPO:${GITHUB_SHA} - - - -Update GitOps repo - -After push - -- name: Update GitOps - run: | - yq -i '.spec.template.spec.containers[0].image = "'"$ECR_REPO:${GITHUB_SHA}"'"' deployment.yaml - - git commit -am "Deploy ${GITHUB_SHA}" - git push - - - - - -infrastructure - -├── dev -│ ├── postgres-master-secret.yaml -│ ├── order-db-secret.yaml -│ ├── user-db-secret.yaml -│ ├── payment-db-secret.yaml -│ ├── product-db-secret.yaml -│ └── postgres-bootstrap-job.yaml -│ ├── cluster-secret-store.yaml -│ ├── ingress.yaml -│ └── namespace-database.yaml - - -platform/ -├── monitoring/ -│ ├── base/ -│ └── overlays/ -│ ├── dev/ -│ ├── staging/ -│ └── prod/ -├── logging/ -│ ├── base/ -│ └── overlays/ -│ ├── dev/ -│ ├── staging/ -│ └── prod/ -├── networking/ -│ ├── base/ -│ └── overlays/ -│ ├── dev/ -│ ├── staging/ -│ └── prod/ -└── tracing/ -| ├── base/ -| └── overlays/ -| ├── dev/ -| ├── staging/ -| └── prod/ -├── overlays/ -│ ├── dev/ -│ ├── staging/ -│ └── prod/ \ No newline at end of file +5. Confirm the platform and application workloads are reconciled successfully. + +--- + +## Basic usage examples + +### Apply the development GitOps root + +```bash +kubectl apply -f argocd/dev/root-app.yaml +``` + +### Inspect ArgoCD application state + +```bash +kubectl get application -A +kubectl describe application dev-platform-root -n argocd +``` + +### Synced environment structure + +This repository supports environment-specific application layering via overlays: + +```bash +argocd/dev/ +argocd/staging/ +argocd/prod/ +``` + +Each environment can reconcile different application versions, settings, and infrastructure constraints while preserving a common platform foundation. + +--- + +## Architecture and deployment flow + +The deployment flow is intentionally simple and enterprise-friendly: + +1. Application source is maintained in the application repo. +2. Containers are built and pushed to the registry. +3. This GitOps repository declares the target state. +4. ArgoCD compares live cluster state with Git state. +5. Kubernetes resources are reconciled automatically. +6. Platform components and service workloads remain consistent across environments. + +This repository is the control plane layer that connects application delivery to operational governance. + +--- + +## Comprehensive documentation + +For deeper implementation details, refer to the structured repository folders and environment manifests: + +- [argocd](argocd) +- [apps](apps) +- [platform](platform) +- [infrastructure](infrastructure) +- [GitHub Actions workflow](.github/workflows/bootstrap-argocd.yml) + +This repository is intentionally organized so platform engineers, DevOps teams, and application teams can work from a common system of record. + +--- + +## Contributing guidelines + +Contributions are welcome. To keep the platform stable, please follow these norms: + +- Create feature branches from the main branch +- Keep changes scoped and environment-aware +- Validate YAML and Kustomize manifests before submission +- Use clear commit messages and meaningful PR descriptions +- Review security, networking, and observability impact before merging +- Ensure environment-specific changes are intentional and supported by the appropriate overlay + +Please open a pull request against the main branch and include a concise summary of the operational impact. + +--- + +## License + +This repository currently does not include a public license file in the root directory. Before production release or external distribution, it is recommended to add an appropriate enterprise license such as MIT, Apache 2.0, or a company-specific policy. + +If you are preparing for open-source publication, add a LICENSE file and update this section to match the selected license. + +--- + +## Technologies used + +- Kubernetes +- ArgoCD +- Kustomize +- GitHub Actions +- AWS EKS +- Prometheus +- Grafana +- Loki +- Tempo +- OpenTelemetry +- Kyverno +- NGINX Ingress / AWS load balancer patterns +- External Secrets / Secret Store integrations +- Docker / containerized microservices + +--- + +## Repository links + +- GitHub repository: [Kubernetes-argocd](https://github.com/Emmy-github-webdev/Kubernetes-argocd) +- GitHub Actions: [Workflow runs](https://github.com/Emmy-github-webdev/Kubernetes-argocd/actions) +- Application source repo: [ja-mics-ap](https://github.com/Emmy-github-webdev/ja-mics-ap) +- Infrastructure repo: enterprise internal infrastructure repository + +--- + +## Summary + +This repository is the GitOps backbone for an enterprise Kubernetes platform. It provides a secure, scalable, and auditable way to manage application delivery, platform components, and environment consistency across multiple deployments. The result is a modern operating model that fits the expectations of enterprise DevOps, platform engineering, and cloud-native delivery teams. diff --git a/README1.md b/README1.md new file mode 100644 index 0000000..43c9445 --- /dev/null +++ b/README1.md @@ -0,0 +1,458 @@ +# Kubernetes-argocd + +Building it this way will help you understand not only Kubernetes, but also how production platforms are assembled: GitOps, observability, security, networking, and application instrumentation. + +### Architecture + + +### Action Runner Controller (ARC) - Self hosted runner + +``` + GitHub + │ + │ Workflow Dispatch + ▼ + Actions Runner Controller + (EKS) + │ + Creates ephemeral runner Pods + │ + ▼ + GitHub Runner Pod + (private subnet) + │ + ┌─────────────────┴─────────────────┐ + │ │ + ▼ ▼ +Terraform AWS Provider PostgreSQL Provider + │ │ + ▼ ▼ + AWS APIs Private RDS (5432) +``` + +### Steps + +1. Create a GitHub App +- Go to settings +- Developer settings +- GitHub Apps +- New GitHub App +- Permissions + - Repository + - Actions - read/Write + - Contents - Read + - Metadata - Read + + - Organization + - Self-hosted runners + - Read/Write +- Download private-key.pem after creation - private-key.pem. You will need + - App ID + - Installation ID + - Private Key + +2. Create namespace + + +Source Repo +├── user-service +├── order-service +├── payment-service +└── product-service + +↓ + +GitHub Actions + +↓ + +ECR + +↓ + +Kubernetes-argocd Repo +├── apps +│ ├── user-service +│ │ ├── base +| │ | ├── deployment.yaml +| │ | ├── kustomization.yaml +| │ | └── poddistruption.yaml +| │ | └── service.yaml +│ │ └── overlays +| │ | ├── dev +| | | | ├── external-secret-patch.yaml +| | | | ├── Image-patch.yaml +| | | | ├── kustomization.yaml +| │ | ├── staging +| │ | └── prod +│ ├── order-service +│ ├── payment-service +│ └── product-service +| +├── platform + │ + ├── monitoring + │ ├── base + │ │ ├── namespace.yaml + │ │ ├── kustomization.yaml + | │ ├── grafana/ + │ | │ ├── datasources.yaml + │ │ | ├── dashboardproviders.yaml + │ │ | └── dashboards/ + │ │ | ├── kubernetes.json + │ │ | ├── nodes.json + │ │ | ├── ingress-nginx.json + │ │ | ├── springboot.json + │ │ | ├── jvm.json + │ │ | ├── postgres.json + │ │ | └── redis.json + │ │ | + │ | | ├── alertmanager/ + │ │ | | ├── config.yaml + │ │ | | ├── receivers.yaml + │ │ | | ├── routes.yaml + │ │ | | ├── inhibit-rules.yaml + │ │ | └── templates/ + │ │ ├── slack.tmpl + │ │ └── email.tmpl + │ │ ├── servicemonitors/ + │ │ │ ├── order.yaml + │ │ │ ├── user.yaml + │ │ │ ├── payment.yaml + │ │ │ ├── ingress-nginx.yaml + │ │ │ ├── postgres.yaml + │ │ │ ├── redis.yaml + │ │ │ └── product.yaml + │ │ │ + │ │ └── prometheusrules/ + │ │ ├── high-cpu.yaml + │ │ ├── high-memory.yaml + │ │ ├── pod-restarts.yaml + │ │ ├── node-health.yaml + │ │ ├── api-errors.yaml + │ │ ├── latency.yaml + │ │ ├── disk-space.yaml + │ │ ├── application-latency.yaml + │ │ ├── disk-pressure.yaml + │ │ ├── ingress-5xx.yaml + │ │ ├── node-not-ready.yaml + │ │ ├── pod-crashloop.yaml + │ │ ├── postgres-connections.yaml + │ │ ├── redis.yaml + │ │ ├── deployment-unavailable.yaml + │ │ └── database-down.yaml + │ │ ├── recording-rules/ + │ │ │ ├── cluster.yaml + │ │ │ ├── nodes.yaml + │ │ │ ├── workloads.yaml + │ │ │ └── applications.yaml + │ │ ├── exporters/ + │ │ │ ├── blackbox-exporter.yaml + │ │ │ ├── postgres-exporter.yaml + │ │ │ ├── Redis-exporter.yaml + │ │ │ └── jmx-exporter.yaml + │ │ ├── exporters/ + │ │ │ └── allow-prometheus.yaml + │ │ + │ └── overlays + │ ├── dev + │ │ ├── kustomization.yaml + │ │ └── values-patch.yaml + │ │ + │ ├── staging + │ └── prod +│ + logging/ + ├── base/ + │ ├── namespace.yaml + │ ├── kustomization.yaml + │ │ + │ ├── loki/ + │ │ ├── helm-release.yaml + │ │ └── values.yaml + │ │ + │ ├── promtail/ + │ │ ├── helm-release.yaml + │ │ └── values.yaml + │ │ + │ ├── fluent-bit/ + │ │ ├── helm-release.yaml + │ │ └── values.yaml + │ │ + │ ├── log-retention/ + │ │ └── retention.yaml + │ │ + │ └── networkpolicy/ + │ └── allow-logging.yaml + │ + └── overlays/ + ├── dev/ + ├── staging/ + └── prod/ +| +| + tracing/ + ├── base/ + │ ├── namespace.yaml + │ ├── kustomization.yaml + │ │ + │ ├── tempo/ + │ │ ├── helm-release.yaml + │ │ └── values.yaml + │ │ + │ ├── opentelemetry-collector/ + │ │ ├── helm-release.yaml + │ │ ├── values.yaml + │ │ └── pipelines.yaml + │ │ + │ └── networkpolicy/ + │ └── allow-tracing.yaml + │ + └── overlays/ + ├── dev/ + ├── staging/ + └── prod/ +| +| + ingress/ + ├── base/ + │ ├── namespace.yaml + │ ├── kustomization.yaml + │ │ + │ ├── aws-load-balancer-controller/ + │ │ ├── helm-release.yaml + │ │ └── values.yaml + │ │ + │ ├── ingress-nginx/ + │ │ ├── helm-release.yaml + │ │ └── values.yaml + │ │ + │ ├── external-dns/ + │ │ ├── helm-release.yaml + │ │ └── values.yaml + │ │ + │ └── cert-manager/ + │ ├── helm-release.yaml + │ ├── values.yaml + │ └── clusterissuers/ + │ ├── letsencrypt-prod.yaml + │ └── letsencrypt-staging.yaml + │ + └── overlays/ + ├── dev/ + ├── staging/ + └── prod/ +| + security/ + ├── base/ + │ ├── namespace.yaml + │ ├── kustomization.yaml + │ │ + │ ├── kyverno/ + │ │ ├── helm-release.yaml + │ │ └── values.yaml + │ │ + │ ├── external-secrets/ + │ │ ├── helm-release.yaml + │ │ └── values.yaml + │ │ + │ ├── sealed-secrets/ + │ │ ├── helm-release.yaml + │ │ └── values.yaml + │ │ + │ ├── networkpolicies/ + │ │ + │ ├── podsecurity/ + │ │ + │ └── policies/ + │ ├── restrict-privileged.yaml + │ ├── require-limits.yaml + │ ├── require-probes.yaml + │ └── disallow-latest-tag.yaml + │ + └── overlays/ + ├── dev/ + ├── staging/ + └── prod/ +| +| + networking/ + ├── base/ + │ ├── namespace.yaml + │ ├── kustomization.yaml + │ │ + │ ├── cni/ + │ │ + │ ├── metrics-server/ + │ │ ├── helm-release.yaml + │ │ └── values.yaml + │ │ + │ ├── gateway-api/ + │ │ + │ ├── networkpolicies/ + │ │ + │ └── dns/ + │ └── coredns-patch.yaml + │ + └── overlays/ + ├── dev/ + ├── staging/ + └── prod/ +| +| +storage/ +├── base/ +│ ├── namespace.yaml +│ ├── kustomization.yaml +│ │ +│ ├── ebs-csi-driver/ +│ │ ├── helm-release.yaml +│ │ └── values.yaml +│ │ +│ ├── efs-csi-driver/ +│ │ ├── helm-release.yaml +│ │ └── values.yaml +│ │ +│ ├── storageclasses/ +│ │ ├── gp3.yaml +│ │ ├── efs.yaml +│ │ └── io2.yaml +│ │ +│ ├── volume-snapshots/ +│ │ ├── snapshotclass.yaml +│ │ └── schedules.yaml +│ │ +│ └── backup/ +│ ├── velero/ +│ │ ├── helm-release.yaml +│ │ └── values.yaml +│ └── backup-schedules.yaml +│ +└── overlays/ + ├── dev/ + ├── staging/ + └── prod/ +| +|___argocd +│ ├── dev +│ | ├── applicationset-apps.yaml +| | ├── applicationset-infra.yaml +| | ├── applicationset-monitoring.yaml +│ | └── root-app.yaml +| | +│ ├── prod +| | +│ ├── staging +| +|___infrastructure +│ | ├── dev +│ | | ├── postgres-master-secret.yaml +│ | | ├── order-db-secret.yaml +│ | | ├── user-db-secret.yaml +│ | | ├── payment-db-secret.yaml +│ | | ├── product-db-secret.yaml +│ | | └── postgres-bootstrap-job.yaml +│ | | ├── cluster-secret-store.yaml +│ | | ├── ingress.yaml +│ | | └── namespace-database.yaml +│ | ├── prod +│ | | +│ | ├── staging + + +↓ + +EKS +### App Repo GitHub Action + +name: Build + +on: + push: + branches: + - main + +jobs: + + build: +9949494944994/C runs-on: ubuntu-latest + + permissions: + id-token: write + contents: read + + steps: + - uses: actions/checkout@v4 + + - uses: aws-actions/configure-aws-credentials@v4 + with: + role-to-assume: arn:aws:iam:::role/github-ecr-push + aws-region: us-east-1 + + - uses: aws-actions/amazon-ecr-login@v2 + + - run: | + docker build -t my-app:${GITHUB_SHA} . + docker tag my-app:${GITHUB_SHA} $ECR_REPO:${GITHUB_SHA} + docker push $ECR_REPO:${GITHUB_SHA} + + + +Update GitOps repo + +After push + +- name: Update GitOps + run: | + yq -i '.spec.template.spec.containers[0].image = "'"$ECR_REPO:${GITHUB_SHA}"'"' deployment.yaml + + git commit -am "Deploy ${GITHUB_SHA}" + git push + + + + + +infrastructure + +├── dev +│ ├── postgres-master-secret.yaml +│ ├── order-db-secret.yaml +│ ├── user-db-secret.yaml +│ ├── payment-db-secret.yaml +│ ├── product-db-secret.yaml +│ └── postgres-bootstrap-job.yaml +│ ├── cluster-secret-store.yaml +│ ├── ingress.yaml +│ └── namespace-database.yaml + + +platform/ +├── monitoring/ +│ ├── base/ +│ └── overlays/ +│ ├── dev/ +│ ├── staging/ +│ └── prod/ +├── logging/ +│ ├── base/ +│ └── overlays/ +│ ├── dev/ +│ ├── staging/ +│ └── prod/ +├── networking/ +│ ├── base/ +│ └── overlays/ +│ ├── dev/ +│ ├── staging/ +│ └── prod/ +└── tracing/ +| ├── base/ +| └── overlays/ +| ├── dev/ +| ├── staging/ +| └── prod/ +├── overlays/ +│ ├── dev/ +│ ├── staging/ +│ └── prod/ \ No newline at end of file From 3bc032a737899047c5900f2cb21e41141c7e47b9 Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Fri, 7 Aug 2026 22:57:08 +0200 Subject: [PATCH 116/122] Added verification steps after deployment --- DEPLOYMENT_VERIFICATION.md | 479 +++++++++++++++++++++++++++++++++++++ README.md | 79 ++++++ 2 files changed, 558 insertions(+) create mode 100644 DEPLOYMENT_VERIFICATION.md diff --git a/DEPLOYMENT_VERIFICATION.md b/DEPLOYMENT_VERIFICATION.md new file mode 100644 index 0000000..3fe184d --- /dev/null +++ b/DEPLOYMENT_VERIFICATION.md @@ -0,0 +1,479 @@ +# Post-Deployment Verification and Troubleshooting + +This guide describes the standard verification flow after deploying the Kubernetes platform with ArgoCD. It covers cluster validation, application health checks, Kubernetes object inspection, AWS authentication, and common troubleshooting steps for the GitOps deployment lifecycle. + +--- + +## 1. Confirm you are connected to the correct EKS cluster + +Start by verifying the active Kubernetes context: + +```bash +kubectl config current-context +``` + +You want the context to point to the correct AWS EKS cluster. If the command returns an unexpected cluster or no value, update the kubeconfig. + +### Check cluster reachability + +```bash +kubectl get nodes +``` + +Expected result: + +```text +NAME STATUS ROLES AGE +ip-10-0-1-45.ec2.internal Ready 3h +``` + +If you see any of the following: + +```text +No resources found +Unable to connect to the server +``` + +Then the cluster is either incorrect or kubeconfig is stale. + +### Refresh kubeconfig + +```bash +aws eks update-kubeconfig \ + --region \ + --name +``` + +Then confirm again: + +```bash +kubectl config current-context +kubectl get nodes +``` + +--- + +## 2. Verify AWS credentials and cluster identity + +Check the AWS identity used by your local environment: + +```bash +aws sts get-caller-identity +``` + +This confirms whether your AWS session is authenticated and associated with the expected account. + +Verify the EKS cluster is visible in the target region: + +```bash +aws eks list-clusters --region us-east-1 +``` + +If the AWS authentication plugin is failing, test it directly: + +```bash +aws eks get-token \ + --region us-east-1 \ + --cluster-name +``` + +If this command fails, the issue is usually related to: + +- expired AWS credentials +- incorrect IAM role assignment +- wrong AWS region +- missing CLI configuration + +--- + +## 3. Check whether ArgoCD applications exist + +Verify the ArgoCD Application resources: + +```bash +kubectl get applications -A +``` + +Expected output should look similar to: + +```text +NAMESPACE NAME SYNC STATUS HEALTH STATUS +argocd user-service Synced Healthy +argocd order-service Synced Healthy +argocd monitoring Synced Healthy +``` + +If no Application resources are present, the root application or ApplicationSet may not have been applied successfully. + +If you use the ArgoCD CLI, you can also verify with: + +```bash +argocd app list +``` + +An `OutOfSync` or missing application state usually means the manifests were not reconciled yet. + +--- + +## 4. Validate the ArgoCD control plane + +Check the ArgoCD namespace: + +```bash +kubectl get pods -n argocd +``` + +You should see components such as: + +```text +argocd-server +argocd-repo-server +argocd-application-controller +argocd-applicationset-controller +``` + +If the namespace does not exist, ArgoCD may not have been installed or bootstrapped correctly. + +Inspect the ArgoCD controller logs for reconciliation problems: + +```bash +kubectl logs -n argocd deployment/argocd-application-controller +``` + +This often reveals: + +- invalid Kustomize configuration +- missing namespaces +- invalid Git repository access +- manifest generation issues +- sync failures caused by bad YAML or resource naming + +If needed, force a refresh: + +```bash +kubectl annotate application \ + -n argocd \ + argocd.argoproj.io/refresh=hard \ + --overwrite +``` + +Inspect the application state: + +```bash +kubectl describe application -n argocd +``` + +--- + +## 5. Check project namespaces + +List all namespaces: + +```bash +kubectl get ns +``` + +You should see namespaces similar to: + +```text +argocd +user +order +payment +product +monitoring +``` + +If expected namespaces are missing, verify whether ArgoCD has created them from the applied manifests. + +--- + +## 6. Verify deployments and service availability + +Check all deployments across namespaces: + +```bash +kubectl get deployments -A +``` + +Expected pattern: + +```text +NAMESPACE NAME READY +order order-service 1/1 +user user-service 1/1 +``` + +If deployments exist but pods are not ready, inspect the deployment resource: + +```bash +kubectl describe deployment -n +``` + +Check pods: + +```bash +kubectl get pods -A +``` + +Common problem states: + +- Pending +- ImagePullBackOff +- CrashLoopBackOff +- Init:Error + +When a pod is unhealthy, inspect it: + +```bash +kubectl describe pod -n +kubectl logs -n +``` + +To view the previous container logs if the app restarted: + +```bash +kubectl logs -n --previous +``` + +--- + +## 7. Common deployment troubleshooting + +### Deployment exists but no pods are running + +This often indicates a scheduling or image issue. Verify the deployment status and inspect events: + +```bash +kubectl describe deployment -n +``` + +Look for problems such as: + +- insufficient resources +- image pull failures +- invalid volume mounts +- readiness probe failures +- node pressure or taints + +### Pods are stuck in Pending + +Check node capacity and scheduling constraints: + +```bash +kubectl get nodes +kubectl describe node +``` + +### Image pull failures + +```bash +kubectl describe pod -n +``` + +Typical causes include: + +- private ECR image permissions +- wrong image name or tag +- registry authentication issue + +### CrashLoopBackOff + +```bash +kubectl logs -n +``` + +Check whether the process is failing because of: + +- application startup errors +- missing environment variables +- secret/config map issues +- database connectivity failures + +--- + +## 8. Restart workloads after a failed sync or config change + +To restart a specific deployment: + +```bash +kubectl rollout restart deployment -n +``` + +For multiple services: + +```bash +kubectl rollout restart deployment order-service -n +kubectl rollout restart deployment payment-service -n +kubectl rollout restart deployment product-service -n +kubectl rollout restart deployment user-service -n +``` + +Restart all deployments in a namespace: + +```bash +kubectl rollout restart deployment -n +``` + +Monitor rollout status: + +```bash +kubectl rollout status deployment/ -n +``` + +--- + +## 9. Kyverno troubleshooting + +If Kyverno is causing issues, start by checking its namespace and workloads: + +```bash +kubectl get pods -n kyverno +``` + +Temporarily scale Kyverno down if needed: + +```bash +kubectl scale deployment -n kyverno --all --replicas=0 +``` + +Confirm pods are removed: + +```bash +kubectl get pods -n kyverno +``` + +Check Helm release records: + +```bash +kubectl get secret -n kyverno | grep sh.helm.release +``` + +If the Helm release metadata is corrupt, remove it: + +```bash +kubectl delete secret -n kyverno sh.helm.release.v1.kyverno.v1 +``` + +Disable Kyverno webhooks if needed: + +```bash +kubectl get validatingwebhookconfiguration | grep kyverno +kubectl get mutatingwebhookconfiguration | grep kyverno +``` + +Delete problematic resources if they are not recoverable: + +```bash +kubectl delete mutatingwebhookconfiguration \ + kyverno-policy-mutating-webhook-cfg \ + kyverno-resource-mutating-webhook-cfg \ + kyverno-verify-mutating-webhook-cfg + +kubectl delete validatingwebhookconfiguration \ + kyverno-cel-exception-validating-webhook-cfg \ + kyverno-cleanup-validating-webhook-cfg \ + kyverno-exception-validating-webhook-cfg \ + kyverno-global-context-validating-webhook-cfg \ + kyverno-policy-validating-webhook-cfg \ + kyverno-resource-validating-webhook-cfg \ + kyverno-ttl-validating-webhook-cfg +``` + +Finally, confirm Kyverno has been removed cleanly: + +```bash +kubectl get all -n kyverno +``` + +--- + +## 10. Monitoring and observability checks + +Check whether Prometheus and Grafana pods are running: + +```bash +kubectl get pods -n monitoring +``` + +Check exposed services: + +```bash +kubectl get svc -n monitoring +``` + +Port-forward Grafana locally: + +```bash +kubectl port-forward -n monitoring svc/kube-prometheus-stack-grafana 3000:80 +``` + +Open: + +```text +http://localhost:3000 +``` + +Retrieve the admin password: + +```bash +kubectl get secret -n monitoring \ + kube-prometheus-stack-grafana \ + -o jsonpath="{.data.admin-password}" | base64 --decode && echo +``` + +Port-forward Prometheus locally: + +```bash +kubectl port-forward -n monitoring svc/kube-prometheus-stack-prometheus 9090:9090 +``` + +Open: + +```text +http://localhost:9090 +``` + +--- + +## 11. Final deployment validation checklist + +Use this quick checklist after every deployment: + +```bash +kubectl config current-context +kubectl get nodes +kubectl get applications -A +kubectl get pods -A +kubectl get deployments -A +kubectl get svc -A +kubectl get ns +``` + +At minimum, the environment should show: + +- connected cluster context +- healthy nodes +- ArgoCD applications present +- expected namespaces created +- deployments ready +- pods running without crash loops +- platform services healthy + +--- + +## 12. Troubleshooting summary + +If the deployment is not working, follow this order: + +1. Confirm the correct cluster and kubeconfig +2. Verify AWS identity and EKS access +3. Check ArgoCD application presence and sync state +4. Inspect ArgoCD controller logs +5. Check namespaces, deployments, and pods +6. Review pod logs and events +7. Restart the affected deployment if needed +8. Validate monitoring services for platform health +9. Resolve Kyverno or policy issues when relevant + +This methodical approach quickly narrows the issue to either cluster access, ArgoCD reconciliation, Kubernetes resource health, or application runtime failures. diff --git a/README.md b/README.md index e206ef9..1cdd354 100644 --- a/README.md +++ b/README.md @@ -291,6 +291,85 @@ If you are preparing for open-source publication, add a LICENSE file and update --- +## Deployment verification + +After deployment, confirm the platform is healthy with the following checks. + +### 1. Verify cluster context and connectivity + +```bash +kubectl config current-context +kubectl get nodes +``` + +If you see `No resources found` or `Unable to connect to the server`, refresh the kubeconfig: + +```bash +aws eks update-kubeconfig \ + --region \ + --name +``` + +### 2. Check ArgoCD and application state + +```bash +kubectl get applications -A +kubectl get pods -n argocd +``` + +You should see ArgoCD pods and synced application resources in the `argocd` namespace. + +### 3. Verify namespaces and workloads + +```bash +kubectl get ns +kubectl get deployments -A +kubectl get pods -A +``` + +If pods are stuck in `Pending`, `ImagePullBackOff`, or `CrashLoopBackOff`, inspect the pod and logs: + +```bash +kubectl describe pod -n +kubectl logs -n +``` + +### 4. Troubleshoot common issues + +```bash +kubectl logs -n argocd deployment/argocd-application-controller +kubectl describe deployment -n +``` + +Typical causes include invalid Kustomize configuration, missing namespaces, image pull errors, secret issues, or Git access problems. + +### 5. Restart workloads if necessary + +```bash +kubectl rollout restart deployment -n +``` + +### 6. Validate monitoring stack + +```bash +kubectl get pods -n monitoring +kubectl get svc -n monitoring +``` + +For Grafana: + +```bash +kubectl port-forward -n monitoring svc/kube-prometheus-stack-grafana 3000:80 +``` + +Then open: + +```text +http://localhost:3000 +``` + +--- + ## Summary This repository is the GitOps backbone for an enterprise Kubernetes platform. It provides a secure, scalable, and auditable way to manage application delivery, platform components, and environment consistency across multiple deployments. The result is a modern operating model that fits the expectations of enterprise DevOps, platform engineering, and cloud-native delivery teams. From 6adba9ee4b537552e9abee67b07c70fe827fa34a Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Mon, 10 Aug 2026 09:52:59 +0200 Subject: [PATCH 117/122] Added VPC and ACM ARN --- infrastructure/overlay/dev/ingress.yaml | 2 +- .../overlays/dev/aws-load-balancer-controller-patch.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/infrastructure/overlay/dev/ingress.yaml b/infrastructure/overlay/dev/ingress.yaml index b2ffdfd..13ad1f8 100644 --- a/infrastructure/overlay/dev/ingress.yaml +++ b/infrastructure/overlay/dev/ingress.yaml @@ -11,7 +11,7 @@ metadata: # HTTPS configuration alb.ingress.kubernetes.io/listen-ports: '[{"HTTP":80},{"HTTPS":443}]' - alb.ingress.kubernetes.io/certificate-arn: arn:aws:acm:us-east-1:579871530627:certificate/77c8e69f-b53a-446c-84d6-98eb1ff8a36c + alb.ingress.kubernetes.io/certificate-arn: arn:aws:acm:us-east-1:579871530627:certificate/220f82b0-2c72-4b01-b620-741cfbba00d9 # Redirect HTTP to HTTPS alb.ingress.kubernetes.io/ssl-redirect: '443' diff --git a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml index 54ef86f..e863a32 100644 --- a/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml +++ b/platform/ingress/overlays/dev/aws-load-balancer-controller-patch.yaml @@ -14,7 +14,7 @@ spec: values: | clusterName: eks-dev-cluster region: us-east-1 - vpcId: vpc-0195ddfde2538cf9a + vpcId: vpc-06601a547622eb138 serviceAccount: create: true From 48b3928cd19273e4c9ea3eed35957b02a53be843 Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Mon, 10 Aug 2026 08:11:30 +0000 Subject: [PATCH 118/122] Promote payment-service to 75c566e3063d58803f614facda8a3a6e0df6e812 --- apps/payment-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/payment-service/overlays/dev/kustomization.yaml b/apps/payment-service/overlays/dev/kustomization.yaml index 4345c35..cac6480 100644 --- a/apps/payment-service/overlays/dev/kustomization.yaml +++ b/apps/payment-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/payment-service - newTag: 556f5d948568e14edc2d380274c0127628db58bf + newTag: 75c566e3063d58803f614facda8a3a6e0df6e812 From 99aceb91bdd01041fa2b41c3256596aa0a985c0d Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Mon, 10 Aug 2026 08:11:33 +0000 Subject: [PATCH 119/122] Promote order-service to 75c566e3063d58803f614facda8a3a6e0df6e812 --- apps/order-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/order-service/overlays/dev/kustomization.yaml b/apps/order-service/overlays/dev/kustomization.yaml index 2e118c2..589e46e 100644 --- a/apps/order-service/overlays/dev/kustomization.yaml +++ b/apps/order-service/overlays/dev/kustomization.yaml @@ -10,7 +10,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/order-service - newTag: 556f5d948568e14edc2d380274c0127628db58bf + newTag: 75c566e3063d58803f614facda8a3a6e0df6e812 replicas: - count: 1 From 7a75f64ce07d7c061c5de86991bd521e2011c5da Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Mon, 10 Aug 2026 08:11:47 +0000 Subject: [PATCH 120/122] Promote product-service to 75c566e3063d58803f614facda8a3a6e0df6e812 --- apps/product-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/product-service/overlays/dev/kustomization.yaml b/apps/product-service/overlays/dev/kustomization.yaml index 767cb09..8dd3f3d 100644 --- a/apps/product-service/overlays/dev/kustomization.yaml +++ b/apps/product-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/product-service - newTag: 556f5d948568e14edc2d380274c0127628db58bf + newTag: 75c566e3063d58803f614facda8a3a6e0df6e812 From 9b7c9ea2f58f73ac66ea154883110c60e02b65bf Mon Sep 17 00:00:00 2001 From: Emmy-github-webdev Date: Mon, 10 Aug 2026 08:11:54 +0000 Subject: [PATCH 121/122] Promote user-service to 75c566e3063d58803f614facda8a3a6e0df6e812 --- apps/user-service/overlays/dev/kustomization.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/user-service/overlays/dev/kustomization.yaml b/apps/user-service/overlays/dev/kustomization.yaml index c617ae3..578738a 100644 --- a/apps/user-service/overlays/dev/kustomization.yaml +++ b/apps/user-service/overlays/dev/kustomization.yaml @@ -7,7 +7,7 @@ namespace: dev images: - name: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service newName: 579871530627.dkr.ecr.us-east-1.amazonaws.com/ja-mics-ap/user-service - newTag: 556f5d948568e14edc2d380274c0127628db58bf + newTag: 75c566e3063d58803f614facda8a3a6e0df6e812 From 5fea98b5675d835cb974f1a4d5a096dd9884750b Mon Sep 17 00:00:00 2001 From: emmy-github-webdev Date: Mon, 10 Aug 2026 10:18:05 +0200 Subject: [PATCH 122/122] Updated the argocd --- argocd/dev/applicationset-apps.yaml | 3 +-- argocd/dev/applicationset-infra.yaml | 3 +-- argocd/dev/applicationset-monitoring.yaml | 3 +-- argocd/dev/kustomization.yaml | 3 +-- argocd/dev/root-app.yaml | 3 +-- 5 files changed, 5 insertions(+), 10 deletions(-) diff --git a/argocd/dev/applicationset-apps.yaml b/argocd/dev/applicationset-apps.yaml index f419b61..5c48ad1 100644 --- a/argocd/dev/applicationset-apps.yaml +++ b/argocd/dev/applicationset-apps.yaml @@ -36,5 +36,4 @@ spec: selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-infra.yaml b/argocd/dev/applicationset-infra.yaml index d7bdda9..3204bb9 100644 --- a/argocd/dev/applicationset-infra.yaml +++ b/argocd/dev/applicationset-infra.yaml @@ -34,5 +34,4 @@ spec: prune: true selfHeal: true syncOptions: - - CreateNamespace=true - \ No newline at end of file + - CreateNamespace=true \ No newline at end of file diff --git a/argocd/dev/applicationset-monitoring.yaml b/argocd/dev/applicationset-monitoring.yaml index 77fb7e8..643c001 100644 --- a/argocd/dev/applicationset-monitoring.yaml +++ b/argocd/dev/applicationset-monitoring.yaml @@ -32,5 +32,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file diff --git a/argocd/dev/kustomization.yaml b/argocd/dev/kustomization.yaml index c032462..e63013f 100644 --- a/argocd/dev/kustomization.yaml +++ b/argocd/dev/kustomization.yaml @@ -4,5 +4,4 @@ kind: Kustomization resources: - applicationset-apps.yaml - applicationset-infra.yaml - - applicationset-monitoring.yaml - \ No newline at end of file + - applicationset-monitoring.yaml \ No newline at end of file diff --git a/argocd/dev/root-app.yaml b/argocd/dev/root-app.yaml index 7e9ea16..91670e8 100644 --- a/argocd/dev/root-app.yaml +++ b/argocd/dev/root-app.yaml @@ -20,5 +20,4 @@ spec: syncPolicy: automated: prune: true - selfHeal: true - \ No newline at end of file + selfHeal: true \ No newline at end of file