feat: add ArgoCD Application and k8s manifests for frontend

- application.yaml: ArgoCD Application resource (manual sync for now,
  same pattern as nextgen-be)
- manifests/: namespace, deployment, service, ingress
This commit is contained in:
2026-09-24 12:51:18 +02:00
parent d5acddad36
commit c18e3db3a7
6 changed files with 119 additions and 0 deletions
+20
View File
@@ -0,0 +1,20 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: nextgen-fe
namespace: argocd # the namespace ArgoCD itself runs in — adjust if different
finalizers:
- resources-finalizer.argocd.argoproj.io
spec:
project: default # or your ArgoCD AppProject name, if you use one per subgroup
source:
repoURL: "ssh://git@gitea-ssh.gitea.svc.cluster.local:22/gitea_admin/nextgen-fe.git"
targetRevision: main
path: manifests
destination:
server: "https://138.199.131.114:6443"
namespace: nextgen-fe
syncPolicy: {}
# Left empty = manual sync. Switch to automated once nginx.conf/Ingress
# are confirmed working manually — see nextgen-be/application.yaml for
# the commented automated block to copy over.
+4
View File
@@ -0,0 +1,4 @@
apiVersion: v1
kind: Namespace
metadata:
name: nextgen-fe
+49
View File
@@ -0,0 +1,49 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: nextgen-fe
namespace: nextgen-fe
labels:
app: nextgen-fe
spec:
replicas: 1
selector:
matchLabels:
app: nextgen-fe
template:
metadata:
labels:
app: nextgen-fe
spec:
imagePullSecrets:
- name: registry-credentials
containers:
- name: nextgen-fe
image: gitea.infrastructure.helmholz.cloud/gitea_admin/nextgen-fe:latest
ports:
- containerPort: 80
readinessProbe:
httpGet:
path: /
port: 80
initialDelaySeconds: 3
periodSeconds: 10
timeoutSeconds: 3
failureThreshold: 3
livenessProbe:
httpGet:
path: /
port: 80
initialDelaySeconds: 10
periodSeconds: 20
timeoutSeconds: 3
failureThreshold: 3
resources:
requests:
cpu: 50m
memory: 64Mi
limits:
cpu: 250m
memory: 128Mi
securityContext:
allowPrivilegeEscalation: false
+13
View File
@@ -0,0 +1,13 @@
apiVersion: v1
kind: Service
metadata:
name: nextgen-fe
namespace: nextgen-fe
spec:
type: ClusterIP
selector:
app: nextgen-fe
ports:
- port: 80
targetPort: 80
protocol: TCP
+24
View File
@@ -0,0 +1,24 @@
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: nextgen-fe
namespace: nextgen-fe
annotations:
kubernetes.io/ingress.class: "nginx"
# TLS terminates at the Hetzner Load Balancer, not here — this Ingress
# only ever sees plain HTTP. Without this, ingress-nginx may still try
# to force an HTTPS redirect and create a loop with the LB.
nginx.ingress.kubernetes.io/ssl-redirect: "false"
spec:
ingressClassName: nginx
rules:
- host: rex24-nextgen.worker.helmholz.cloud
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: nextgen-fe
port:
number: 80
+9
View File
@@ -0,0 +1,9 @@
apiVersion: v1
data:
.dockerconfigjson: eyJhdXRocyI6eyJnaXRlYS5pbmZyYXN0cnVjdHVyZS5oZWxtaG9sei5jbG91ZCI6eyJ1c2VybmFtZSI6ImdpdGVhX2FkbWluIiwicGFzc3dvcmQiOiIwMWVlMmUxOTJmYmE4NDA0OGI3YTQ2NDMzNmNhYTAyZmRlZjU3MDJiIiwiYXV0aCI6IloybDBaV0ZmWVdSdGFXNDZNREZsWlRKbE1Ua3labUpoT0RRd05EaGlOMkUwTmpRek16WmpZV0V3TW1aa1pXWTFOekF5WWc9PSJ9fX0=
kind: Secret
metadata:
creationTimestamp: null
name: registry-credentials
namespace: nextgen-fe
type: kubernetes.io/dockerconfigjson