跳转至

🚀 ExitVideo-Bot · ArgoCD GitOps 全套

ArgoCD 是 GitOps 的事实标准。本目录给出一站式安装 + 配置 + 应用管理。

目录

argocd/
├── install.sh                   # 一键安装 ArgoCD + Image Updater + ESO
├── appset.yaml                  # ApplicationSet(多环境管理)
├── appset-prod.yaml             # 生产环境应用
├── appset-staging.yaml          # Staging 环境
├── image-updater-config.yaml    # Image Updater 规则
├── rbac-policies.yaml           # ArgoCD 细粒度权限
├── notifications.yaml           # Slack/PagerDuty 通知
├── runbooks/
│   ├── first-deploy.md
│   ├── rollback.md
│   └── disaster-recovery.md

一键安装

cd infra/argocd

# 安装 ArgoCD + Image Updater + ESO
chmod +x install.sh
./install.sh prod

# 验证
kubectl get pods -n argocd
kubectl get pods -n argocd-image-updater
kubectl get pods -n external-secrets

部署流程

Git push → GitHub webhook → ArgoCD 检测 → 拉新 manifest → Helm 渲染
   ↓                                                       ↓
   ↓                                                  Apply to K8s
   ↓                                                       ↓
Renovate 自动更新                              Image Updater 检测新镜像
   ↓                                                       ↓
   └──────────────→ PR 自动合并 ←────────────────────────┘

关键概念

ApplicationSet

  • 用 1 个 yaml 模板生成 N 个 Application(多环境)
  • 支持 git / git-collector-generator / cluster 三种生成器

Image Updater

  • 监听 image registry(新 tag 推送触发)
  • 自动更新 git repo 中 manifest 的 image tag
  • ArgoCD 检测到变更 → 自动同步

SSO

  • GitHub / GitLab / Google SAML 都可
  • 配合 RBAC 做团队权限

Notifications

  • 触发:sync 成功 / 失败 / 健康度降级
  • 路由:Slack / PagerDuty / Email / Webhook

验证清单

[ ] ArgoCD UI 访问:https://argocd.exitvideo.com
[ ] Apps 列表:argocd app list
[ ] Sync 状态:argocd app get exitvideo-prod
[ ] Image Updater 日志:kubectl logs -n argocd-image-updater -l app.kubernetes.io/name=image-updater
[ ] Notifications:Slack 测试收到 ping

Runbook

  • 新集群首次部署:runbooks/first-deploy.md
  • 回滚:runbooks/rollback.md
  • 灾难恢复:runbooks/disaster-recovery.md