# %s ## Overview This repository contains the core configuration for Flux CD, which manages our Kubernetes clusters using a GitOps approach. It defines the sources of truth for our applications and the automation rules for deploying them. ## Repository Structure The structure is designed to be minimal, with all cluster-specific configurations located in a dedicated directory. ``` . ├── clusters/ │ └── dev-cluster/ │ └── cicd-manifests-repo.yaml # Flux resource definitions └── README.md ``` ## Configuration Details The **/clusters/dev-cluster** directory contains the primary Flux CD custom resources that orchestrate the deployment pipeline: * **`HelmRepository`**: Configures access to the OCI-based Helm chart registry where application charts are stored. * **`GitRepository`**: Defines the source Git repository (`cicd-deployment-manifests`) that holds the application deployment manifests. * **`Kustomization`**: Specifies how the manifests from the source repository should be applied to the cluster. Multiple `Kustomization` resources are used to manage different environments and enforce deployment dependencies (e.g., ensuring namespaces exist before applications are deployed). ## Operational Workflow 1. **Source Monitoring**: Flux continuously monitors the `cicd-deployment-manifests` repository for any new commits to the `main` branch. 2. **Automated Reconciliation**: Upon detecting changes, Flux automatically fetches the latest manifests and applies them to the cluster. 3. **Dependency Management**: The `dependsOn` attribute in the `Kustomization` resources ensures that deployments occur in the correct order. 4. **Pruning**: Flux is configured to prune resources. If a manifest is deleted from the Git repository, Flux will automatically delete the corresponding resource from the Kubernetes cluster. ## Prerequisites For Flux to operate correctly, the Kubernetes cluster must be bootstrapped with the following secrets in the `flux-system` namespace. ### Required Secrets **1. GitHub Authentication (`github-auth`)** A secret containing a GitHub Personal Access Token (PAT) with repository access. ```yaml apiVersion: v1 kind: Secret metadata: name: github-auth namespace: flux-system type: Opaque data: username: password: ``` **2. Container Registry Authentication (`ghcr-auth`)** A Docker registry secret for pulling images from the GitHub Container Registry (GHCR). ```yaml apiVersion: v1 kind: Secret metadata: name: ghcr-auth namespace: flux-system type: kubernetes.io/dockerconfigjson data: .dockerconfigjson: ``` --- *This repository is automatically generated and managed by internal CI/CD tooling.*