stack.basicstack.de/apps
CTO Agent b874f3d184 Add memory limits to Argo CD components to prevent OOM incidents
Implements resource governance for all Argo CD components via kustomization
overlay. This prevents unlimited memory consumption that led to the control
plane resource exhaustion incident (DEV-281).

Resource limits applied:
- application-controller: 512Mi limit, 256Mi request
- repo-server: 512Mi limit, 256Mi request
- redis: 256Mi limit, 128Mi request
- server: 256Mi limit, 128Mi request
- notifications-controller: 128Mi limit, 64Mi request
- applicationset-controller: 256Mi limit, 128Mi request

The limits are based on observed usage patterns with headroom for growth
while preventing runaway memory consumption.

Usage: kubectl apply -k apps/argocd/

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-12 09:19:28 +00:00
..
argocd Add memory limits to Argo CD components to prevent OOM incidents 2026-07-12 09:19:28 +00:00
backup Convert all secrets to SealedSecrets for enhanced security 2026-07-01 18:38:27 +00:00
bookstack Convert all secrets to SealedSecrets for enhanced security 2026-07-01 18:38:27 +00:00
directus Convert all secrets to SealedSecrets for enhanced security 2026-07-01 18:38:27 +00:00
forgejo Convert all secrets to SealedSecrets for enhanced security 2026-07-01 18:38:27 +00:00
opencloud Configure OpenCloud daily backup to Hetzner Object Storage 2026-07-12 09:19:28 +00:00
paperclip Convert all secrets to SealedSecrets for enhanced security 2026-07-01 18:38:27 +00:00
passbolt Convert all secrets to SealedSecrets for enhanced security 2026-07-01 18:38:27 +00:00
platform-prod Convert all secrets to SealedSecrets for enhanced security 2026-07-01 18:38:27 +00:00
pocket-id Convert all secrets to SealedSecrets for enhanced security 2026-07-01 18:38:27 +00:00
stalwart Fix Stalwart backup CronJob to handle ReadWriteOnce PVC 2026-07-11 11:21:39 +00:00
README.md Initialize CD/CI repository structure with Stalwart example 2026-07-01 18:08:31 +00:00

Applications

This directory contains deployment configurations for all applications running on the basicstack.de cluster.

Structure

Each application should have its own subdirectory containing:

  • Kubernetes manifests: Deployment, StatefulSet, Service, ConfigMap, Secret definitions
  • Helm values: If using Helm charts, include values.yaml files
  • Configuration files: Application-specific configs (TOML, JSON, YAML)
  • Documentation: README or guide specific to the application deployment
  • Patches: Any kubectl patches or modifications needed

Example: Stalwart

The stalwart/ directory serves as a reference implementation, containing:

  • Multiple deployment variants (basic, with OIDC, etc.)
  • Helm values files
  • Monitoring dashboard configurations
  • Backup/restore procedures
  • Operational documentation

Adding a New Application

  1. Create a new directory: apps/<application-name>/
  2. Add your Kubernetes manifests
  3. Include a README.md explaining:
    • What the application does
    • How to deploy it
    • Configuration options
    • Troubleshooting steps
  4. Test the deployment in a dev environment
  5. Commit with a descriptive message

Naming Conventions

  • Directory names: lowercase, hyphen-separated (e.g., my-app)
  • Manifest files: descriptive names indicating resource type (e.g., deployment.yaml, service.yaml)
  • Use consistent naming across applications