---
# Flux GitRepository + Kustomizations for the primary cluster.
#
# URL is templated at project-create time via substitution of
# {{GITHUB_OWNER}}/{{PROJECT_NAME}} (see src/create.js PLACEHOLDERS).
# Applied once by the GitHub Actions deploy workflow at
# .github/workflows/deploy.yml — after that, Flux reconciles the repo's
# k8s/ directory every minute (GitRepository interval) and the
# Kustomizations every 10 min.
#
# Layout in the customer's repo:
#   k8s/base/                                # app + traefik + backup + etc.
#   k8s/gitops/supabase/                     # HelmRepo + HelmRelease + values CM
#   k8s/gitops/cert-manager-webhook-hetzner/ # HelmRepo + HelmRelease
#   k8s/overlays/production-<region>/        # per-env overlay on top of base
apiVersion: source.toolkit.fluxcd.io/v1
kind: GitRepository
metadata:
  name: vibecarbon
  namespace: flux-system
spec:
  # 1-min poll keeps the "git push → reconcile" feedback loop tight.
  interval: 1m
  url: https://github.com/{{GITHUB_OWNER}}/{{PROJECT_NAME}}
  ref:
    branch: main
  # Secret populated by the deploy workflow at first run, containing a
  # `username` + `password` (PAT or GitHub App token with repo:read).
  secretRef:
    name: flux-system
---
# Base manifests (namespace, network policies, app, traefik, backup).
# Hetzner CCM and CSI are installed via cloud-init, not as Kubernetes manifests.
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
  name: vibecarbon-base
  namespace: flux-system
spec:
  interval: 10m
  targetNamespace: vibecarbon
  sourceRef:
    kind: GitRepository
    name: vibecarbon
  path: ./k8s/base
  prune: true
  wait: true
  timeout: 10m
  healthChecks:
    - apiVersion: apps/v1
      kind: Deployment
      name: app
      namespace: vibecarbon
---
# Supabase chart install (Phase 2 overlay from 2026-04-20 refactor).
# The `supabase-values` ConfigMap content is generated by kustomize from
# values.yaml inside the overlay — Flux's kustomize-controller runs the
# same generation as `kubectl apply -k`.
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
  name: vibecarbon-supabase
  namespace: flux-system
spec:
  interval: 10m
  targetNamespace: flux-system
  sourceRef:
    kind: GitRepository
    name: vibecarbon
  path: ./k8s/gitops/supabase
  prune: true
  wait: true
  timeout: 30m
  dependsOn:
    - name: vibecarbon-base
  healthChecks:
    - apiVersion: helm.toolkit.fluxcd.io/v2
      kind: HelmRelease
      name: supabase
      namespace: flux-system
---
# cert-manager-webhook-hetzner chart install (Phase 3 overlay).
# Applied unconditionally; the ClusterIssuer DNS01 solver in
# ./k8s/base/cert-manager/ references the webhook at install time.
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
  name: vibecarbon-cert-manager-webhook-hetzner
  namespace: flux-system
spec:
  interval: 10m
  targetNamespace: flux-system
  sourceRef:
    kind: GitRepository
    name: vibecarbon
  path: ./k8s/gitops/cert-manager-webhook-hetzner
  prune: true
  wait: true
  timeout: 10m
  dependsOn:
    - name: vibecarbon-base
  healthChecks:
    - apiVersion: helm.toolkit.fluxcd.io/v2
      kind: HelmRelease
      name: cert-manager-webhook-hetzner
      namespace: flux-system
---
# Production overlay (region-specific patches on top of ./k8s/base).
# Applied only when the region matches; the deploy workflow renders the
# correct overlay name (production-nbg1, production-hel1, etc.) into a
# Kustomization name specific to the cluster at apply time.
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
  name: vibecarbon-production-nbg1
  namespace: flux-system
spec:
  interval: 10m
  targetNamespace: vibecarbon
  sourceRef:
    kind: GitRepository
    name: vibecarbon
  path: ./k8s/overlays/production-nbg1
  prune: true
  wait: true
  timeout: 10m
  dependsOn:
    - name: vibecarbon-base
