Design principles
Project structure
Reconciliation model
The operator runs three independent controllers, each watching different resources:Startup sequence
CRD ownership model
The operator follows a strict ownership model for the two CRDs:
The user (or CLI) creates and manages the
.spec of each persona. The operator exclusively manages .status, writing validation results, health information, resource baselines, and ArgoCD sync state.
RBAC model
Every write verb the operator holds targets adorgu.io CRD, a Kubernetes Event, or a leader-election Lease. Everything else in the cluster is read-only.
Security and permissions
The ClusterRole in full, and what it deliberately omits
Ownership model
Which workloads the CLI will patch, and which it only recommends for
CRD specification
Full ApplicationPersona and ClusterPersona schema
Configuration
All operator configuration options