forked from roger/k3s-cluster
The platform-engineer ArgoCD account was created in argocd-cm.yaml but no argocd-rbac-cm.yaml existed, so ArgoCD's default-deny policy blocked all API calls with 'permission denied'. This grants the account read access to applications, clusters, repositories, and projects, plus the ability to trigger syncs — exactly what the platform-engineer bot needs.