From c3aac37e52ab18f69edb2c6ca46f6d62bc0c91f0 Mon Sep 17 00:00:00 2001 From: nick-gorse Date: Thu, 28 May 2026 18:44:16 +0100 Subject: [PATCH] remote rollout --- ...ut-notifications-secret.sealed.secret.yaml | 16 - .../argo-rollouts/demo-rollout.yaml | 38 -- .../argo-rollouts/ingressroute.yaml | 16 - .../argo-rollouts/kustomization.yaml | 11 - .../production/argo-rollouts/namespace.yaml | 4 - .../overlays/production/argocd-cm-patch.yaml | 13 + .../argocd-cmd-params-cm-patch.yaml | 1 + .../production/argocd-rbac-cm-patch.yaml | 7 + temp.yaml | 408 ------------------ 9 files changed, 21 insertions(+), 493 deletions(-) delete mode 100644 manifest/overlays/production/argo-rollouts/argo-rollout-notifications-secret.sealed.secret.yaml delete mode 100644 manifest/overlays/production/argo-rollouts/demo-rollout.yaml delete mode 100644 manifest/overlays/production/argo-rollouts/ingressroute.yaml delete mode 100644 manifest/overlays/production/argo-rollouts/kustomization.yaml delete mode 100644 manifest/overlays/production/argo-rollouts/namespace.yaml delete mode 100644 temp.yaml diff --git a/manifest/overlays/production/argo-rollouts/argo-rollout-notifications-secret.sealed.secret.yaml b/manifest/overlays/production/argo-rollouts/argo-rollout-notifications-secret.sealed.secret.yaml deleted file mode 100644 index 7ba885b..0000000 --- a/manifest/overlays/production/argo-rollouts/argo-rollout-notifications-secret.sealed.secret.yaml +++ /dev/null @@ -1,16 +0,0 @@ ---- -apiVersion: bitnami.com/v1alpha1 -kind: SealedSecret -metadata: - name: argo-rollouts-notification-secret - namespace: argo-rollouts -spec: - encryptedData: - gitea-token: AgAPVIJ377mIWJe/D/rt1NCviYHRNmd2nXht9q9nE4F4qU3GLWXpubECeKBKfI8P11Ad/QhLlbF1vcdG3g5YFDauIkcpB3/zs9TU5s0spHotWMWuIHaHroVyI/1YnVwcBcp/VhCWazxqJ1401wbfTTK9xGRwVh95wjxvazsRaM3bVGqxeFx8hbcYitlEhfz+esiCT3v8xvumvlIVKXy79yuoDnK1H7gov8FkuNhNpxzoImYv0nUM7cJsXBEobbl2wpBiEzLYmt59GNOrWudCE437LkoJHDJUQ0uLMiQg9abiz4V4f8yipupgIoKC7JrFupnq5DyiA78AvzHeidYQg/bgS3ZICoWojPpoSDkLmpFCe3WVbXvfWEocxSYu10xVEUX7aPkQ+bjjsypKwOdXzxi1PkFMYXLLwudf0zQS+7hFDtK3xNNm7ew6D1LEvrrcGhN6w1eJuCPi8ULoezJiJuioQx/aiiaILT/M2bJzI7wHV1xE/uLArXvsNcQAplrOzeX6LPSm0QUABsZmQkWSFogvjoFCsWgE18bAJAjLkma/3Xp/0wpgAZoRZw0B50zAI6JFdWK5vTEdJMNADYybNRmDGKC987MDi0o+jBg8lae8ksaWLGInaKO2OPeaOK1m+9ngkotskAV68aJjzBnhJ9r7CN12jH2OrSiu6BpFWTgQvk9+Pv65pMNYq7LbOd8ljgxNExwBmfGa78SfzL3mzwTjTg9F8Y6ixARORYqCXMFXBQK0H77zWTd5 - template: - metadata: - annotations: - kustomize.config.k8s.io/behavior: merge - name: argo-rollouts-notification-secret - namespace: argo-rollouts - type: Opaque diff --git a/manifest/overlays/production/argo-rollouts/demo-rollout.yaml b/manifest/overlays/production/argo-rollouts/demo-rollout.yaml deleted file mode 100644 index ebad234..0000000 --- a/manifest/overlays/production/argo-rollouts/demo-rollout.yaml +++ /dev/null @@ -1,38 +0,0 @@ -# This example demonstrates a Rollout using the canary update strategy with a customized rollout -# plan. The prescribed steps initially sets a canary weight of 20%, then pauses indefinitely. Once -# resumed, the rollout performs a gradual, automated 20% weight increase until it reaches 100%. -apiVersion: argoproj.io/v1alpha1 -kind: Rollout -metadata: - name: rollout-canary - namespace: argo-rollouts -spec: - replicas: 5 - revisionHistoryLimit: 2 - selector: - matchLabels: - app: rollout-canary - template: - metadata: - labels: - app: rollout-canary - spec: - containers: - - name: rollouts-demo - image: argoproj/rollouts-demo:blue - imagePullPolicy: Always - ports: - - containerPort: 8080 - strategy: - canary: - steps: - - setWeight: 20 - # The following pause step will pause the rollout indefinitely until manually resumed. - # Rollouts can be manually resumed by running `kubectl argo rollouts promote ROLLOUT` - - pause: {} - - setWeight: 40 - - pause: {duration: 40s} - - setWeight: 60 - - pause: {duration: 20s} - - setWeight: 80 - - pause: {duration: 20s} \ No newline at end of file diff --git a/manifest/overlays/production/argo-rollouts/ingressroute.yaml b/manifest/overlays/production/argo-rollouts/ingressroute.yaml deleted file mode 100644 index 398a327..0000000 --- a/manifest/overlays/production/argo-rollouts/ingressroute.yaml +++ /dev/null @@ -1,16 +0,0 @@ -apiVersion: traefik.io/v1alpha1 -kind: IngressRoute -metadata: - name: argo-rollouts-dashboard - namespace: argo-rollouts -spec: - entryPoints: - - websecure - routes: - - kind: Rule - match: Host(`argo-rollout.olb42.com`) - services: - - name: argo-rollouts-dashboard - port: 3100 - tls: - secretName: olb42-wildcard-tls diff --git a/manifest/overlays/production/argo-rollouts/kustomization.yaml b/manifest/overlays/production/argo-rollouts/kustomization.yaml deleted file mode 100644 index c4bf022..0000000 --- a/manifest/overlays/production/argo-rollouts/kustomization.yaml +++ /dev/null @@ -1,11 +0,0 @@ -apiVersion: kustomize.config.k8s.io/v1beta1 -kind: Kustomization - -namespace: argo-rollouts - -resources: - - namespace.yaml - - ingressroute.yaml - - argo-rollout-notifications-secret.sealed.secret.yaml - - https://github.com/argoproj/argo-rollouts/releases/download/v1.9.0/install.yaml - - https://github.com/argoproj/argo-rollouts/releases/download/v1.9.0/dashboard-install.yaml \ No newline at end of file diff --git a/manifest/overlays/production/argo-rollouts/namespace.yaml b/manifest/overlays/production/argo-rollouts/namespace.yaml deleted file mode 100644 index 67214dc..0000000 --- a/manifest/overlays/production/argo-rollouts/namespace.yaml +++ /dev/null @@ -1,4 +0,0 @@ -apiVersion: v1 -kind: Namespace -metadata: - name: argo-rollouts diff --git a/manifest/overlays/production/argocd-cm-patch.yaml b/manifest/overlays/production/argocd-cm-patch.yaml index 6ed3f55..7e0e0fb 100644 --- a/manifest/overlays/production/argocd-cm-patch.yaml +++ b/manifest/overlays/production/argocd-cm-patch.yaml @@ -8,6 +8,7 @@ data: accounts.mcpserver: apiKey accounts.anonymous.enabled: "true" statusbadge.enabled: "true" + exec.enabled: "true" kustomize.buildOptions: --enable-helm ui.bannercontent: "Homepage" @@ -45,6 +46,18 @@ data: - '.metadata.annotations."autoscaling.alpha.kubernetes.io/conditions"' - '.metadata.annotations."autoscaling.alpha.kubernetes.io/metrics"' - '.metadata.annotations."autoscaling.alpha.kubernetes.io/current-metrics"' + extension.config.metrics: | + services: + - '.url."http://argoplane-metrics-backend.argocd.svc:8080"' + extension.config.networking: | + services: + - '.url."http://argoplane-networking-backend.argocd.svc:8082"' + extension.config.logs: | + services: + - '.url."http://argoplane-logs-backend.argocd.svc:8083"' + extension.config.events: | + services: + - '.url."http://argoplane-events-backend.argocd.svc:8085"' resource.customizations.ignoreResourceUpdates.discovery.k8s.io_EndpointSlice: | jsonPointers: - /metadata diff --git a/manifest/overlays/production/argocd-cmd-params-cm-patch.yaml b/manifest/overlays/production/argocd-cmd-params-cm-patch.yaml index 84a3c49..adb1a66 100644 --- a/manifest/overlays/production/argocd-cmd-params-cm-patch.yaml +++ b/manifest/overlays/production/argocd-cmd-params-cm-patch.yaml @@ -7,3 +7,4 @@ data: redis.server: shared-redis.data:6379 server.insecure: "true" server.disable.auth: "true" + server.enable.proxy.extension: "true" diff --git a/manifest/overlays/production/argocd-rbac-cm-patch.yaml b/manifest/overlays/production/argocd-rbac-cm-patch.yaml index 389faca..20eca6b 100644 --- a/manifest/overlays/production/argocd-rbac-cm-patch.yaml +++ b/manifest/overlays/production/argocd-rbac-cm-patch.yaml @@ -12,5 +12,12 @@ data: g, mcpserver, role:admin g, homepage, role:readonly g, role:admin, role:readonly + p, role:admin, extensions, invoke, metrics, allow + p, role:admin, extensions, invoke, backups, allow + p, role:admin, extensions, invoke, networking, allow + p, role:admin, extensions, invoke, logs, allow + p, role:admin, extensions, invoke, vulnerabilities, allow + p, role:admin, extensions, invoke, events, allow + policy.default: role:readonly \ No newline at end of file diff --git a/temp.yaml b/temp.yaml deleted file mode 100644 index b6f4b67..0000000 --- a/temp.yaml +++ /dev/null @@ -1,408 +0,0 @@ -apiVersion: apps/v1 -kind: Deployment -metadata: - labels: - app.kubernetes.io/component: server - app.kubernetes.io/name: argocd-server - app.kubernetes.io/part-of: argocd - name: argocd-server - namespace: argocd -spec: - selector: - matchLabels: - app.kubernetes.io/name: argocd-server - template: - metadata: - labels: - app.kubernetes.io/name: argocd-server - spec: - affinity: - podAntiAffinity: - preferredDuringSchedulingIgnoredDuringExecution: - - podAffinityTerm: - labelSelector: - matchLabels: - app.kubernetes.io/name: argocd-server - topologyKey: kubernetes.io/hostname - weight: 100 - - podAffinityTerm: - labelSelector: - matchLabels: - app.kubernetes.io/part-of: argocd - topologyKey: kubernetes.io/hostname - weight: 5 - containers: - - args: - - /usr/local/bin/argocd-server - env: - - name: REDIS_PASSWORD - valueFrom: - secretKeyRef: - key: auth - name: argocd-redis - - name: ARGOCD_SERVER_INSECURE - valueFrom: - configMapKeyRef: - key: server.insecure - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_BASEHREF - valueFrom: - configMapKeyRef: - key: server.basehref - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_ROOTPATH - valueFrom: - configMapKeyRef: - key: server.rootpath - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_LOGFORMAT - valueFrom: - configMapKeyRef: - key: server.log.format - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_LOG_LEVEL - valueFrom: - configMapKeyRef: - key: server.log.level - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_REPO_SERVER - valueFrom: - configMapKeyRef: - key: repo.server - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_DEX_SERVER - valueFrom: - configMapKeyRef: - key: server.dex.server - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_DISABLE_AUTH - valueFrom: - configMapKeyRef: - key: server.disable.auth - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_ENABLE_GZIP - valueFrom: - configMapKeyRef: - key: server.enable.gzip - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_REPO_SERVER_TIMEOUT_SECONDS - valueFrom: - configMapKeyRef: - key: server.repo.server.timeout.seconds - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_X_FRAME_OPTIONS - valueFrom: - configMapKeyRef: - key: server.x.frame.options - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_CONTENT_SECURITY_POLICY - valueFrom: - configMapKeyRef: - key: server.content.security.policy - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_REPO_SERVER_PLAINTEXT - valueFrom: - configMapKeyRef: - key: server.repo.server.plaintext - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_REPO_SERVER_STRICT_TLS - valueFrom: - configMapKeyRef: - key: server.repo.server.strict.tls - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_DEX_SERVER_PLAINTEXT - valueFrom: - configMapKeyRef: - key: server.dex.server.plaintext - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_DEX_SERVER_STRICT_TLS - valueFrom: - configMapKeyRef: - key: server.dex.server.strict.tls - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_TLS_MIN_VERSION - valueFrom: - configMapKeyRef: - key: server.tls.minversion - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_TLS_MAX_VERSION - valueFrom: - configMapKeyRef: - key: server.tls.maxversion - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_TLS_CIPHERS - valueFrom: - configMapKeyRef: - key: server.tls.ciphers - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_CONNECTION_STATUS_CACHE_EXPIRATION - valueFrom: - configMapKeyRef: - key: server.connection.status.cache.expiration - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_OIDC_CACHE_EXPIRATION - valueFrom: - configMapKeyRef: - key: server.oidc.cache.expiration - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_STATIC_ASSETS - valueFrom: - configMapKeyRef: - key: server.staticassets - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_APP_STATE_CACHE_EXPIRATION - valueFrom: - configMapKeyRef: - key: server.app.state.cache.expiration - name: argocd-cmd-params-cm - optional: true - - name: REDIS_SERVER - valueFrom: - configMapKeyRef: - key: redis.server - name: argocd-cmd-params-cm - optional: true - - name: REDIS_COMPRESSION - valueFrom: - configMapKeyRef: - key: redis.compression - name: argocd-cmd-params-cm - optional: true - - name: REDISDB - valueFrom: - configMapKeyRef: - key: redis.db - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_DEFAULT_CACHE_EXPIRATION - valueFrom: - configMapKeyRef: - key: server.default.cache.expiration - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_MAX_COOKIE_NUMBER - valueFrom: - configMapKeyRef: - key: server.http.cookie.maxnumber - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_LISTEN_ADDRESS - valueFrom: - configMapKeyRef: - key: server.listen.address - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_METRICS_LISTEN_ADDRESS - valueFrom: - configMapKeyRef: - key: server.metrics.listen.address - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_OTLP_ADDRESS - valueFrom: - configMapKeyRef: - key: otlp.address - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_OTLP_INSECURE - valueFrom: - configMapKeyRef: - key: otlp.insecure - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_OTLP_HEADERS - valueFrom: - configMapKeyRef: - key: otlp.headers - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_OTLP_ATTRS - valueFrom: - configMapKeyRef: - key: otlp.attrs - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_APPLICATION_NAMESPACES - valueFrom: - configMapKeyRef: - key: application.namespaces - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_ENABLE_PROXY_EXTENSION - valueFrom: - configMapKeyRef: - key: server.enable.proxy.extension - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_K8SCLIENT_RETRY_MAX - valueFrom: - configMapKeyRef: - key: server.k8sclient.retry.max - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_K8SCLIENT_RETRY_BASE_BACKOFF - valueFrom: - configMapKeyRef: - key: server.k8sclient.retry.base.backoff - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_API_CONTENT_TYPES - valueFrom: - configMapKeyRef: - key: server.api.content.types - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SERVER_WEBHOOK_PARALLELISM_LIMIT - valueFrom: - configMapKeyRef: - key: server.webhook.parallelism.limit - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_APPLICATIONSET_CONTROLLER_ENABLE_NEW_GIT_FILE_GLOBBING - valueFrom: - configMapKeyRef: - key: applicationsetcontroller.enable.new.git.file.globbing - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_APPLICATIONSET_CONTROLLER_SCM_ROOT_CA_PATH - valueFrom: - configMapKeyRef: - key: applicationsetcontroller.scm.root.ca.path - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_APPLICATIONSET_CONTROLLER_ALLOWED_SCM_PROVIDERS - valueFrom: - configMapKeyRef: - key: applicationsetcontroller.allowed.scm.providers - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_APPLICATIONSET_CONTROLLER_ENABLE_SCM_PROVIDERS - valueFrom: - configMapKeyRef: - key: applicationsetcontroller.enable.scm.providers - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_APPLICATIONSET_CONTROLLER_ENABLE_GITHUB_API_METRICS - valueFrom: - configMapKeyRef: - key: applicationsetcontroller.enable.github.api.metrics - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_HYDRATOR_ENABLED - valueFrom: - configMapKeyRef: - key: hydrator.enabled - name: argocd-cmd-params-cm - optional: true - - name: ARGOCD_SYNC_WITH_REPLACE_ALLOWED - valueFrom: - configMapKeyRef: - key: server.sync.replace.allowed - name: argocd-cmd-params-cm - optional: true - image: quay.io/argoproj/argocd:v3.3.6 - imagePullPolicy: Always - livenessProbe: - httpGet: - path: /healthz?full=true - port: 8080 - initialDelaySeconds: 3 - periodSeconds: 30 - timeoutSeconds: 5 - name: argocd-server - ports: - - containerPort: 8080 - - containerPort: 8083 - readinessProbe: - httpGet: - path: /healthz - port: 8080 - initialDelaySeconds: 3 - periodSeconds: 30 - securityContext: - allowPrivilegeEscalation: false - capabilities: - drop: - - ALL - readOnlyRootFilesystem: true - runAsNonRoot: true - seccompProfile: - type: RuntimeDefault - volumeMounts: - - mountPath: /app/config/ssh - name: ssh-known-hosts - - mountPath: /app/config/tls - name: tls-certs - - mountPath: /app/config/server/tls - name: argocd-repo-server-tls - - mountPath: /app/config/dex/tls - name: argocd-dex-server-tls - - mountPath: /home/argocd - name: plugins-home - - mountPath: /tmp - name: tmp - - mountPath: /home/argocd/params - name: argocd-cmd-params-cm - nodeSelector: - kubernetes.io/os: linux - serviceAccountName: argocd-server - volumes: - - emptyDir: {} - name: plugins-home - - emptyDir: {} - name: tmp - - configMap: - name: argocd-ssh-known-hosts-cm - name: ssh-known-hosts - - configMap: - name: argocd-tls-certs-cm - name: tls-certs - - name: argocd-repo-server-tls - secret: - items: - - key: tls.crt - path: tls.crt - - key: tls.key - path: tls.key - - key: ca.crt - path: ca.crt - optional: true - secretName: argocd-repo-server-tls - - name: argocd-dex-server-tls - secret: - items: - - key: tls.crt - path: tls.crt - - key: ca.crt - path: ca.crt - optional: true - secretName: argocd-dex-server-tls - - configMap: - items: - - key: server.profile.enabled - path: profiler.enabled - name: argocd-cmd-params-cm - optional: true - name: argocd-cmd-params-cm \ No newline at end of file