From e4434ed046431b9027a17c36528f1f40df868429 Mon Sep 17 00:00:00 2001 From: nick-gorse Date: Sun, 14 Jun 2026 03:25:43 +0100 Subject: [PATCH] update readme --- README.md | 28 +++++++++++++++---- .../overlays/production/argocd-cm-patch.yaml | 1 - 2 files changed, 23 insertions(+), 6 deletions(-) diff --git a/README.md b/README.md index cc84589..370e6fa 100644 --- a/README.md +++ b/README.md @@ -10,16 +10,34 @@ Argo CD and intentionally uses a conservative sync policy. - Target namespace: `argocd` - Render path: `manifest/overlays/production` - Repo URL used by Argo CD: `http://gitea-ha-http.apps:3000/olb42/argocd.git` -- Config management plugin: `ksops` +- Live state observed via `document_state` on 2026-06-14: `Synced` and `Healthy` +- Live revision: `aa13430d2464162e4f4f7e68ee99deef02234a80` +- Config management: native Kustomize overlay with + `kustomize.buildOptions: --enable-helm`; Lovely CMP sidecar is installed on + the repo-server ## Runtime -The base installs upstream Argo CD `v3.3.6` from the official install manifest. -The production overlay adds the Traefik route for `argocd.olb42.com`, KSOPS CMP -configuration, repo credentials, notifications, Redis credentials, and patches -for Argo CD config, RBAC, command parameters, repo-server behavior, and bundled +The base installs upstream Argo CD `v3.4.3` from the official install manifest. +The production overlay adds the Traefik route for `argocd.olb42.com`, repo +credentials, notifications, Redis credentials, Image Updater `v1.2.0`, the +Lovely `v1.2.4` CMP sidecar, ArgoPlane UI extension loaders, and patches for +Argo CD config, RBAC, command parameters, repo-server behavior, and bundled Redis disablement. +The live `argocd` namespace currently has the core Argo CD workloads ready: +`argocd-application-controller` StatefulSet `1/1`, plus +`argocd-applicationset-controller`, `argocd-dex-server`, +`argocd-notifications-controller`, `argocd-repo-server`, and `argocd-server` +Deployments all `1/1`. `argocd-redis` is intentionally scaled to `0/0` because +the bundled Redis is disabled. Extension workloads such as +`argocd-extension-pod-files` and the ArgoPlane backend Deployments are managed +as separate Argo CD applications in the same namespace. + +Secrets for the Argo CD control plane and Gitea repository credentials are +tracked as `SealedSecret` resources. The application resource tree shows those +SealedSecrets healthy and owning the generated Kubernetes `Secret` objects. + ## Sync policy Automated sync is disabled for the Argo CD application itself. Prune and diff --git a/manifest/overlays/production/argocd-cm-patch.yaml b/manifest/overlays/production/argocd-cm-patch.yaml index c42e05d..ed9c5c7 100644 --- a/manifest/overlays/production/argocd-cm-patch.yaml +++ b/manifest/overlays/production/argocd-cm-patch.yaml @@ -61,7 +61,6 @@ data: extension.config.pod-files: | services: - url: http://argocd-extension-pod-files.argocd - resource.customizations.ignoreResourceUpdates.discovery.k8s.io_EndpointSlice: | jsonPointers: - /metadata