fix: remove argocd-server https port and disable auth for headlamp plugin
Validate manifests / validate (push) Successful in 6s
Validate manifests / validate (push) Successful in 6s
- Removes https:443 port from argocd-server service (redundant in insecure mode) so K8s API proxy can resolve service endpoint without ambiguity - Adds server.disable.auth=true to allow headlamp plugin unauthenticated API access (external access protected by Traefik OIDC)
This commit is contained in:
@@ -6,3 +6,4 @@ metadata:
|
|||||||
data:
|
data:
|
||||||
redis.server: shared-redis.data:6379
|
redis.server: shared-redis.data:6379
|
||||||
server.insecure: "true"
|
server.insecure: "true"
|
||||||
|
server.disable.auth: "true"
|
||||||
|
|||||||
@@ -0,0 +1,7 @@
|
|||||||
|
- op: replace
|
||||||
|
path: /spec/ports
|
||||||
|
value:
|
||||||
|
- name: http
|
||||||
|
port: 80
|
||||||
|
protocol: TCP
|
||||||
|
targetPort: 8080
|
||||||
@@ -23,6 +23,10 @@ patches:
|
|||||||
- path: argocd-notifications-cm-patch.yaml
|
- path: argocd-notifications-cm-patch.yaml
|
||||||
- path: repo-server-patch.yaml
|
- path: repo-server-patch.yaml
|
||||||
- path: disable-bundled-redis-patch.yaml
|
- path: disable-bundled-redis-patch.yaml
|
||||||
|
- path: argocd-server-service-patch.yaml
|
||||||
|
target:
|
||||||
|
kind: Service
|
||||||
|
name: argocd-server
|
||||||
|
|
||||||
# # KSOPS decrypts secret.enc.yaml at render time.
|
# # KSOPS decrypts secret.enc.yaml at render time.
|
||||||
# # The presence of ksops-generator.yaml activates the KSOPS CMP plugin.
|
# # The presence of ksops-generator.yaml activates the KSOPS CMP plugin.
|
||||||
|
|||||||
Reference in New Issue
Block a user