fix: remove argocd-server https port and disable auth for headlamp plugin
Validate manifests / validate (push) Successful in 6s

- Removes https:443 port from argocd-server service (redundant in insecure mode)
  so K8s API proxy can resolve service endpoint without ambiguity
- Adds server.disable.auth=true to allow headlamp plugin unauthenticated API access
  (external access protected by Traefik OIDC)
This commit is contained in:
2026-05-23 23:24:25 +01:00
parent a015262e29
commit e712652ef5
3 changed files with 12 additions and 0 deletions
@@ -6,3 +6,4 @@ metadata:
data: data:
redis.server: shared-redis.data:6379 redis.server: shared-redis.data:6379
server.insecure: "true" server.insecure: "true"
server.disable.auth: "true"
@@ -0,0 +1,7 @@
- op: replace
path: /spec/ports
value:
- name: http
port: 80
protocol: TCP
targetPort: 8080
@@ -23,6 +23,10 @@ patches:
- path: argocd-notifications-cm-patch.yaml - path: argocd-notifications-cm-patch.yaml
- path: repo-server-patch.yaml - path: repo-server-patch.yaml
- path: disable-bundled-redis-patch.yaml - path: disable-bundled-redis-patch.yaml
- path: argocd-server-service-patch.yaml
target:
kind: Service
name: argocd-server
# # KSOPS decrypts secret.enc.yaml at render time. # # KSOPS decrypts secret.enc.yaml at render time.
# # The presence of ksops-generator.yaml activates the KSOPS CMP plugin. # # The presence of ksops-generator.yaml activates the KSOPS CMP plugin.