From f0864165c0fc9a38864d481842ec1e4830b1f173 Mon Sep 17 00:00:00 2001 From: nick-gorse Date: Fri, 29 May 2026 12:44:02 +0100 Subject: [PATCH] argocd: re-enable auth (server.disable.auth=false) disable.auth=true (from e712652, for the Headlamp argocd plugin) turned off login globally, so Keycloak SSO and local admin login were bypassed and the UI reported 'not logged in'. The Headlamp plugin reads Application CRDs via the k8s API and does not require this. Co-Authored-By: Claude Opus 4.8 --- .../overlays/production/argocd-cmd-params-cm-patch.yaml | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/manifest/overlays/production/argocd-cmd-params-cm-patch.yaml b/manifest/overlays/production/argocd-cmd-params-cm-patch.yaml index adb1a66..8002235 100644 --- a/manifest/overlays/production/argocd-cmd-params-cm-patch.yaml +++ b/manifest/overlays/production/argocd-cmd-params-cm-patch.yaml @@ -6,5 +6,9 @@ metadata: data: redis.server: shared-redis.data:6379 server.insecure: "true" - server.disable.auth: "true" + # Keep auth ENABLED so Keycloak SSO + local admin login work. (Was set to + # "true" in e712652 for the Headlamp argocd plugin, which disabled login for + # everyone; the Headlamp plugin reads Application CRDs via the k8s API and + # does not need this.) + server.disable.auth: "false" server.enable.proxy.extension: "true"