5 Commits
Author SHA1 Message Date
olb042 a0903f38ee change cache
Validate manifests / validate (push) Successful in 6s
2026-08-27 13:33:34 +01:00
olb042andClaude Opus 4.8 f0864165c0 argocd: re-enable auth (server.disable.auth=false)
Validate manifests / validate (push) Successful in 5s
disable.auth=true (from e712652, for the Headlamp argocd plugin) turned off
login globally, so Keycloak SSO and local admin login were bypassed and the
UI reported 'not logged in'. The Headlamp plugin reads Application CRDs via
the k8s API and does not require this.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-05-29 12:44:02 +01:00
olb042 c3aac37e52 remote rollout
Validate manifests / validate (push) Successful in 7s
2026-05-28 18:44:16 +01:00
olb042 e712652ef5 fix: remove argocd-server https port and disable auth for headlamp plugin
Validate manifests / validate (push) Successful in 6s
- Removes https:443 port from argocd-server service (redundant in insecure mode)
  so K8s API proxy can resolve service endpoint without ambiguity
- Adds server.disable.auth=true to allow headlamp plugin unauthenticated API access
  (external access protected by Traefik OIDC)
2026-05-23 23:24:25 +01:00
olb042 40eb3b842c feat: initial ArgoCD GitOps self-management setup
Validate manifests / validate (push) Failing after 4s
- Base references upstream ArgoCD v3.3.6 install.yaml
- Production overlay applies all cluster customizations:
  - KSOPS CMP sidecar on argocd-repo-server
  - Custom ConfigMaps (argocd-cm, argocd-cmd-params-cm, argocd-rbac-cm, argocd-notifications-cm)
  - Redis migrated to shared-redis.data:6379
  - Traefik IngressRoute for argocd.olb42.com
  - SOPS-encrypted secrets (age key, redis auth, gitea tokens, repo-creds)
- Bootstrap Application with prune:false for safe self-management
2026-04-19 23:36:09 +01:00