argocd-notifications-secret and argocd-secret are defined as empty secrets in the upstream install.yaml. Without the merge annotation, kustomize errors on duplicate resource IDs when the KSOPS generator also produces them.
KSOPS cannot handle multi-document YAML files; each secret needs its own encrypted file. Updated ksops-generator.yaml to reference all 7 secrets.
- Base references upstream ArgoCD v3.3.6 install.yaml - Production overlay applies all cluster customizations: - KSOPS CMP sidecar on argocd-repo-server - Custom ConfigMaps (argocd-cm, argocd-cmd-params-cm, argocd-rbac-cm, argocd-notifications-cm) - Redis migrated to shared-redis.data:6379 - Traefik IngressRoute for argocd.olb42.com - SOPS-encrypted secrets (age key, redis auth, gitea tokens, repo-creds) - Bootstrap Application with prune:false for safe self-management