apiVersion: apps/v1 kind: Deployment metadata: name: argocd-repo-server namespace: argocd annotations: glance/parent: argocd spec: template: metadata: annotations: glance/parent: argocd spec: initContainers: - name: copyutil image: quay.io/argoproj/argocd:v3.5.1 command: - sh - -c args: - /bin/cp --update=none /usr/local/bin/argocd /var/run/argocd/argocd && /bin/ln -s /var/run/argocd/argocd /var/run/argocd/argocd-cmp-server securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL readOnlyRootFilesystem: true runAsNonRoot: true seccompProfile: type: RuntimeDefault volumeMounts: - mountPath: /var/run/argocd name: var-files - name: ghcr-auth image: quay.io/argoproj/argocd:v3.5.1 securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL readOnlyRootFilesystem: true runAsNonRoot: true seccompProfile: type: RuntimeDefault env: - name: HELM_CONFIG_HOME value: /helm-working-dir - name: HELM_REGISTRY_CONFIG value: /helm-working-dir/config.json - name: GITEA_USERNAME valueFrom: secretKeyRef: name: gitea-basic-authregcred key: username - name: GITEA_PASSWORD valueFrom: secretKeyRef: name: gitea-basic-authregcred key: password volumeMounts: - name: registry-auth-dir mountPath: /helm-working-dir command: - /bin/bash - -exc - 'echo -n $GITEA_PASSWORD | helm registry login git.olb42.com--username $GITEA_USERNAME --password-stdin -' containers: - name: argocd-lovely-plugin image: ghcr.io/crumbhole/lovely:1.2.4 command: - /var/run/argocd/argocd-cmp-server securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL runAsNonRoot: true runAsUser: 999 seccompProfile: type: RuntimeDefault volumeMounts: - mountPath: /var/run/argocd name: var-files - mountPath: /home/argocd/cmp-server/plugins name: plugins - mountPath: /tmp name: lovely-tmp - name: argocd-repo-server env: - name: HELM_REGISTRY_CONFIG value: /helm-working-dir/config.json volumeMounts: - name: registry-auth-dir mountPath: /helm-working-dir volumes: - name: lovely-tmp emptyDir: {} - name: registry-auth-dir emptyDir: {}