apiVersion: apps/v1 kind: Deployment metadata: name: argocd-server annotations: glance/url: https://argocd.olb42.com glance/description: CI Deployment glance/icon: di:argo-cd glance/id: argocd spec: template: spec: initContainers: - name: extension-pod-files image: quay.io/argoprojlabs/argocd-extension-installer:v0.0.8 env: - name: EXTENSION_URL value: http://argocd-extension-pod-files.argocd/ui/extension.tar.gz volumeMounts: - name: extensions mountPath: /tmp/extensions/ securityContext: runAsUser: 1000 allowPrivilegeEscalation: false - name: ghcr-auth image: quay.io/argoproj/argocd:v3.4.3 securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL readOnlyRootFilesystem: true runAsNonRoot: true seccompProfile: type: RuntimeDefault env: - name: HELM_CONFIG_HOME value: /helm-working-dir - name: HELM_REGISTRY_CONFIG value: /helm-working-dir/config.json - name: GITEA_USERNAME valueFrom: secretKeyRef: name: gitea-basic-authregcred key: username - name: GITEA_PASSWORD valueFrom: secretKeyRef: name: gitea-basic-authregcred key: password volumeMounts: - name: registry-auth-dir mountPath: /helm-working-dir command: - /bin/bash - -exc - 'echo -n $GITEA_PASSWORD | helm registry login https://git.olb42.com/api/packages/olb42/helm/ --username $GITEA_USERNAME --password-stdin -' # ArgoPlane UI extension bundles. Copies only the enabled bundles into # the shared /tmp/extensions volume. "argoplane" is the required shell # bundle that renders the feature views (Metrics/Networking/Logs/Events) # into the ArgoCD UI — without it the feature bundles register into a # window event that nothing consumes, so no tabs appear. Keep the # feature names in sync with the enabled backends in apps/argoplane. - name: argoplane-extensions image: ghcr.io/natrontech/argoplane-ui-extensions:1.4.1 env: - name: ENABLED_EXTENSIONS value: "argoplane,metrics,networking,logs,events" volumeMounts: - name: extensions mountPath: /tmp/extensions/ securityContext: allowPrivilegeEscalation: false containers: - name: argocd-server volumeMounts: - name: extensions mountPath: /tmp/extensions/ - name: registry-auth-dir mountPath: /helm-working-dir env: - name: HELM_REGISTRY_CONFIG value: /helm-working-dir/config.json volumes: - name: extensions emptyDir: {} - name: registry-auth-dir emptyDir: {}