2.1 KiB
argocd
GitOps source for the cluster Argo CD installation. This app is self-managed by Argo CD and intentionally uses a conservative sync policy.
Current deployment
- Bootstrap:
enabled: true, applied frommain - Argo application:
argocd-production - Target namespace:
argocd - Render path:
manifest/overlays/production - Repo URL used by Argo CD:
http://gitea-ha-http.apps:3000/olb42/argocd.git - Live state observed via
document_stateon 2026-06-14:SyncedandHealthy - Live revision:
aa13430d2464162e4f4f7e68ee99deef02234a80 - Config management: native Kustomize overlay with
kustomize.buildOptions: --enable-helm; Lovely CMP sidecar is installed on the repo-server
Runtime
The base installs upstream Argo CD v3.4.3 from the official install manifest.
The production overlay adds the Traefik route for argocd.olb42.com, repo
credentials, notifications, Redis credentials, Image Updater v1.2.0, the
Lovely v1.2.4 CMP sidecar, ArgoPlane UI extension loaders, and patches for
Argo CD config, RBAC, command parameters, repo-server behavior, and bundled
Redis disablement.
The live argocd namespace currently has the core Argo CD workloads ready:
argocd-application-controller StatefulSet 1/1, plus
argocd-applicationset-controller, argocd-dex-server,
argocd-notifications-controller, argocd-repo-server, and argocd-server
Deployments all 1/1. argocd-redis is intentionally scaled to 0/0 because
the bundled Redis is disabled. Extension workloads such as
argocd-extension-pod-files and the ArgoPlane backend Deployments are managed
as separate Argo CD applications in the same namespace.
Secrets for the Argo CD control plane and Gitea repository credentials are
tracked as SealedSecret resources. The application resource tree shows those
SealedSecrets healthy and owning the generated Kubernetes Secret objects.
Sync policy
Automated sync is disabled for the Argo CD application itself. Prune and self-heal are also disabled so a bad self-management change cannot remove the control plane that would be needed to repair it.