Files
olb042 e4434ed046
Validate manifests / validate (push) Successful in 7s
update readme
2026-06-14 03:25:43 +01:00

2.1 KiB

argocd

GitOps source for the cluster Argo CD installation. This app is self-managed by Argo CD and intentionally uses a conservative sync policy.

Current deployment

  • Bootstrap: enabled: true, applied from main
  • Argo application: argocd-production
  • Target namespace: argocd
  • Render path: manifest/overlays/production
  • Repo URL used by Argo CD: http://gitea-ha-http.apps:3000/olb42/argocd.git
  • Live state observed via document_state on 2026-06-14: Synced and Healthy
  • Live revision: aa13430d2464162e4f4f7e68ee99deef02234a80
  • Config management: native Kustomize overlay with kustomize.buildOptions: --enable-helm; Lovely CMP sidecar is installed on the repo-server

Runtime

The base installs upstream Argo CD v3.4.3 from the official install manifest. The production overlay adds the Traefik route for argocd.olb42.com, repo credentials, notifications, Redis credentials, Image Updater v1.2.0, the Lovely v1.2.4 CMP sidecar, ArgoPlane UI extension loaders, and patches for Argo CD config, RBAC, command parameters, repo-server behavior, and bundled Redis disablement.

The live argocd namespace currently has the core Argo CD workloads ready: argocd-application-controller StatefulSet 1/1, plus argocd-applicationset-controller, argocd-dex-server, argocd-notifications-controller, argocd-repo-server, and argocd-server Deployments all 1/1. argocd-redis is intentionally scaled to 0/0 because the bundled Redis is disabled. Extension workloads such as argocd-extension-pod-files and the ArgoPlane backend Deployments are managed as separate Argo CD applications in the same namespace.

Secrets for the Argo CD control plane and Gitea repository credentials are tracked as SealedSecret resources. The application resource tree shows those SealedSecrets healthy and owning the generated Kubernetes Secret objects.

Sync policy

Automated sync is disabled for the Argo CD application itself. Prune and self-heal are also disabled so a bad self-management change cannot remove the control plane that would be needed to repair it.