f0864165c0fc9a38864d481842ec1e4830b1f173
Validate manifests / validate (push) Successful in 5s
disable.auth=true (from e712652, for the Headlamp argocd plugin) turned off
login globally, so Keycloak SSO and local admin login were bypassed and the
UI reported 'not logged in'. The Headlamp plugin reads Application CRDs via
the k8s API and does not require this.
Co-Authored-By: Claude Opus 4.8 <[email protected]>
argocd
GitOps source for the cluster Argo CD installation. This app is self-managed by Argo CD and intentionally uses a conservative sync policy.
Current deployment
- Bootstrap:
enabled: true, applied frommain - Argo application:
argocd-production - Target namespace:
argocd - Render path:
manifest/overlays/production - Repo URL used by Argo CD:
http://gitea-ha-http.apps:3000/olb42/argocd.git - Config management plugin:
ksops
Runtime
The base installs upstream Argo CD v3.3.6 from the official install manifest.
The production overlay adds the Traefik route for argocd.olb42.com, KSOPS CMP
configuration, repo credentials, notifications, Redis credentials, and patches
for Argo CD config, RBAC, command parameters, repo-server behavior, and bundled
Redis disablement.
Sync policy
Automated sync is disabled for the Argo CD application itself. Prune and self-heal are also disabled so a bad self-management change cannot remove the control plane that would be needed to repair it.
Languages
Dotenv
100%