Force Replace sync for the Recreate puppet master to clear stale rollingUpdate
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful

## Why

ArgoCD fails to sync the puppet app with:

    Deployment.apps "puppetserver-master" is invalid:
    spec.strategy.rollingUpdate: Forbidden: may not be specified when strategy type is 'Recreate'

The manifest is already correct: #341 changed the master to
`spec.strategy.type: Recreate` with no rollingUpdate block. The failure is a
live-object artifact. When the master ran RollingUpdate, the API server
defaulted `spec.strategy.rollingUpdate` (maxSurge/maxUnavailable) onto the
object. That defaulted field is owned by no applier, so neither a client-side
merge nor server-side apply drops it when the desired manifest omits it. The
live object therefore keeps `rollingUpdate` while gaining `type: Recreate`,
which the API server rejects — blocking every sync.

## Changes

- Annotate the `puppetserver-master` Deployment with
  `argocd.argoproj.io/sync-options: Replace=true`. Replace performs a full PUT
  that overwrites the whole object, dropping the stale `rollingUpdate` field
  and letting the Recreate strategy apply cleanly. The annotation is scoped to
  this one resource, so puppetdb/puppetboard/compiler keep the app-wide
  ServerSideApply behaviour.
This commit is contained in:
Ben Vincent
2026-08-09 19:15:42 +10:00
parent 4d58f37ea5
commit 878df4f97c
@@ -4,6 +4,8 @@ metadata:
annotations:
configmap.reloader.stakater.com/auto: "true"
secret.reloader.stakater.com/reload: "vault-ca-cert"
# Replace clears the stale, API-server-defaulted spec.strategy.rollingUpdate that SSA cannot drop, which otherwise makes Recreate invalid.
argocd.argoproj.io/sync-options: Replace=true
labels:
app.kubernetes.io/component: puppetserver
app.kubernetes.io/instance: puppetserver