From 878df4f97cb06e35f8b976d7962f8c0ce7af13d1 Mon Sep 17 00:00:00 2001 From: Ben Vincent Date: Sun, 9 Aug 2026 19:15:42 +1000 Subject: [PATCH] Force Replace sync for the Recreate puppet master to clear stale rollingUpdate MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ## Why ArgoCD fails to sync the puppet app with: Deployment.apps "puppetserver-master" is invalid: spec.strategy.rollingUpdate: Forbidden: may not be specified when strategy type is 'Recreate' The manifest is already correct: #341 changed the master to `spec.strategy.type: Recreate` with no rollingUpdate block. The failure is a live-object artifact. When the master ran RollingUpdate, the API server defaulted `spec.strategy.rollingUpdate` (maxSurge/maxUnavailable) onto the object. That defaulted field is owned by no applier, so neither a client-side merge nor server-side apply drops it when the desired manifest omits it. The live object therefore keeps `rollingUpdate` while gaining `type: Recreate`, which the API server rejects — blocking every sync. ## Changes - Annotate the `puppetserver-master` Deployment with `argocd.argoproj.io/sync-options: Replace=true`. Replace performs a full PUT that overwrites the whole object, dropping the stale `rollingUpdate` field and letting the Recreate strategy apply cleanly. The annotation is scoped to this one resource, so puppetdb/puppetboard/compiler keep the app-wide ServerSideApply behaviour. --- apps/base/puppet/deployment_puppetserver-master.yaml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/apps/base/puppet/deployment_puppetserver-master.yaml b/apps/base/puppet/deployment_puppetserver-master.yaml index 189b901..8f76b2a 100644 --- a/apps/base/puppet/deployment_puppetserver-master.yaml +++ b/apps/base/puppet/deployment_puppetserver-master.yaml @@ -4,6 +4,8 @@ metadata: annotations: configmap.reloader.stakater.com/auto: "true" secret.reloader.stakater.com/reload: "vault-ca-cert" + # Replace clears the stale, API-server-defaulted spec.strategy.rollingUpdate that SSA cannot drop, which otherwise makes Recreate invalid. + argocd.argoproj.io/sync-options: Replace=true labels: app.kubernetes.io/component: puppetserver app.kubernetes.io/instance: puppetserver