Force Replace sync for the Recreate puppet master to clear stale rollingUpdate #349
Reference in New Issue
Block a user
Delete Branch "benvin/puppetmaster-recreate-strategy-fix"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why
ArgoCD fails to sync the puppet app with:
The manifest is already correct: #341 changed the master to
spec.strategy.type: Recreatewith no rollingUpdate block. The failure is a live-object artifact. When the master ran RollingUpdate the API server defaultedspec.strategy.rollingUpdate(maxSurge/maxUnavailable) onto the object. That defaulted field is owned by no applier, so neither a client-side merge nor server-side apply drops it when the desired manifest omits it. The live object therefore keepsrollingUpdatewhile gainingtype: Recreate, which the API server rejects — blocking every sync.k8s forbids any
rollingUpdatefield whenstrategy.typeisRecreate; the two are mutually exclusive, so the sync cannot converge until the stale field is removed from the live object.Changes
puppetserver-masterDeployment withargocd.argoproj.io/sync-options: Replace=true. Replace performs a full PUT that overwrites the whole object, dropping the stalerollingUpdatefield and letting the Recreate strategy apply cleanly. The annotation is scoped to this one resource, so puppetdb/puppetboard/compiler keep the app-wide ServerSideApply behaviour.Validation
kustomize build --enable-helm apps/overlays/au-syd1/puppetrenderspuppetserver-masterwithstrategy: { type: Recreate }(no rollingUpdate) and the new sync-options annotation.make kubeconform: puppet overlay 34/34 valid; only the known cattle-system rancher kubeVersion incompatibility fails.pre-commit: all hooks pass.## Why ArgoCD fails to sync the puppet app with: Deployment.apps "puppetserver-master" is invalid: spec.strategy.rollingUpdate: Forbidden: may not be specified when strategy type is 'Recreate' The manifest is already correct: #341 changed the master to `spec.strategy.type: Recreate` with no rollingUpdate block. The failure is a live-object artifact. When the master ran RollingUpdate, the API server defaulted `spec.strategy.rollingUpdate` (maxSurge/maxUnavailable) onto the object. That defaulted field is owned by no applier, so neither a client-side merge nor server-side apply drops it when the desired manifest omits it. The live object therefore keeps `rollingUpdate` while gaining `type: Recreate`, which the API server rejects — blocking every sync. ## Changes - Annotate the `puppetserver-master` Deployment with `argocd.argoproj.io/sync-options: Replace=true`. Replace performs a full PUT that overwrites the whole object, dropping the stale `rollingUpdate` field and letting the Recreate strategy apply cleanly. The annotation is scoped to this one resource, so puppetdb/puppetboard/compiler keep the app-wide ServerSideApply behaviour.