Force Replace sync for the Recreate puppet master to clear stale rollingUpdate #349

Merged
benvin merged 1 commits from benvin/puppetmaster-recreate-strategy-fix into main 2026-08-09 20:55:01 +10:00
Owner

Why

ArgoCD fails to sync the puppet app with:

Deployment.apps "puppetserver-master" is invalid:
spec.strategy.rollingUpdate: Forbidden: may not be specified when strategy type is 'Recreate'

The manifest is already correct: #341 changed the master to spec.strategy.type: Recreate with no rollingUpdate block. The failure is a live-object artifact. When the master ran RollingUpdate the API server defaulted spec.strategy.rollingUpdate (maxSurge/maxUnavailable) onto the object. That defaulted field is owned by no applier, so neither a client-side merge nor server-side apply drops it when the desired manifest omits it. The live object therefore keeps rollingUpdate while gaining type: Recreate, which the API server rejects — blocking every sync.

k8s forbids any rollingUpdate field when strategy.type is Recreate; the two are mutually exclusive, so the sync cannot converge until the stale field is removed from the live object.

Changes

  • Annotate the puppetserver-master Deployment with argocd.argoproj.io/sync-options: Replace=true. Replace performs a full PUT that overwrites the whole object, dropping the stale rollingUpdate field and letting the Recreate strategy apply cleanly. The annotation is scoped to this one resource, so puppetdb/puppetboard/compiler keep the app-wide ServerSideApply behaviour.

Validation

  • kustomize build --enable-helm apps/overlays/au-syd1/puppet renders puppetserver-master with strategy: { type: Recreate } (no rollingUpdate) and the new sync-options annotation.
  • make kubeconform: puppet overlay 34/34 valid; only the known cattle-system rancher kubeVersion incompatibility fails.
  • pre-commit: all hooks pass.
## Why ArgoCD fails to sync the puppet app with: Deployment.apps "puppetserver-master" is invalid: spec.strategy.rollingUpdate: Forbidden: may not be specified when strategy type is 'Recreate' The manifest is already correct: #341 changed the master to `spec.strategy.type: Recreate` with no rollingUpdate block. The failure is a live-object artifact. When the master ran RollingUpdate the API server defaulted `spec.strategy.rollingUpdate` (maxSurge/maxUnavailable) onto the object. That defaulted field is owned by no applier, so neither a client-side merge nor server-side apply drops it when the desired manifest omits it. The live object therefore keeps `rollingUpdate` while gaining `type: Recreate`, which the API server rejects — blocking every sync. k8s forbids any `rollingUpdate` field when `strategy.type` is `Recreate`; the two are mutually exclusive, so the sync cannot converge until the stale field is removed from the live object. ## Changes - Annotate the `puppetserver-master` Deployment with `argocd.argoproj.io/sync-options: Replace=true`. Replace performs a full PUT that overwrites the whole object, dropping the stale `rollingUpdate` field and letting the Recreate strategy apply cleanly. The annotation is scoped to this one resource, so puppetdb/puppetboard/compiler keep the app-wide ServerSideApply behaviour. ## Validation - `kustomize build --enable-helm apps/overlays/au-syd1/puppet` renders `puppetserver-master` with `strategy: { type: Recreate }` (no rollingUpdate) and the new sync-options annotation. - `make kubeconform`: puppet overlay 34/34 valid; only the known cattle-system rancher kubeVersion incompatibility fails. - `pre-commit`: all hooks pass.
unkinben added 1 commit 2026-08-09 19:16:02 +10:00
Force Replace sync for the Recreate puppet master to clear stale rollingUpdate
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
878df4f97c
## Why

ArgoCD fails to sync the puppet app with:

    Deployment.apps "puppetserver-master" is invalid:
    spec.strategy.rollingUpdate: Forbidden: may not be specified when strategy type is 'Recreate'

The manifest is already correct: #341 changed the master to
`spec.strategy.type: Recreate` with no rollingUpdate block. The failure is a
live-object artifact. When the master ran RollingUpdate, the API server
defaulted `spec.strategy.rollingUpdate` (maxSurge/maxUnavailable) onto the
object. That defaulted field is owned by no applier, so neither a client-side
merge nor server-side apply drops it when the desired manifest omits it. The
live object therefore keeps `rollingUpdate` while gaining `type: Recreate`,
which the API server rejects — blocking every sync.

## Changes

- Annotate the `puppetserver-master` Deployment with
  `argocd.argoproj.io/sync-options: Replace=true`. Replace performs a full PUT
  that overwrites the whole object, dropping the stale `rollingUpdate` field
  and letting the Recreate strategy apply cleanly. The annotation is scoped to
  this one resource, so puppetdb/puppetboard/compiler keep the app-wide
  ServerSideApply behaviour.
benvin merged commit c0c3eb4f66 into main 2026-08-09 20:55:01 +10:00
benvin deleted branch benvin/puppetmaster-recreate-strategy-fix 2026-08-09 20:55:01 +10:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unkin/argocd-apps#349