--- apiVersion: v1 kind: ConfigMap metadata: name: argocd-cm namespace: argocd data: kustomize.buildOptions: "--enable-helm" # Kubernetes defaults apiVersion/kind onto every StatefulSet # volumeClaimTemplates entry, but neither the raw manifests nor the helm # charts emit them, so live StatefulSets carry TypeMeta that git lacks. # volumeClaimTemplates are immutable on an existing StatefulSet, so ArgoCD # can never reconcile the removal and the resource stays perpetually # OutOfSync. Ignore the defaulted TypeMeta fleet-wide. resource.customizations.ignoreDifferences.apps_StatefulSet: | jqPathExpressions: - '.spec.volumeClaimTemplates[]?.apiVersion' - '.spec.volumeClaimTemplates[]?.kind' # External URL ArgoCD serves on (TLS terminated at the traefik-internal gateway). url: https://argocd.k8s.syd1.au.unkin.net # OIDC login via Authentik. The client secret is seeded in Vault out of band # and surfaced as the `argocd-oidc` Secret (labelled part-of=argocd) by VSO; # `$argocd-oidc:client_secret` resolves the key from that Secret. oidc.config: | name: Authentik issuer: https://identity.unkin.net/application/o/argocd/ clientID: argocd clientSecret: $argocd-oidc:client_secret # The Authentik client is public (the iOS app can't hold a secret), so # Authentik no longer enforces clientSecret; PKCE replaces it as the # protection against authorization-code interception. enablePKCEAuthentication: true # identity.unkin.net now serves the LetsEncrypt *.unkin.net wildcard, so the # stock image trust store validates it; no rootCA pin. requestedScopes: - openid - profile - email # Hierarchical group claim from terraform-authentik (includes permission # groups inherited via role groups). Read for RBAC below. - ak_groups requestedIDTokenClaims: ak_groups: essential: true