15f1171ac591f217ac2d064d5ce54651262ba516
Kubernetes defaults apiVersion=v1 and kind=PersistentVolumeClaim onto every StatefulSet volumeClaimTemplates entry, but neither the raw manifests nor the rendered helm charts emit those fields. Live StatefulSets therefore carry TypeMeta that git lacks, and ArgoCD reports a diff removing it. Because volumeClaimTemplates are immutable on an existing StatefulSet, ArgoCD can never apply the removal, so consul-server, kanidm and nats stay perpetually OutOfSync and can contribute to sync failures. Add a fleet-wide resource.customizations.ignoreDifferences for apps/StatefulSet that ignores the defaulted apiVersion/kind under every volumeClaimTemplates entry. A single global customization covers the affected StatefulSets across both raw manifests (kanidm) and helm renders (consul, nats), and is inert for those whose charts already emit TypeMeta (vault, woodpecker).
argocd-apps docs
Operational notes for the manifests in this repo.
| Doc | What it covers |
|---|---|
| cnpg-backups.md | How CNPG Postgres backups (WAL archiving + nightly base backups) to Ceph RGW are configured. |
| cnpg-restore.md | Restoring a CNPG cluster: full recovery, point-in-time recovery, cutover, and gotchas. |
| authentik-rancher-sso.md | Manual runtime step to point Rancher's OIDC auth at the canonical identity.unkin.net issuer and trust the internal CA. |
| gitea-migration.md | Staged cutover of the git.unkin.net forge from the Puppet VM to the gitea namespace. |
| ca-rotation.md | Rolling the internal unkin.net PKI CA (vault-ca-cert): what Reloader restarts automatically vs. manual/CNPG restarts. |
Description
Languages
Shell
88.8%
Makefile
11.2%