878df4f97cb06e35f8b976d7962f8c0ce7af13d1
## Why
ArgoCD fails to sync the puppet app with:
Deployment.apps "puppetserver-master" is invalid:
spec.strategy.rollingUpdate: Forbidden: may not be specified when strategy type is 'Recreate'
The manifest is already correct: #341 changed the master to
`spec.strategy.type: Recreate` with no rollingUpdate block. The failure is a
live-object artifact. When the master ran RollingUpdate, the API server
defaulted `spec.strategy.rollingUpdate` (maxSurge/maxUnavailable) onto the
object. That defaulted field is owned by no applier, so neither a client-side
merge nor server-side apply drops it when the desired manifest omits it. The
live object therefore keeps `rollingUpdate` while gaining `type: Recreate`,
which the API server rejects — blocking every sync.
## Changes
- Annotate the `puppetserver-master` Deployment with
`argocd.argoproj.io/sync-options: Replace=true`. Replace performs a full PUT
that overwrites the whole object, dropping the stale `rollingUpdate` field
and letting the Recreate strategy apply cleanly. The annotation is scoped to
this one resource, so puppetdb/puppetboard/compiler keep the app-wide
ServerSideApply behaviour.
argocd-apps docs
Operational notes for the manifests in this repo.
| Doc | What it covers |
|---|---|
| cnpg-backups.md | How CNPG Postgres backups (WAL archiving + nightly base backups) to Ceph RGW are configured. |
| cnpg-restore.md | Restoring a CNPG cluster: full recovery, point-in-time recovery, cutover, and gotchas. |
| authentik-rancher-sso.md | Manual runtime step to point Rancher's OIDC auth at the canonical identity.unkin.net issuer and trust the internal CA. |
| gitea-migration.md | Staged cutover of the git.unkin.net forge from the Puppet VM to the gitea namespace. |
| ca-rotation.md | Rolling the internal unkin.net PKI CA (vault-ca-cert): what Reloader restarts automatically vs. manual/CNPG restarts. |
Description
Languages
Shell
88.8%
Makefile
11.2%