a8d52311cd
## Why Kubernetes defaults `apiVersion: v1` and `kind: PersistentVolumeClaim` onto every StatefulSet `volumeClaimTemplates` entry, but neither the raw manifests nor the rendered helm charts in this repo emit those fields. Live StatefulSets therefore carry TypeMeta that git lacks, and ArgoCD reports a diff that removes it. `volumeClaimTemplates` are immutable on an existing StatefulSet, so ArgoCD can never apply the removal. The affected StatefulSets stay perpetually OutOfSync and the un-appliable diff can contribute to sync failures. Rendering the overlays confirms this is a chronic render-vs-live mismatch, not a regression: the source manifests/charts have never emitted the TypeMeta. Affected StatefulSets (render lacks TypeMeta, live defaults it in): - `consul-server` (consul, helm render) - `nats` (logging, helm render) - `kanidm` (kanidm, raw manifest) `vault` and the `woodpecker` StatefulSets already emit TypeMeta from their charts and are unaffected. ## How - Add a fleet-wide `resource.customizations.ignoreDifferences.apps_StatefulSet` to the `argocd-cm` patch, using `jqPathExpressions` to ignore the defaulted `apiVersion` and `kind` under every `volumeClaimTemplates` entry. A single global customization is chosen over per-manifest edits because the affected StatefulSets span both raw manifests (kanidm) and helm renders (consul, nats) whose output cannot be edited; it is inert for StatefulSets that already emit TypeMeta (vault, woodpecker) and future-proof for new ones. The live StatefulSets are left untouched — their `volumeClaimTemplates` are immutable, and recreation would orphan PVCs. --------- Co-authored-by: Ben Vincent <neotheo@gmail.com> Reviewed-on: #350 Co-authored-by: Ben Vincent <ben@unkin.net> Co-committed-by: Ben Vincent <ben@unkin.net>
66 lines
3.2 KiB
YAML
66 lines
3.2 KiB
YAML
---
|
|
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: argocd-cm
|
|
namespace: argocd
|
|
data:
|
|
kustomize.buildOptions: "--enable-helm"
|
|
# Kubernetes defaults apiVersion/kind onto every StatefulSet
|
|
# volumeClaimTemplates entry, but neither the raw manifests nor the helm
|
|
# charts emit them, so live StatefulSets carry TypeMeta that git lacks.
|
|
# volumeClaimTemplates are immutable on an existing StatefulSet, so ArgoCD
|
|
# can never reconcile the removal and the resource stays perpetually
|
|
# OutOfSync. Ignore the defaulted TypeMeta fleet-wide.
|
|
resource.customizations.ignoreDifferences.apps_StatefulSet: |
|
|
jqPathExpressions:
|
|
- '.spec.volumeClaimTemplates[]?.apiVersion'
|
|
- '.spec.volumeClaimTemplates[]?.kind'
|
|
# External URL ArgoCD serves on (TLS terminated at the traefik-internal gateway).
|
|
url: https://argocd.k8s.syd1.au.unkin.net
|
|
# OIDC login via Authentik. The client secret is seeded in Vault out of band
|
|
# and surfaced as the `argocd-oidc` Secret (labelled part-of=argocd) by VSO;
|
|
# `$argocd-oidc:client_secret` resolves the key from that Secret.
|
|
oidc.config: |
|
|
name: Authentik
|
|
issuer: https://identity.unkin.net/application/o/argocd/
|
|
clientID: argocd
|
|
clientSecret: $argocd-oidc:client_secret
|
|
# argocd-server does OIDC discovery/egress to identity.unkin.net over TLS,
|
|
# which is served by the internal `unkin.net` CA (not a public root), so the
|
|
# stock image trust store rejects it (x509: certificate signed by unknown
|
|
# authority). Anchor on the stable `unkin.net` root; identity presents its
|
|
# intermediate in the handshake, and the intermediate is periodically
|
|
# re-keyed, so pinning the root (not the intermediate) is rotation-proof.
|
|
rootCA: |
|
|
-----BEGIN CERTIFICATE-----
|
|
MIIDLzCCAhegAwIBAgIUIDADwsHIrQ8dfncpechBdIUCQdIwDQYJKoZIhvcNAQEL
|
|
BQAwFDESMBAGA1UEAxMJdW5raW4ubmV0MB4XDTI0MDQyNzExMjcwMloXDTM0MDQy
|
|
NTExMjczMlowFDESMBAGA1UEAxMJdW5raW4ubmV0MIIBIjANBgkqhkiG9w0BAQEF
|
|
AAOCAQ8AMIIBCgKCAQEA3ENPv7R7gCUJAg8Q4hB2LEZSdvbK155YbcrguLDDnu6m
|
|
2fkJn8jYMMW3Z6/+Y04ouGwi6sKup8ggTb217sY+dC4IUZjotDPAhruxfXVQAh0v
|
|
Yr3RYoxVDrm4nRSFLo1RA4Qt+1KK299mHGQf9iAiwbsFp5mDrJT9uz15FE2uWmbK
|
|
8/onMyJC4fnkMihVN6NIgTtjpHYNm5aAJwxoWldTopgF0ucb7X3XVPNbKAmd3Avd
|
|
lsOo6m751zSZ0HvJOxgRSy7lvPzMuUfCQsOcmI4O4+Z2FL4Y7p+T9DvWkciC7L3i
|
|
tBiK30fPfGKNpWaof1ONCcPQNjMwWcEFXqSiWUOXkwIDAQABo3kwdzAOBgNVHQ8B
|
|
Af8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUGpy/pj6F8e3gSOAp
|
|
r+6hAYQdOScwHwYDVR0jBBgwFoAUGpy/pj6F8e3gSOApr+6hAYQdOScwFAYDVR0R
|
|
BA0wC4IJdW5raW4ubmV0MA0GCSqGSIb3DQEBCwUAA4IBAQA5xocILzuvD+R2Iub1
|
|
UnTdcVpgNcxJmESz0eX4UrkcBmddtuFINXvDTv5//XTFs78LsVVSf00xZ+2C62Xe
|
|
xRdCdluHN8VDCAKulP4XJY1BiZ7im0v+iMgPDKhq4OXb86WFYI/8J6uRm7oIAwj1
|
|
zhhKxMimkzli+yHB8ipL15W7l68CMUgmOjFA+EG6sbfadFpQTX/h6TVj3FQPkU/p
|
|
UJEm2XjlGNAKGJrNRU47PM4vRDv5Joyowp9zv/pHFXvUJladaJupMKRJQVWQz1US
|
|
EXE67rawG79s3vm8dDolnbli/IhPHtjDRIprxAwrMs5tt9cY0xsRkFBZVcAOjrpb
|
|
4gqd
|
|
-----END CERTIFICATE-----
|
|
requestedScopes:
|
|
- openid
|
|
- profile
|
|
- email
|
|
# Hierarchical group claim from terraform-authentik (includes permission
|
|
# groups inherited via role groups). Read for RBAC below.
|
|
- ak_groups
|
|
requestedIDTokenClaims:
|
|
ak_groups:
|
|
essential: true
|