feat(argocd): switch to community Helm chart (DEV-519)
Replace the vendored ~33k-line apps/argocd/argocd-install.yaml with the
argoproj/argo-helm chart argo-cd 10.4.0 (app v3.5.1). Values live in
apps/argocd/values.yaml; the local kustomize wrapper now only carries the
Traefik ingress and the sealed secrets. The root apps/app-argocd.yaml
Application becomes multi-source (chart + this repo as $values), enables
ServerSideApply + ApplyOutOfSyncOnly, and pins the resources-finalizer
explicitly.
Behavior-equivalent to the previous install: same URL, OIDC (Pocket ID),
argo_admins RBAC mapping, resource.exclusions list, and per-component
memory limits (DEV-281). Ingress is disabled in the chart; ours stays in
kustomize with cert-manager letsencrypt-prod annotations.
README.md updated with the Helm bump procedure. argocd-install.yaml
removed.
Verified locally:
helm template argocd argo/argo-cd --version 10.4.0 \
-f apps/argocd/values.yaml -n argocd
# renders 34k lines, image: quay.io/argoproj/argocd:v3.5.1
kustomize build apps/argocd/
# renders 1 Ingress + 3 SealedSecrets, no errors
Refs: DEV-521, plan DEV-519 §3, §8.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-08-23 08:32:23 +00:00
|
|
|
global:
|
|
|
|
|
image:
|
|
|
|
|
tag: v3.5.1
|
|
|
|
|
|
|
|
|
|
configs:
|
|
|
|
|
cm:
|
|
|
|
|
url: https://argo.basicstack.de
|
|
|
|
|
application.instanceLabelKey: argocd.argoproj.io/instance
|
|
|
|
|
resource.exclusions: |
|
|
|
|
|
- apiGroups: [cilium.io]
|
|
|
|
|
kinds: [CiliumIdentity, CiliumEndpoint, CiliumEndpointSlice]
|
|
|
|
|
- apiGroups: [kyverno.io, reports.kyverno.io, wgpolicyk8s.io]
|
|
|
|
|
kinds: [PolicyReport, ClusterPolicyReport, EphemeralReport,
|
|
|
|
|
ClusterEphemeralReport, AdmissionReport, ClusterAdmissionReport,
|
|
|
|
|
BackgroundScanReport, ClusterBackgroundScanReport, UpdateRequest]
|
|
|
|
|
oidc.config: |
|
|
|
|
|
name: Pocket ID
|
|
|
|
|
issuer: https://auth.basicstack.de
|
2026-08-23 10:33:50 +00:00
|
|
|
clientID: $argocd-oidc-secret:oidc.pocketid.clientId
|
|
|
|
|
clientSecret: $argocd-oidc-secret:oidc.pocketid.clientSecret
|
feat(argocd): switch to community Helm chart (DEV-519)
Replace the vendored ~33k-line apps/argocd/argocd-install.yaml with the
argoproj/argo-helm chart argo-cd 10.4.0 (app v3.5.1). Values live in
apps/argocd/values.yaml; the local kustomize wrapper now only carries the
Traefik ingress and the sealed secrets. The root apps/app-argocd.yaml
Application becomes multi-source (chart + this repo as $values), enables
ServerSideApply + ApplyOutOfSyncOnly, and pins the resources-finalizer
explicitly.
Behavior-equivalent to the previous install: same URL, OIDC (Pocket ID),
argo_admins RBAC mapping, resource.exclusions list, and per-component
memory limits (DEV-281). Ingress is disabled in the chart; ours stays in
kustomize with cert-manager letsencrypt-prod annotations.
README.md updated with the Helm bump procedure. argocd-install.yaml
removed.
Verified locally:
helm template argocd argo/argo-cd --version 10.4.0 \
-f apps/argocd/values.yaml -n argocd
# renders 34k lines, image: quay.io/argoproj/argocd:v3.5.1
kustomize build apps/argocd/
# renders 1 Ingress + 3 SealedSecrets, no errors
Refs: DEV-521, plan DEV-519 §3, §8.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-08-23 08:32:23 +00:00
|
|
|
requestedScopes: [openid, profile, email, groups]
|
|
|
|
|
requestedIDTokenClaims:
|
|
|
|
|
groups: {essential: true}
|
|
|
|
|
|
|
|
|
|
rbac:
|
|
|
|
|
policy.default: role:readonly
|
|
|
|
|
policy.csv: |
|
|
|
|
|
g, argo_admins, role:admin
|
|
|
|
|
p, role:admin, applications, *, */*, allow
|
|
|
|
|
p, role:admin, clusters, *, *, allow
|
|
|
|
|
p, role:admin, repositories, *, *, allow
|
|
|
|
|
p, role:admin, projects, *, *, allow
|
|
|
|
|
p, role:admin, accounts, *, *, allow
|
|
|
|
|
p, role:admin, gpgkeys, *, *, allow
|
|
|
|
|
p, role:admin, certificates, *, *, allow
|
|
|
|
|
p, role:admin, exec, *, *, allow
|
|
|
|
|
|
2026-08-23 10:20:55 +00:00
|
|
|
params:
|
|
|
|
|
server.insecure: "true"
|
|
|
|
|
|
2026-08-23 10:18:04 +00:00
|
|
|
ssh:
|
|
|
|
|
extraHosts: |
|
|
|
|
|
forgejo.forgejo.svc.cluster.local ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCnFlDTGVmri7geuOfZ1UvHzCRi1U5BqCq+9MwkrbGkZCmBmUt3ek95JBZzurLvR/0rE624B9tB1AvSJIEIQ1W1YXD4ydiDaHX6J0sip6lEfqhREx0y91C15zHgi9jN0UKidse1g0xlLHpwePUmz8/2BJcLHJuwbZSdUu7+uhDIYtIJ5+3trX3IABNeluRA5TkspPAC0ViEaz4saWgWQWjKL8dsb3jIR94DiWAVpQnhaCBEILkIStJrmWl0O5B10Jr3KWy18szr9UVd8edCkoEXriCR8gx69jHdmuem5WlZPGvsK5Adf0mXE8S3rdyHqWOkDRs6Wlwd9p/1nDY8c8wtE3vqhefCpt1BwpTys9PMmgUfG0at/W+NdvalRqgQz26Bso8Tf7hcfyA/B69U2pvjA0tbgdIGJ5kLeCzpz9kpCYn8wSIuNIJ86BpyfnjRYFCYJVc6Ls86i8j3fEZAjEX7bmbeDBHQnyyH+rjq+Llo8aUd2Uf7HoSA93EjeuWq/Ta+YbWEWrp9Mrd48jnypxHXsiwDzqkm+YGQbXHfasiarxji/eQ5UMMG8hCxpLp1lJLhGN2th4eCLkpwchFr5jZGWgyZCth1WzQGj7NHvDTxKRU6n4MfsEX1B6GF0D60qtM5vZynpmO902mkn6wtxo+pCkDMroj668a62zw3rSS5Bw==
|
|
|
|
|
|
feat(argocd): switch to community Helm chart (DEV-519)
Replace the vendored ~33k-line apps/argocd/argocd-install.yaml with the
argoproj/argo-helm chart argo-cd 10.4.0 (app v3.5.1). Values live in
apps/argocd/values.yaml; the local kustomize wrapper now only carries the
Traefik ingress and the sealed secrets. The root apps/app-argocd.yaml
Application becomes multi-source (chart + this repo as $values), enables
ServerSideApply + ApplyOutOfSyncOnly, and pins the resources-finalizer
explicitly.
Behavior-equivalent to the previous install: same URL, OIDC (Pocket ID),
argo_admins RBAC mapping, resource.exclusions list, and per-component
memory limits (DEV-281). Ingress is disabled in the chart; ours stays in
kustomize with cert-manager letsencrypt-prod annotations.
README.md updated with the Helm bump procedure. argocd-install.yaml
removed.
Verified locally:
helm template argocd argo/argo-cd --version 10.4.0 \
-f apps/argocd/values.yaml -n argocd
# renders 34k lines, image: quay.io/argoproj/argocd:v3.5.1
kustomize build apps/argocd/
# renders 1 Ingress + 3 SealedSecrets, no errors
Refs: DEV-521, plan DEV-519 §3, §8.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-08-23 08:32:23 +00:00
|
|
|
controller:
|
|
|
|
|
resources:
|
|
|
|
|
requests:
|
|
|
|
|
memory: 256Mi
|
|
|
|
|
limits:
|
|
|
|
|
memory: 512Mi
|
|
|
|
|
|
|
|
|
|
repoServer:
|
|
|
|
|
resources:
|
|
|
|
|
requests:
|
|
|
|
|
memory: 256Mi
|
|
|
|
|
limits:
|
|
|
|
|
memory: 512Mi
|
|
|
|
|
|
|
|
|
|
server:
|
|
|
|
|
resources:
|
|
|
|
|
requests:
|
|
|
|
|
memory: 128Mi
|
|
|
|
|
limits:
|
|
|
|
|
memory: 256Mi
|
|
|
|
|
ingress:
|
|
|
|
|
enabled: false
|
|
|
|
|
|
|
|
|
|
redis:
|
|
|
|
|
resources:
|
|
|
|
|
requests:
|
|
|
|
|
memory: 128Mi
|
|
|
|
|
limits:
|
|
|
|
|
memory: 256Mi
|
|
|
|
|
|
|
|
|
|
notifications:
|
|
|
|
|
resources:
|
|
|
|
|
requests:
|
|
|
|
|
memory: 64Mi
|
|
|
|
|
limits:
|
|
|
|
|
memory: 128Mi
|
|
|
|
|
|
|
|
|
|
applicationSet:
|
|
|
|
|
resources:
|
|
|
|
|
requests:
|
|
|
|
|
memory: 128Mi
|
|
|
|
|
limits:
|
|
|
|
|
memory: 256Mi
|