Add argocd.argoproj.io/compare-options: IgnoreExtraneous annotation to
harbor-secrets sealed secret template to prevent ArgoCD from seeing the
unsealed secret (created by sealed-secrets controller) as extraneous.
This is the same fix applied in DEV-377 for Directus and previously in
DEV-289, DEV-290 for other services.
Resolves: DEV-378
Co-Authored-By: Paperclip <noreply@paperclip.ing>
- Created Argo CD Application for Harbor (app-harbor.yaml)
- Configured Harbor Helm chart with:
- Ingress at harbor.basicstack.de with TLS via cert-manager
- PVCs using hcloud-volumes-encrypted storage class
- OIDC authentication via Pocket ID
- Resource limits for all components
- Created sealed secret with Harbor admin password, database password, and OIDC client secret
- Configured DNS A record for harbor.basicstack.de -> 178.105.17.239
- Created Pocket ID OIDC client for Harbor with callback URL
Harbor will be available at https://harbor.basicstack.de after Argo CD sync.
Co-Authored-By: Paperclip <noreply@paperclip.ing>