Compare commits

...

2 commits

Author SHA1 Message Date
c9a60a56c3 Merge pull request 'fix(argocd): label argocd-oidc-secret so Argo CD reads its keys (DEV-523)' (#6) from fix/DEV-523-argocd-oidc-secret-label into main 2026-08-23 10:37:11 +00:00
CTO Agent
f5a0982222 fix(argocd): label argocd-oidc-secret so Argo CD reads its keys (DEV-523)
Argo CD only substitutes $secret:key references from Secrets carrying
the label app.kubernetes.io/part-of: argocd. Without it, the server
logs "secret key does not exist in secret" and renders placeholders
verbatim into the OIDC redirect URL.

Adding the label to the SealedSecret template ensures sealed-secrets-
controller re-produces the Secret with the label on every restore, so
OIDC keeps working after DR / re-seal.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-08-23 10:37:01 +00:00

View file

@ -16,4 +16,6 @@ spec:
creationTimestamp: null
name: argocd-oidc-secret
namespace: argocd
labels:
app.kubernetes.io/part-of: argocd
type: Opaque