Re-sealed the three Argo CD secrets with namespace: argocd instead of namespace: paperclip to match the kustomization.yaml deployment target. The sealed-secrets controller was failing to unseal these because they were encrypted for the 'paperclip' namespace but Kustomize was deploying them to the 'argocd' namespace. Sealed secrets use strict scope by default, so namespace/name must match exactly. Fixed files: - apps/argocd/argocd-oidc-secret-sealed.yaml - apps/argocd/repo-basicstack-org-secret-sealed.yaml - apps/argocd/repo-stack-basicstack-de-secret-sealed.yaml Root cause: DEV-284 investigation revealed controller error logs showing "no key could decrypt secret" for all three Argo CD sealed secrets. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|---|---|---|
| .. | ||
| argocd | ||
| backup | ||
| bookstack | ||
| directus | ||
| forgejo | ||
| opencloud | ||
| paperclip | ||
| passbolt | ||
| platform-prod | ||
| pocket-id | ||
| stalwart | ||
| app-argocd.yaml | ||
| app-basicstack-org.yaml | ||
| app-stack-basicstack-de.yaml | ||
| README.md | ||
Applications
This directory contains deployment configurations for all applications running on the basicstack.de cluster.
Structure
Each application should have its own subdirectory containing:
- Kubernetes manifests: Deployment, StatefulSet, Service, ConfigMap, Secret definitions
- Helm values: If using Helm charts, include values.yaml files
- Configuration files: Application-specific configs (TOML, JSON, YAML)
- Documentation: README or guide specific to the application deployment
- Patches: Any kubectl patches or modifications needed
Example: Stalwart
The stalwart/ directory serves as a reference implementation, containing:
- Multiple deployment variants (basic, with OIDC, etc.)
- Helm values files
- Monitoring dashboard configurations
- Backup/restore procedures
- Operational documentation
Adding a New Application
- Create a new directory:
apps/<application-name>/ - Add your Kubernetes manifests
- Include a README.md explaining:
- What the application does
- How to deploy it
- Configuration options
- Troubleshooting steps
- Test the deployment in a dev environment
- Commit with a descriptive message
Naming Conventions
- Directory names: lowercase, hyphen-separated (e.g.,
my-app) - Manifest files: descriptive names indicating resource type (e.g.,
deployment.yaml,service.yaml) - Use consistent naming across applications