stack.basicstack.de/apps/pocket-id/README.md
CTO Agent 794cf51d0c Add Pocket ID deployment manifests for Argo CD GitOps
Migrated Pocket ID deployment from manual kubectl to GitOps. All existing resources
will be adopted by Argo CD without recreation, preserving data and configuration.

Key safety measures:
- PVC has Delete=false annotation to prevent data loss
- Existing sealed secret reused for ENCRYPTION_KEY
- TLS certificate managed by cert-manager (not in Git)
- All OIDC clients and user data preserved in existing PVC

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-12 14:35:28 +00:00

2.2 KiB

Pocket ID Deployment

This directory contains the Kubernetes manifests for the Pocket ID deployment at https://auth.basicstack.de

Components

  • deployment.yaml: Main Pocket ID application deployment

    • Image: ghcr.io/pocket-id/pocket-id:v2.9.0
    • Resources: 100m CPU / 256Mi RAM (requests), 500m CPU / 512Mi RAM (limits)
    • Healthchecks: liveness and readiness probes using built-in healthcheck command
  • service.yaml: ClusterIP service exposing port 1411

  • pvc.yaml: PersistentVolumeClaim for application data

    • CRITICAL: Has argocd.argoproj.io/sync-options: Delete=false annotation to prevent data loss
    • Storage: 5Gi on local-path storage class
    • Contains all user accounts, OIDC clients, and application configuration
  • ingress.yaml: Traefik ingress with TLS

    • Host: auth.basicstack.de
    • TLS certificate managed by cert-manager (letsencrypt-prod)
  • pocket-id-secrets-sealed.yaml: SealedSecret containing ENCRYPTION_KEY

    • Managed by sealed-secrets controller
    • Automatically unsealed to create pocket-id-secrets Secret

Migration to Argo CD

This deployment was migrated from manual kubectl deployments to Argo CD GitOps on 2026-07-12.

Safety Measures

  1. PVC Protection: The PVC has Delete=false sync option to prevent accidental deletion
  2. Resource Adoption: Existing resources are adopted by Argo CD without recreation
  3. Data Preservation: The existing PVC volume is reused, preserving all data
  4. Secret Management: Secrets are managed via SealedSecrets for secure GitOps
  5. TLS Certificate: Managed by cert-manager, automatically renewed

Verification Steps

After Argo CD sync:

  1. Verify all resources are healthy in Argo CD UI
  2. Check pod is running: kubectl get pods -n pocket-id
  3. Verify web UI is accessible: https://auth.basicstack.de
  4. Test OIDC login flow with an existing client
  5. Verify all existing OIDC clients are still present in admin UI

Important Notes

  • DO NOT delete the PVC - it contains all application data
  • The ENCRYPTION_KEY in the sealed secret must match the existing key to decrypt stored data
  • All existing OIDC client IDs and secrets are preserved in the PVC data
  • The TLS secret is managed by cert-manager and should NOT be committed to Git