stack.basicstack.de/apps/pocket-id
2026-07-18 13:12:34 +00:00
..
deployment.yaml apps/pocket-id/deployment.yaml aktualisiert 2026-07-18 13:12:21 +00:00
ingress.yaml Add Pocket ID deployment manifests for Argo CD GitOps 2026-07-12 14:35:28 +00:00
MIGRATION.md Add Pocket ID migration verification and rollout guide 2026-07-12 14:36:50 +00:00
pocket-id-secrets-sealed.yaml Add IgnoreExtraneous annotation to Pocket ID sealed secret template 2026-07-12 14:49:32 +00:00
pvc.yaml Add Pocket ID deployment manifests for Argo CD GitOps 2026-07-12 14:35:28 +00:00
README.md apps/pocket-id/README.md aktualisiert 2026-07-18 13:12:34 +00:00
service.yaml Add Pocket ID deployment manifests for Argo CD GitOps 2026-07-12 14:35:28 +00:00

Pocket ID Deployment

This directory contains the Kubernetes manifests for the Pocket ID deployment at https://auth.basicstack.de

Components

  • deployment.yaml: Main Pocket ID application deployment

    • Image: ghcr.io/pocket-id/pocket-id:v2.11.0
    • Resources: 100m CPU / 256Mi RAM (requests), 500m CPU / 512Mi RAM (limits)
    • Healthchecks: liveness and readiness probes using built-in healthcheck command
  • service.yaml: ClusterIP service exposing port 1411

  • pvc.yaml: PersistentVolumeClaim for application data

    • CRITICAL: Has argocd.argoproj.io/sync-options: Delete=false annotation to prevent data loss
    • Storage: 5Gi on local-path storage class
    • Contains all user accounts, OIDC clients, and application configuration
  • ingress.yaml: Traefik ingress with TLS

    • Host: auth.basicstack.de
    • TLS certificate managed by cert-manager (letsencrypt-prod)
  • pocket-id-secrets-sealed.yaml: SealedSecret containing ENCRYPTION_KEY

    • Managed by sealed-secrets controller
    • Automatically unsealed to create pocket-id-secrets Secret

Migration to Argo CD

This deployment was migrated from manual kubectl deployments to Argo CD GitOps on 2026-07-12.

Safety Measures

  1. PVC Protection: The PVC has Delete=false sync option to prevent accidental deletion
  2. Resource Adoption: Existing resources are adopted by Argo CD without recreation
  3. Data Preservation: The existing PVC volume is reused, preserving all data
  4. Secret Management: Secrets are managed via SealedSecrets for secure GitOps
  5. TLS Certificate: Managed by cert-manager, automatically renewed

Verification Steps

After Argo CD sync:

  1. Verify all resources are healthy in Argo CD UI
  2. Check pod is running: kubectl get pods -n pocket-id
  3. Verify web UI is accessible: https://auth.basicstack.de
  4. Test OIDC login flow with an existing client
  5. Verify all existing OIDC clients are still present in admin UI

Important Notes

  • DO NOT delete the PVC - it contains all application data
  • The ENCRYPTION_KEY in the sealed secret must match the existing key to decrypt stored data
  • All existing OIDC client IDs and secrets are preserved in the PVC data
  • The TLS secret is managed by cert-manager and should NOT be committed to Git