stack.basicstack.de/apps/argocd
CTO Agent ba748d6ab4 Enable Argo CD self-management by removing argocd exclusion
This allows the stack Application to manage Argo CD's own configuration
via GitOps, implementing the app-of-apps pattern.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-12 09:20:18 +00:00
..
app-basicstack-org.yaml Add Argo CD Application for basicstack.org 2026-07-12 09:19:28 +00:00
app-stack-basicstack-de.yaml Enable Argo CD self-management by removing argocd exclusion 2026-07-12 09:20:18 +00:00
argocd-ingress.yaml Add Argo CD installation manifests with Pocket ID SSO 2026-07-12 09:19:28 +00:00
argocd-install.yaml Add Argo CD installation manifests with Pocket ID SSO 2026-07-12 09:19:28 +00:00
argocd-oidc-secret-sealed.yaml Add Argo CD sealed secrets for OIDC and repository access 2026-07-12 09:19:28 +00:00
kustomization.yaml Add memory limits to Argo CD components to prevent OOM incidents 2026-07-12 09:19:28 +00:00
README.md Add memory limits to Argo CD components to prevent OOM incidents 2026-07-12 09:19:28 +00:00
repo-basicstack-org-secret-sealed.yaml Add Argo CD sealed secrets for OIDC and repository access 2026-07-12 09:19:28 +00:00
repo-stack-basicstack-de-secret-sealed.yaml Add Argo CD sealed secrets for OIDC and repository access 2026-07-12 09:19:28 +00:00

Argo CD Deployment

This directory contains the Argo CD deployment configuration for the basicstack.de k3s cluster.

Files

  • argocd-install.yaml - Auto-generated Argo CD installation manifest (DO NOT EDIT DIRECTLY)
  • kustomization.yaml - Kustomize overlay that adds resource limits and other customizations
  • argocd-ingress.yaml - Ingress configuration for Argo CD UI
  • argocd-oidc-secret-sealed.yaml - Sealed secret for OIDC integration
  • repo-*.yaml - Sealed secrets for Git repository access

Resource Limits

IMPORTANT: Resource limits were added after DEV-281 (resource exhaustion incident on 2026-07-12).

All Argo CD components now have memory limits to prevent OOM incidents:

Component Memory Limit Memory Request
application-controller 512Mi 256Mi
repo-server 512Mi 256Mi
redis 256Mi 128Mi
server 256Mi 128Mi
notifications-controller 128Mi 64Mi
applicationset-controller 256Mi 128Mi

These limits are based on observed usage patterns and provide headroom while preventing unlimited memory consumption.

Deployment

kubectl apply -k apps/argocd/

This will apply the base manifests plus all patches defined in kustomization.yaml.

kubectl apply -f apps/argocd/argocd-install.yaml
kubectl apply -f apps/argocd/argocd-ingress.yaml
# etc.

Note: This skips the resource limit patches and is NOT recommended.

Updating Argo CD

When updating to a new Argo CD version:

  1. Download the new install manifest:

    curl -sSL https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml > argocd-install.yaml
    
  2. Apply with kustomize (resource limits will be automatically applied):

    kubectl apply -k apps/argocd/
    
  3. Verify resource limits are in place:

    kubectl get statefulset,deployment -n argocd -o custom-columns='NAME:.metadata.name,MEMORY_LIMIT:.spec.template.spec.containers[0].resources.limits.memory'
    

Troubleshooting

Check resource usage

kubectl top pods -n argocd

Check if resource limits are applied

kubectl get deployment,statefulset -n argocd -o json | jq '.items[] | {name: .metadata.name, limits: .spec.template.spec.containers[0].resources.limits}'

Rollback if needed

If there are issues after applying resource limits:

# Remove limits from a specific component
kubectl patch deployment -n argocd argocd-server --type='json' -p='[{"op": "remove", "path": "/spec/template/spec/containers/0/resources"}]'

History

  • 2026-07-12: Added resource limits via kustomization to prevent OOM incidents (DEV-281)
  • 2026-07-11: Initial deployment