Fix ArgoCD ServerSideDiff permanent OutOfSync diffs

Add explicit CRD/API defaults to manifests that were causing ArgoCD's
SSA dry-run to produce results different from live state:

- HTTPRoutes: add group, kind, weight defaults to parentRefs/backendRefs
- Kyverno ClusterPolicies: add skipBackgroundRequests, allowExistingViolations
- Tetragon TracingPolicies: add return, maxData, resolve, returnCopy defaults
- Gateway certificateRefs: add group="" default
- Guacamole Gateway: add group="" to certificateRefs

Add ignoreDifferences for resources that legitimately differ:
- Cilium cert Secrets (auto-generated, data always differs)
- Istio ValidatingWebhookConfiguration failurePolicy (istiod mutates)
- Crowdsec LAPI Secrets (randomly generated)
- ServiceMonitor/PodMonitor relabeling action defaults
- StatefulSet volumeClaimTemplates apiVersion/kind defaults

Persist argocd-cm ignoreDifferences config in ArgoCD Helm values.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Scooby Husky
2026-03-10 17:32:59 -05:00
co-authored by Claude Opus 4.6
parent 4270309224
commit 131cbca4a6
39 changed files with 248 additions and 36 deletions
+7 -2
View File
@@ -5,7 +5,9 @@ metadata:
namespace: argocd
spec:
parentRefs:
- name: edge
- group: gateway.networking.k8s.io
kind: Gateway
name: edge
namespace: gateway
sectionName: https
hostnames:
@@ -16,5 +18,8 @@ spec:
type: PathPrefix
value: /
backendRefs:
- name: argocd-server
- group: ""
kind: Service
name: argocd-server
port: 80
weight: 1
+30
View File
@@ -6,6 +6,36 @@ global:
configs:
cm:
url: https://argocd.kube.huskypup.net
resource.customizations.ignoreDifferences.all: |
managedFieldsManagers:
- external-secrets
- istio-system
jqPathExpressions:
- .metadata.finalizers
resource.customizations.ignoreDifferences.external-secrets.io_ExternalSecret: |
jqPathExpressions:
- .metadata.annotations."force-sync"
- .metadata.annotations."reconcile.external-secrets.io/force-sync"
- .metadata.finalizers
- .spec.data[].remoteRef.conversionStrategy
- .spec.data[].remoteRef.decodingStrategy
- .spec.data[].remoteRef.metadataPolicy
resource.customizations.ignoreDifferences.gateway.networking.k8s.io_HTTPRoute: |
jqPathExpressions:
- .metadata.annotations
- .spec.parentRefs[].port
resource.customizations.ignoreDifferences.monitoring.coreos.com_ServiceMonitor: |
jqPathExpressions:
- .spec.endpoints[].relabelings[].action
- .spec.endpoints[].metricRelabelings[].action
resource.customizations.ignoreDifferences.monitoring.coreos.com_PodMonitor: |
jqPathExpressions:
- .spec.podMetricsEndpoints[].relabelings[].action
- .spec.podMetricsEndpoints[].metricRelabelings[].action
resource.customizations.ignoreDifferences.apps_StatefulSet: |
jqPathExpressions:
- .spec.volumeClaimTemplates[].apiVersion
- .spec.volumeClaimTemplates[].kind
oidc.config: |
name: Authentik
issuer: https://auth.kube.huskypup.net/application/o/argocd/
+7 -2
View File
@@ -5,7 +5,9 @@ metadata:
namespace: frigate
spec:
parentRefs:
- name: edge
- group: gateway.networking.k8s.io
kind: Gateway
name: edge
namespace: gateway
sectionName: https
hostnames:
@@ -16,5 +18,8 @@ spec:
type: PathPrefix
value: /
backendRefs:
- name: frigate
- group: ""
kind: Service
name: frigate
port: 5000
weight: 1
+28 -8
View File
@@ -5,7 +5,9 @@ metadata:
namespace: gitlab
spec:
parentRefs:
- name: edge
- group: gateway.networking.k8s.io
kind: Gateway
name: edge
namespace: gateway
sectionName: https
hostnames:
@@ -16,8 +18,11 @@ spec:
type: PathPrefix
value: /
backendRefs:
- name: gitlab-webservice-default
- group: ""
kind: Service
name: gitlab-webservice-default
port: 8181
weight: 1
---
apiVersion: gateway.networking.k8s.io/v1
@@ -27,7 +32,9 @@ metadata:
namespace: gitlab
spec:
parentRefs:
- name: edge
- group: gateway.networking.k8s.io
kind: Gateway
name: edge
namespace: gateway
sectionName: https
hostnames:
@@ -38,8 +45,11 @@ spec:
type: PathPrefix
value: /
backendRefs:
- name: gitlab-registry
- group: ""
kind: Service
name: gitlab-registry
port: 5000
weight: 1
---
apiVersion: gateway.networking.k8s.io/v1
@@ -49,7 +59,9 @@ metadata:
namespace: gitlab
spec:
parentRefs:
- name: edge
- group: gateway.networking.k8s.io
kind: Gateway
name: edge
namespace: gateway
sectionName: https
hostnames:
@@ -60,8 +72,11 @@ spec:
type: PathPrefix
value: /
backendRefs:
- name: gitlab-minio-svc
- group: ""
kind: Service
name: gitlab-minio-svc
port: 9000
weight: 1
---
apiVersion: gateway.networking.k8s.io/v1
@@ -71,7 +86,9 @@ metadata:
namespace: gitlab
spec:
parentRefs:
- name: edge
- group: gateway.networking.k8s.io
kind: Gateway
name: edge
namespace: gateway
sectionName: https
hostnames:
@@ -82,5 +99,8 @@ spec:
type: PathPrefix
value: /
backendRefs:
- name: gitlab-kas
- group: ""
kind: Service
name: gitlab-kas
port: 8154
weight: 1
+13 -4
View File
@@ -27,7 +27,8 @@ spec:
tls:
mode: Terminate
certificateRefs:
- kind: Secret
- group: ""
kind: Secret
name: guacamole-envoy-tls
---
@@ -38,7 +39,9 @@ metadata:
namespace: guacamole
spec:
parentRefs:
- name: guacamole
- group: gateway.networking.k8s.io
kind: Gateway
name: guacamole
sectionName: https
hostnames:
- guacamole.kube.huskypup.net
@@ -55,13 +58,19 @@ spec:
type: ReplacePrefixMatch
replacePrefixMatch: /
backendRefs:
- name: guacamole
- group: ""
kind: Service
name: guacamole
port: 8080
weight: 1
# Standard root routing
- matches:
- path:
type: PathPrefix
value: /
backendRefs:
- name: guacamole
- group: ""
kind: Service
name: guacamole
port: 8080
weight: 1
+7 -2
View File
@@ -5,7 +5,9 @@ metadata:
namespace: home-assistant
spec:
parentRefs:
- name: edge
- group: gateway.networking.k8s.io
kind: Gateway
name: edge
namespace: gateway
sectionName: https
hostnames:
@@ -16,5 +18,8 @@ spec:
type: PathPrefix
value: /
backendRefs:
- name: esphome
- group: ""
kind: Service
name: esphome
port: 6052
weight: 1
@@ -5,7 +5,9 @@ metadata:
namespace: home-assistant
spec:
parentRefs:
- name: edge
- group: gateway.networking.k8s.io
kind: Gateway
name: edge
namespace: gateway
sectionName: https
hostnames:
@@ -16,5 +18,8 @@ spec:
type: PathPrefix
value: /
backendRefs:
- name: home-assistant
- group: ""
kind: Service
name: home-assistant
port: 8123
weight: 1
+7 -2
View File
@@ -5,7 +5,9 @@ metadata:
namespace: n8n
spec:
parentRefs:
- name: edge
- group: gateway.networking.k8s.io
kind: Gateway
name: edge
namespace: gateway
sectionName: https
hostnames:
@@ -16,5 +18,8 @@ spec:
type: PathPrefix
value: /
backendRefs:
- name: n8n
- group: ""
kind: Service
name: n8n
port: 80
weight: 1
+7 -2
View File
@@ -5,7 +5,9 @@ metadata:
namespace: nextcloud
spec:
parentRefs:
- name: edge
- group: gateway.networking.k8s.io
kind: Gateway
name: edge
namespace: gateway
sectionName: https
hostnames:
@@ -16,5 +18,8 @@ spec:
type: PathPrefix
value: /
backendRefs:
- name: nextcloud
- group: ""
kind: Service
name: nextcloud
port: 8080
weight: 1
+7 -2
View File
@@ -5,7 +5,9 @@ metadata:
namespace: teslamate
spec:
parentRefs:
- name: edge
- group: gateway.networking.k8s.io
kind: Gateway
name: edge
namespace: gateway
sectionName: https
hostnames:
@@ -16,5 +18,8 @@ spec:
type: PathPrefix
value: /
backendRefs:
- name: teslamate
- group: ""
kind: Service
name: teslamate
port: 4000
weight: 1