mirror of
https://gitlab.kube.huskypup.net/Scooby/Homelabv4.git
synced 2026-08-20 23:16:49 +00:00
Fix ArgoCD ServerSideDiff permanent OutOfSync diffs
Add explicit CRD/API defaults to manifests that were causing ArgoCD's SSA dry-run to produce results different from live state: - HTTPRoutes: add group, kind, weight defaults to parentRefs/backendRefs - Kyverno ClusterPolicies: add skipBackgroundRequests, allowExistingViolations - Tetragon TracingPolicies: add return, maxData, resolve, returnCopy defaults - Gateway certificateRefs: add group="" default - Guacamole Gateway: add group="" to certificateRefs Add ignoreDifferences for resources that legitimately differ: - Cilium cert Secrets (auto-generated, data always differs) - Istio ValidatingWebhookConfiguration failurePolicy (istiod mutates) - Crowdsec LAPI Secrets (randomly generated) - ServiceMonitor/PodMonitor relabeling action defaults - StatefulSet volumeClaimTemplates apiVersion/kind defaults Persist argocd-cm ignoreDifferences config in ArgoCD Helm values. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
4270309224
commit
131cbca4a6
@@ -14,6 +14,7 @@ spec:
|
||||
background: true
|
||||
rules:
|
||||
- name: check-namespace-ambient-label
|
||||
skipBackgroundRequests: true
|
||||
match:
|
||||
any:
|
||||
- resources:
|
||||
@@ -74,6 +75,7 @@ spec:
|
||||
- user-*
|
||||
- cluster-fleet-*
|
||||
validate:
|
||||
allowExistingViolations: true
|
||||
message: "Application namespaces must have istio.io/dataplane-mode=ambient for zero-trust mTLS."
|
||||
pattern:
|
||||
metadata:
|
||||
|
||||
Reference in New Issue
Block a user