From 7a8eb2046f20db33be81cb5cbfaae8b41328baa9 Mon Sep 17 00:00:00 2001 From: Scooby Husky Date: Tue, 10 Mar 2026 19:53:10 -0500 Subject: [PATCH] Fix n8n, gitlab, and netbird-operator degraded states - n8n: Set replicaCount=1 (RWO PVC incompatible with multiple replicas), add resource limits to satisfy Kyverno policy - gitlab: Add ignoreDifferences for redis-gitlab-additional service (port names and selectors managed by Redis operator) - netbird-operator: Add ExternalSecret for netbird-mgmt-api-key in netbird namespace and add manifests source to Application Co-Authored-By: Claude Opus 4.6 --- apps/n8n/values.yaml | 8 +++++--- argocd-apps/apps/gitlab.yaml | 8 ++++++++ .../infrastructure/netbird-operator.yaml | 3 +++ .../manifests/external-secret.yaml | 18 ++++++++++++++++++ 4 files changed, 34 insertions(+), 3 deletions(-) create mode 100644 infrastructure/netbird-operator/manifests/external-secret.yaml diff --git a/apps/n8n/values.yaml b/apps/n8n/values.yaml index 82ce426..34db655 100644 --- a/apps/n8n/values.yaml +++ b/apps/n8n/values.yaml @@ -40,8 +40,8 @@ config: secret: {} # --- Deployment replicas --- -# Increased to 2 for high availability and faster response times -replicaCount: 2 +# Single replica required: RWO PVC can't be shared across pods on different nodes +replicaCount: 1 # --- Service configuration --- service: @@ -72,11 +72,13 @@ persistence: size: 10Gi # --- Resources --- -# No CPU limits (burst allowed). Keep requests minimal for scheduling. resources: requests: cpu: 100m memory: 512Mi + limits: + cpu: "1" + memory: 1Gi # --- Startup probe --- # Allows app to start without being killed by liveness probe diff --git a/argocd-apps/apps/gitlab.yaml b/argocd-apps/apps/gitlab.yaml index e964ccb..814aadb 100644 --- a/argocd-apps/apps/gitlab.yaml +++ b/argocd-apps/apps/gitlab.yaml @@ -25,6 +25,14 @@ spec: destination: server: https://kubernetes.default.svc namespace: gitlab + ignoreDifferences: + # Redis operator reconciles this service with different port names and selectors + - group: "" + kind: Service + name: redis-gitlab-additional + jsonPointers: + - /spec/ports + - /spec/selector syncPolicy: automated: prune: true diff --git a/argocd-apps/infrastructure/netbird-operator.yaml b/argocd-apps/infrastructure/netbird-operator.yaml index 904fa41..a78c942 100644 --- a/argocd-apps/infrastructure/netbird-operator.yaml +++ b/argocd-apps/infrastructure/netbird-operator.yaml @@ -19,6 +19,9 @@ spec: - repoURL: https://gitlab.kube.huskypup.net/Scooby/Homelabv4.git targetRevision: main ref: values + - repoURL: https://gitlab.kube.huskypup.net/Scooby/Homelabv4.git + targetRevision: main + path: infrastructure/netbird-operator/manifests destination: server: https://kubernetes.default.svc namespace: netbird diff --git a/infrastructure/netbird-operator/manifests/external-secret.yaml b/infrastructure/netbird-operator/manifests/external-secret.yaml new file mode 100644 index 0000000..a3e11ac --- /dev/null +++ b/infrastructure/netbird-operator/manifests/external-secret.yaml @@ -0,0 +1,18 @@ +apiVersion: external-secrets.io/v1 +kind: ExternalSecret +metadata: + name: netbird-mgmt-api-key + namespace: netbird +spec: + refreshInterval: 1h + secretStoreRef: + kind: ClusterSecretStore + name: vault-backend + target: + name: netbird-mgmt-api-key + creationPolicy: Owner + data: + - secretKey: NB_API_KEY + remoteRef: + key: netbird-api-token + property: api-token