diff --git a/infrastructure/vps-standby/authentik/manifests/presync-job.yaml b/infrastructure/vps-standby/authentik/manifests/presync-job.yaml index 6d3eaa8..5ee2125 100644 --- a/infrastructure/vps-standby/authentik/manifests/presync-job.yaml +++ b/infrastructure/vps-standby/authentik/manifests/presync-job.yaml @@ -3,17 +3,39 @@ # infrastructure/authentik/manifests/presync-job.yaml, scoped to a # dedicated ServiceAccount here (no shared argocd-hook-sa exists on the # vps-standby cluster the way it does at home). +# +# SA/Role/RoleBinding are PreSync hooks too (hook-weight "-1", before the +# Job's default weight "0") - without that they're just regular resources +# applied in ArgoCD's normal Sync phase, which runs AFTER PreSync hooks, +# so the Job's pod would fail to create with "serviceaccount not found" +# (confirmed live 2026-08-18). apiVersion: v1 kind: ServiceAccount metadata: name: authentik-hook namespace: authentik + annotations: + argocd.argoproj.io/hook: PreSync + argocd.argoproj.io/hook-weight: "-1" + # No hook-delete-policy here on purpose: SA/Role/RoleBinding aren't + # Jobs, so ArgoCD treats them as immediately "succeeded" on creation - + # a HookSucceeded delete policy would remove the SA right away, + # possibly racing with (or before) the weight "0" Job below that + # actually needs it to still exist while it runs. --- apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: authentik-hook namespace: authentik + annotations: + argocd.argoproj.io/hook: PreSync + argocd.argoproj.io/hook-weight: "-1" + # No hook-delete-policy here on purpose: SA/Role/RoleBinding aren't + # Jobs, so ArgoCD treats them as immediately "succeeded" on creation - + # a HookSucceeded delete policy would remove the SA right away, + # possibly racing with (or before) the weight "0" Job below that + # actually needs it to still exist while it runs. rules: - apiGroups: [""] resources: ["secrets"] @@ -27,6 +49,14 @@ kind: RoleBinding metadata: name: authentik-hook namespace: authentik + annotations: + argocd.argoproj.io/hook: PreSync + argocd.argoproj.io/hook-weight: "-1" + # No hook-delete-policy here on purpose: SA/Role/RoleBinding aren't + # Jobs, so ArgoCD treats them as immediately "succeeded" on creation - + # a HookSucceeded delete policy would remove the SA right away, + # possibly racing with (or before) the weight "0" Job below that + # actually needs it to still exist while it runs. subjects: - kind: ServiceAccount name: authentik-hook @@ -43,6 +73,7 @@ metadata: namespace: authentik annotations: argocd.argoproj.io/hook: PreSync + argocd.argoproj.io/hook-weight: "0" argocd.argoproj.io/hook-delete-policy: BeforeHookCreation spec: backoffLimit: 3