Scooby Husky and Claude Opus 4.6
131cbca4a6
Fix ArgoCD ServerSideDiff permanent OutOfSync diffs
...
Add explicit CRD/API defaults to manifests that were causing ArgoCD's
SSA dry-run to produce results different from live state:
- HTTPRoutes: add group, kind, weight defaults to parentRefs/backendRefs
- Kyverno ClusterPolicies: add skipBackgroundRequests, allowExistingViolations
- Tetragon TracingPolicies: add return, maxData, resolve, returnCopy defaults
- Gateway certificateRefs: add group="" default
- Guacamole Gateway: add group="" to certificateRefs
Add ignoreDifferences for resources that legitimately differ:
- Cilium cert Secrets (auto-generated, data always differs)
- Istio ValidatingWebhookConfiguration failurePolicy (istiod mutates)
- Crowdsec LAPI Secrets (randomly generated)
- ServiceMonitor/PodMonitor relabeling action defaults
- StatefulSet volumeClaimTemplates apiVersion/kind defaults
Persist argocd-cm ignoreDifferences config in ArgoCD Helm values.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-10 17:32:59 -05:00
Scooby Husky and Claude Opus 4.6
782a271e17
Revert Ceph to v19.2.0 - v19.2.3 has same expand-bluefs issue
...
BlueStore has UUID inconsistency at block position 0x0 that causes
expand_devices assertion in both v19.2.0 and v19.2.3. The OSD
daemon itself runs fine; only expand-bluefs init container crashes.
Will use deployment patches with do-not-reconcile annotation instead.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-10 06:00:45 -05:00
Scooby Husky and Claude Opus 4.6
fefa183db7
Upgrade Ceph to v19.2.3, fix netbird webhook failurePolicy
...
- Ceph v19.2.0 has BlueStore::expand_devices assertion bug that
crashes OSD expand-bluefs init containers. v19.2.3 includes fixes.
- NetBird operator webhook failurePolicy: Fail blocks all pod
creation cluster-wide when webhook service is unreachable.
Changed to Ignore.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-10 05:29:39 -05:00
Scooby Husky and Claude Opus 4.6
7640fb895b
Fix degraded ArgoCD applications
...
- frigate: Remove duplicate PVCs (Helm manages them), update config size to 15Gi
- gitlab: Fix sync-admin-job secretKeyRef schema error, fetch password via kubectl
- nextcloud: Remove duplicate PVC, remove invalid pod-level securityContext
- rook-ceph: Update cephfs-smb-pvc to 50Gi, remove unsupported dashboard.config
- nessus: Add privileged PSS label for NET_ADMIN/NET_RAW capabilities
- scylla-manager: Add privileged PSS label for SYS_NICE capability
- n8n: Create missing n8n-main-persistence PVC
- projects: Add authentik namespace to applications project destinations
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-10 00:05:29 -05:00
Scooby Husky
aacb8eebbe
Initial commit
2026-03-09 20:21:35 -05:00