apiVersion: argoproj.io/v1alpha1 kind: Application metadata: name: gitlab namespace: argocd annotations: argocd.argoproj.io/sync-wave: "50" finalizers: - resources-finalizer.argocd.argoproj.io spec: project: applications sources: - repoURL: https://charts.gitlab.io chart: gitlab targetRevision: 7.7.0 helm: valueFiles: - $values/apps/gitlab/values.yaml - repoURL: https://gitlab.kube.huskypup.net/Scooby/Homelabv4.git targetRevision: main ref: values - repoURL: https://gitlab.kube.huskypup.net/Scooby/Homelabv4.git targetRevision: main path: apps/gitlab/manifests destination: server: https://kubernetes.default.svc namespace: gitlab ignoreDifferences: # Redis operator reconciles this service with different port names and selectors - group: "" kind: Service name: redis-gitlab-additional jsonPointers: - /spec/ports - /spec/selector # GitLab cross-site replication (see # /home/scooby/.claude/plans/jiggly-snacking-iverson.md) - the chart # has no mechanism to register an externally-hosted (VPS) Gitaly node # into Praefect's virtual storage. Lets the live ConfigMap's `data` # be kubectl-patched directly (see apps/gitlab/manifests/ # praefect-ha-configmap.yaml for the content + patch command) without # ArgoCD reverting it on the next sync - Helm still creates the # object and everything else about it stays normally managed. - group: "" kind: ConfigMap name: gitlab-praefect jsonPointers: - /data syncPolicy: automated: prune: true selfHeal: true managedNamespaceMetadata: labels: pod-security.kubernetes.io/enforce: privileged syncOptions: - CreateNamespace=true - ServerSideApply=true - ServerSideDiff=true - RespectIgnoreDifferences=true