Files
Scooby HuskyandClaude Opus 4.6 ff00f666a0 Add privileged PodSecurity label to 8 namespaces for NetBird router
NetBird router deployments require NET_ADMIN capability, which is
blocked by the default baseline PodSecurity standard. Add
managedNamespaceMetadata with pod-security.kubernetes.io/enforce:
privileged to argocd, frigate, gitlab, grafana, guacamole,
home-assistant, teslamate, and vault ArgoCD Applications.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-15 22:27:39 -05:00

48 lines
1.3 KiB
YAML

apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: gitlab
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "50"
finalizers:
- resources-finalizer.argocd.argoproj.io
spec:
project: applications
sources:
- repoURL: https://charts.gitlab.io
chart: gitlab
targetRevision: 7.7.0
helm:
valueFiles:
- $values/apps/gitlab/values.yaml
- repoURL: https://gitlab.kube.huskypup.net/Scooby/Homelabv4.git
targetRevision: main
ref: values
- repoURL: https://gitlab.kube.huskypup.net/Scooby/Homelabv4.git
targetRevision: main
path: apps/gitlab/manifests
destination:
server: https://kubernetes.default.svc
namespace: gitlab
ignoreDifferences:
# Redis operator reconciles this service with different port names and selectors
- group: ""
kind: Service
name: redis-gitlab-additional
jsonPointers:
- /spec/ports
- /spec/selector
syncPolicy:
automated:
prune: true
selfHeal: true
managedNamespaceMetadata:
labels:
pod-security.kubernetes.io/enforce: privileged
syncOptions:
- CreateNamespace=true
- ServerSideApply=true
- ServerSideDiff=true
- RespectIgnoreDifferences=true