ArgoCD

Watches Git and keeps the cluster in sync, with health checks and a full sync history

ArgoCD is the GitOps controller: it watches this catalog and keeps the cluster in sync with what Git declares. It is installed before everything else (Vault comes first via CI, because ArgoCD reads its own secrets from Vault through ESO). This page covers the controller itself; the argocd-apps catalog that registers every service has its own page.

Chart values

The full argocd/values.yaml from the service's own chart:

## Custom resource configuration
crds:
  install: true
  keep: true

configs:
  params:
    server.insecure: true

  secret:
    createSecret: false

  cm:
    statusbadge.enabled: "true"
    resource.exclusions: |
      - apiGroups:
        - snapshot.storage.k8s.io
        kinds:
        - VolumeSnapshot
        - VolumeSnapshotContent
        clusters:
        - "*"
    accounts.reader: apiKey
    accounts.reader.enabled: "true"

  rbac:
    policy.default: "role:readonly"
    policy.csv: |
      p, role:reader,  applications, *, */*, allow
      g, reader, role:reader

redis:
  enabled: false

externalRedis:
  host: valkey-opi5-cluster.g.external-redis.com
  port: 22810
  existingSecret: redis-user-secret

server:
  ingress:
    enabled: false
    controller: generic
    annotations:
      istio.ingress.kubernetes.io/router.entrypoints: websecure
    ingressClassName: istio
    hostname: argocd.opi5cluster.co.uk
    path: /
    pathType: Prefix
    tls: false
    extraTls:
      - hosts:
          - argocd.opi5cluster.co.uk
        secretName: opi5cluster-co-uk-domain-secret

  extraArgs:
    - --redis-use-tls

  # Monitoring: expose Prometheus metrics on argocd-server-metrics:8083
  # (scraped by the `monitoring` Alloy DaemonSet → New Relic).
  metrics:
    enabled: true

controller:
  extraArgs:
    - --redis-use-tls

  # Monitoring: expose Prometheus metrics on
  # argocd-application-controller-metrics:8082.
  metrics:
    enabled: true

repoServer:
  extraArgs:
    - --redis-use-tls

  # Monitoring: expose Prometheus metrics on
  # argocd-repo-server-metrics:8084.
  metrics:
    enabled: true

# Monitoring: expose Prometheus metrics on
# argocd-applicationset-controller-metrics:8080.
applicationSet:
  metrics:
    enabled: true

# Array of Extra K8s Manifests to deploy
extraObjects:
  - apiVersion: external-secrets.io/v1
    kind: ExternalSecret
    metadata:
      name: redis-user-external-secret
      namespace: argocd
    spec:
      refreshInterval: 24h
      secretStoreRef:
        kind: ClusterSecretStore
        name: vault-cluster-secret-store
      target:
        name: redis-user-secret
        creationPolicy: Owner
      data:
        - secretKey: redis-password
          remoteRef:
            key: redis
            property: aiven_password

Manifests & templates

templates/argo-configmap.yaml

ArgoCD ConfigMap overlay.

Show manifest
apiVersion: v1
kind: ConfigMap
metadata:
  name: argocd-cm
  namespace: argocd
data:
  timeout.reconciliation: 30s

templates/argocd-secret.yaml

ArgoCD secret: SSO and GitLab credentials.

Show manifest
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
  name: argocd-external-secret
  namespace: argocd
spec:
  refreshInterval: 12h
  secretStoreRef:
    kind: ClusterSecretStore
    name: vault-cluster-secret-store
  target:
    name: argocd-secret
    creationPolicy: Owner
  data:
    - secretKey: webhook.gitlab.secret
      remoteRef:
        key: gitlab/personal-credentials
        property: webhook-secret
    - secretKey: admin.password
      remoteRef:
        key: argocd
        property: admin-password
    - secretKey: admin.passwordMtime
      remoteRef:
        key: argocd
        property: admin-passwordMtime
    - secretKey: server.secretkey
      remoteRef:
        key: argocd
        property: server-secretkey

templates/http-route.yaml

Gateway API HTTPRoute exposing the service through the Istio gateway under opi5cluster.co.uk.

Show manifest
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
  name: argocd-httproute
  namespace: argocd
  annotations:
    link.argocd.argoproj.io/external-link: "https://argocd.opi5cluster.co.uk"
spec:
  parentRefs:
    - name: istio-gateway
      namespace: istio
      sectionName: websecure
  hostnames:
    - argocd.opi5cluster.co.uk
  rules:
    - backendRefs:
        - name: argocd-server
          port: 80
  • The controller ConfigMap sets a 30s reconciliation interval, and the server, controller, repo-server, and ApplicationSet components all expose Prometheus metrics scraped by the monitoring stack.

Trade-offs

Decision. ArgoCD is the only deploy path

Alternative. CI jobs running kubectl or helm install directly

Why. Drift becomes visible and revertible, and Git stays the single source of truth for what runs.

Decision. Bundled Redis replaced by an external managed Valkey

Alternative. The Redis chart shipped with ArgoCD

Why. One less stateful workload on the cluster, and its credentials arrive through Vault via an ExternalSecret rendered as an extra manifest.

Decision. Read-only RBAC by default (role:readonly)

Alternative. Everyone admin

Why. The UI stays safe to browse; syncs are deliberate actions, not something a viewer can trigger.

← Back to GitOps & Delivery · All service groups