Decision. ArgoCD is the only deploy path
Alternative. CI jobs running kubectl or helm install directly
Why. Drift becomes visible and revertible, and Git stays the single source of truth for what runs.
Watches Git and keeps the cluster in sync, with health checks and a full sync history
ArgoCD is the GitOps controller: it watches this catalog and keeps the cluster in sync with what Git declares. It is installed before everything else (Vault comes first via CI, because ArgoCD reads its own secrets from Vault through ESO). This page covers the controller itself; the argocd-apps catalog that registers every service has its own page.
The full argocd/values.yaml from the service's
own chart:
## Custom resource configuration
crds:
install: true
keep: true
configs:
params:
server.insecure: true
secret:
createSecret: false
cm:
statusbadge.enabled: "true"
resource.exclusions: |
- apiGroups:
- snapshot.storage.k8s.io
kinds:
- VolumeSnapshot
- VolumeSnapshotContent
clusters:
- "*"
accounts.reader: apiKey
accounts.reader.enabled: "true"
rbac:
policy.default: "role:readonly"
policy.csv: |
p, role:reader, applications, *, */*, allow
g, reader, role:reader
redis:
enabled: false
externalRedis:
host: valkey-opi5-cluster.g.external-redis.com
port: 22810
existingSecret: redis-user-secret
server:
ingress:
enabled: false
controller: generic
annotations:
istio.ingress.kubernetes.io/router.entrypoints: websecure
ingressClassName: istio
hostname: argocd.opi5cluster.co.uk
path: /
pathType: Prefix
tls: false
extraTls:
- hosts:
- argocd.opi5cluster.co.uk
secretName: opi5cluster-co-uk-domain-secret
extraArgs:
- --redis-use-tls
# Monitoring: expose Prometheus metrics on argocd-server-metrics:8083
# (scraped by the `monitoring` Alloy DaemonSet → New Relic).
metrics:
enabled: true
controller:
extraArgs:
- --redis-use-tls
# Monitoring: expose Prometheus metrics on
# argocd-application-controller-metrics:8082.
metrics:
enabled: true
repoServer:
extraArgs:
- --redis-use-tls
# Monitoring: expose Prometheus metrics on
# argocd-repo-server-metrics:8084.
metrics:
enabled: true
# Monitoring: expose Prometheus metrics on
# argocd-applicationset-controller-metrics:8080.
applicationSet:
metrics:
enabled: true
# Array of Extra K8s Manifests to deploy
extraObjects:
- apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: redis-user-external-secret
namespace: argocd
spec:
refreshInterval: 24h
secretStoreRef:
kind: ClusterSecretStore
name: vault-cluster-secret-store
target:
name: redis-user-secret
creationPolicy: Owner
data:
- secretKey: redis-password
remoteRef:
key: redis
property: aiven_password templates/argo-configmap.yaml ArgoCD ConfigMap overlay.
apiVersion: v1
kind: ConfigMap
metadata:
name: argocd-cm
namespace: argocd
data:
timeout.reconciliation: 30s templates/argocd-secret.yaml ArgoCD secret: SSO and GitLab credentials.
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: argocd-external-secret
namespace: argocd
spec:
refreshInterval: 12h
secretStoreRef:
kind: ClusterSecretStore
name: vault-cluster-secret-store
target:
name: argocd-secret
creationPolicy: Owner
data:
- secretKey: webhook.gitlab.secret
remoteRef:
key: gitlab/personal-credentials
property: webhook-secret
- secretKey: admin.password
remoteRef:
key: argocd
property: admin-password
- secretKey: admin.passwordMtime
remoteRef:
key: argocd
property: admin-passwordMtime
- secretKey: server.secretkey
remoteRef:
key: argocd
property: server-secretkey templates/http-route.yaml Gateway API HTTPRoute exposing the service through the Istio gateway under opi5cluster.co.uk.
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: argocd-httproute
namespace: argocd
annotations:
link.argocd.argoproj.io/external-link: "https://argocd.opi5cluster.co.uk"
spec:
parentRefs:
- name: istio-gateway
namespace: istio
sectionName: websecure
hostnames:
- argocd.opi5cluster.co.uk
rules:
- backendRefs:
- name: argocd-server
port: 80 Decision. ArgoCD is the only deploy path
Alternative. CI jobs running kubectl or helm install directly
Why. Drift becomes visible and revertible, and Git stays the single source of truth for what runs.
Decision. Bundled Redis replaced by an external managed Valkey
Alternative. The Redis chart shipped with ArgoCD
Why. One less stateful workload on the cluster, and its credentials arrive through Vault via an ExternalSecret rendered as an extra manifest.
Decision. Read-only RBAC by default (role:readonly)
Alternative. Everyone admin
Why. The UI stays safe to browse; syncs are deliberate actions, not something a viewer can trigger.