Reflector

Copies secrets and config maps into the namespaces that need them

Reflector copies secrets and config maps between namespaces based on label annotations. The main use is fanning out Vault-synced secrets, such as the Cloudflare DNS token, to every namespace that needs them without duplicating ExternalSecret resources.

ArgoCD configuration

Excerpt from argocd-apps/values.yaml in the argocd-apps chart, with annotations added for this site:

reflector:
  # false: installed by external-helm-repos/reflector.yaml, same pattern as ESO
  application: false
  project: k3s-services
  info: "This service is installed with the reflector.yaml file in the
    external-hel-repos folder"
  # false
  autoSync: false

Manifests & templates

argocd-apps/templates/external-helm-repos/reflector.yaml

Application manifest installing the upstream reflector chart from its public Helm repo.

Show manifest
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: reflector
  namespace: argocd
  annotations:
    meta.helm.sh/release-name: argocd-configuration
    meta.helm.sh/release-namespace: argocd
    argocd.argoproj.io/sync-wave: "-6"
  labels:
    app.kubernetes.io/managed-by: Helm
    meta.helm.sh/release-name: argocd-configuration
    meta.helm.sh/release-namespace: argocd
spec:
  destination:
    namespace: reflector
    server: https://kubernetes.default.svc
  project: k3s-services
  source:
    chart: reflector
    helm:
      parameters:
        - name: serviceAccount.name
          value: reflector-service-account
        - name: resources.requests.cpu
          value: 15m
        - name: resources.requests.memory
          value: 110M
    repoURL: https://emberstack.github.io/helm-charts
    targetRevision: 10.0.65
  syncPolicy:
    syncOptions:
      - CreateNamespace=true
      - ApplyOutOfSyncOnly=true
      - PrunePropagationPolicy=foreground

Trade-offs

Decision. Mirror one canonical secret to consumer namespaces

Alternative. Creating one ExternalSecret per namespace

Why. ESO writes the secret once from Vault, Reflector fans it out, and rotation only touches a single object.

← Back to Platform & Infrastructure · All service groups