A StatefulSet's volumeClaimTemplates are immutable, and the API server injects creationTimestamp, volumeMode and a status block that are not in the manifest. ArgoCD diffed those and reported OutOfSync permanently, since no sync could ever resolve them. infisical-postgres and infisical-valkey are the only StatefulSets here using volumeClaimTemplates, which is why this app alone was affected.
40 lines
1.4 KiB
YAML
40 lines
1.4 KiB
YAML
apiVersion: argoproj.io/v1alpha1
|
|
kind: Application
|
|
metadata:
|
|
name: infisical
|
|
namespace: argocd
|
|
spec:
|
|
project: default
|
|
source:
|
|
repoURL: https://gitea.jsme.be/Jeffrey/Kubernetes-Manifests.git
|
|
path: applications/infisical
|
|
targetRevision: HEAD
|
|
directory:
|
|
recurse: true
|
|
# secret.yaml holds Infisical's own bootstrap secrets — applied out-of-band,
|
|
# committed here only as an emptied template. Never let ArgoCD apply it.
|
|
exclude: secret.yaml
|
|
destination:
|
|
server: https://kubernetes.default.svc
|
|
namespace: infisical
|
|
# A StatefulSet's volumeClaimTemplates are immutable, and the API server
|
|
# injects fields into them that are not in the manifest (creationTimestamp,
|
|
# volumeMode, a status block). ArgoCD diffs those and reports OutOfSync
|
|
# forever, since syncing can never resolve them. infisical-postgres and
|
|
# infisical-valkey are the only StatefulSets here using volumeClaimTemplates,
|
|
# which is why this app alone was affected.
|
|
ignoreDifferences:
|
|
- group: apps
|
|
kind: StatefulSet
|
|
jqPathExpressions:
|
|
- '.spec.volumeClaimTemplates[]?.metadata.creationTimestamp'
|
|
- '.spec.volumeClaimTemplates[]?.spec.volumeMode'
|
|
- '.spec.volumeClaimTemplates[]?.status'
|
|
syncPolicy:
|
|
automated:
|
|
prune: true
|
|
selfHeal: true
|
|
syncOptions:
|
|
- ApplyOutOfSyncOnly=true
|
|
- ServerSideApply=true
|