# ArgoCD Helm Values — Bootstrap Mode (SOPS plugin added post-bootstrap) # Chart: https://github.com/argoproj/argo-helm global: domain: argocd.riotpiao.com # Server configuration server: # Ingress is managed declaratively in k8s/bootstrap/ingress/ingress.yaml # (ssl-passthrough) instead of here — two Ingress objects for the same # host caused undefined nginx routing behavior (502s). Do not re-enable. ingress: enabled: false resources: requests: cpu: 100m memory: 256Mi limits: cpu: 500m memory: 1Gi # Tolerations for control-plane tolerations: - key: node-role.kubernetes.io/control-plane operator: Exists effect: NoSchedule # Repo server configuration repoServer: resources: requests: cpu: 100m memory: 256Mi limits: cpu: 1000m memory: 1Gi # Tolerations for control-plane tolerations: - key: node-role.kubernetes.io/control-plane operator: Exists effect: NoSchedule # SOPS decryption is now done natively inside kustomize via the ksops exec # generator (see k8s/argocd/secrets/), not a CMP sidecar. The repo-server's # own `kustomize build --enable-alpha-plugins --enable-exec` runs ksops, which # shells out to sops using the age key at SOPS_AGE_KEY_FILE. Install sops + # ksops into a shared emptyDir on PATH; the repo-server container mounts them. env: - name: SOPS_AGE_KEY_FILE value: /sops-age/key.txt - name: XDG_CONFIG_HOME value: /.config initContainers: - name: install-sops-ksops image: alpine:3.20 command: [sh, -c] args: - | set -e apk add --no-cache curl tar curl -sSL -o /custom-tools/sops \ https://github.com/getsops/sops/releases/download/v3.9.3/sops-v3.9.3.linux.amd64 chmod +x /custom-tools/sops curl -sSL https://github.com/viaduct-ai/kustomize-sops/releases/download/v4.5.1/ksops_4.5.1_Linux_x86_64.tar.gz \ | tar -xz -C /custom-tools ksops chmod +x /custom-tools/ksops volumeMounts: - mountPath: /custom-tools name: custom-tools volumeMounts: - mountPath: /usr/local/bin/sops name: custom-tools subPath: sops - mountPath: /usr/local/bin/ksops name: custom-tools subPath: ksops - mountPath: /sops-age name: sops-age readOnly: true volumes: - name: custom-tools emptyDir: {} - name: sops-age secret: secretName: sops-age # Controller configuration controller: resources: requests: cpu: 200m memory: 512Mi limits: cpu: 1000m memory: 2Gi # Tolerations for control-plane tolerations: - key: node-role.kubernetes.io/control-plane operator: Exists effect: NoSchedule # Application controller configuration applicationSet: enabled: true # Notifications (optional, for Slack/Discord alerts) notifications: enabled: false # Redis for caching redis: enabled: true resources: requests: cpu: 50m memory: 64Mi limits: cpu: 200m memory: 256Mi # ArgoCD configuration configs: # Default project allows all repos cm: admin.enabled: "true" application.instanceLabelKey: argocd.argoproj.io/instance # Let every kustomize build run the ksops exec generator. kustomize.buildOptions: --enable-alpha-plugins --enable-exec params: server.insecure: false # RBAC (allow admin full access) rbac: policy.default: role:readonly policy.csv: | g, admin, role:admin