feat: prepare the values for Argo CD v3.4.9 on argo-helm chart 10.2.2 - #67
Merged
Merged
Conversation
- Extension installer: chart >= 9.4.18 ships argocd-extension-installer v1.0.1, which exits non-zero when the tarball download fails and blocks argocd-server from starting. Set IGNORE_FAILURE=true to keep the pre-v1 fail-open behaviour (a missing extension renders nothing in the UI). - global.networkPolicy.create: true made explicit. Chart 10.0.0 flipped the default as the fix for GHSA-47m3-95c7-g2g8 (repo-server reachable from any pod); pinning it means a chart bump cannot flip it silently. Note: on the current chart 9.3.7 this already renders the same five NetworkPolicies. - Remove server.ingress.hosts/paths, ignored since chart 6.0.0 (the Ingress host comes from global.domain, path defaults to /); render unchanged. - README: CRDs come from platform-crds and must be applied server-side (the ApplicationSet CRD exceeds the client-side-apply limit since 3.3); example chart 10.2.2 and argocd_app_version v3.4.9. Rendered with chart 10.2.2 + v3.4.9, old tpl vs new tpl: the only diff is the IGNORE_FAILURE env on the otel-extension init container. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FSau4e6nS8Y7eM1nQHwq6k
…rationale Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FSau4e6nS8Y7eM1nQHwq6k
Same repo.gpkg.io/repository/raw-github/ pattern GlueKube uses for GitHub release assets, so argocd-server no longer depends on direct egress to github.com at startup. The proxy serves the tarball byte-identical to GitHub. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FSau4e6nS8Y7eM1nQHwq6k
venkatamutyala
requested review from
hamzabouissi and
yesterdaysrebel
and removed request for
yesterdaysrebel
September 17, 2026 17:09
hamzabouissi
approved these changes
Sep 18, 2026
This was referenced Sep 18, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Companion to the Kubernetes 1.35 platform upgrade (GlueOps/platform-helm-chart-platform#1498, CRDs in GlueOps/platform-crds#83 with the Argo CD pin at v3.4.9). Argo CD moves v3.2.12 -> v3.4.9 on argo-helm 9.3.7 -> 10.2.2 (10.2.2 is the last chart on the 3.4 line; it ships v3.4.6, so the image tag override this module already applies via
argocd_app_versioncarries it to v3.4.9). The chart version itself is pinned by the consumer (terraform-module-cloud-multy-prerequisites), not here.What this changes in
argocd.yaml.tplIGNORE_FAILURE: "true"on theotel-extensioninstaller envargocd-extension-installerv1.0.1, which exits non-zero when the tarball download fails and blocks argocd-server from starting. v0.0.9 always exited 0. This keeps the fail-open behaviour: a missing extension renders nothing.global.networkPolicy.create: truemade explicit, with a commenttrueas the fix for GHSA-47m3-95c7-g2g8 (repo-server reachable from any pod -> RCE). Pinning it means a future chart bump cannot flip it silently. Renders 5 NetworkPolicies:argocd-serverallows all ingress, the three controllers allow only:metricsfrom any namespace,argocd-repo-server:8081only from theargocd-*pods in the namespace; redis-ha gets none. Note: on the current chart 9.3.7 this already renders the same five policies, so applying this module version ahead of the chart bump brings the fix forward. Requires a CNI that enforces NetworkPolicy.EXTENSION_URLmoved tohttps://repo.gpkg.io/repository/raw-github/GlueOps/argo-cd-ui-extention/...raw-githubproxy pattern GlueKube uses for GitHub release assets; argocd-server no longer needs direct egress to github.com at startup. The proxy serves the tarball byte-identical to GitHub (sha256 compared).server.ingress.hosts/pathsremovedglobal.domainand the path defaults to/. Render unchanged.README: CRDs come from platform-crds and must be applied
--server-side(the ApplicationSet CRD exceeds the client-side-apply annotation limit since 3.3); example bumped to chart 10.2.2 /argocd_app_version = "v3.4.9".Upstream 3.2 -> 3.4 review (summary; full report in the platform PR thread)
Nothing in
argocd-cm,argocd-cmd-params-cmorargocd-rbac-cmthat this module sets was renamed or removed; builtin RBAC policy and resource/action lists are byte-identical between v3.2.12 and v3.4.9;oidc.config,extension.config,server.enable.proxy.extensionand--application-namespaces=*are unchanged. Behaviour changes that apply: Application health isMissingonly when all resources are missing (3.4); 3.4.4 RBAC fix for apps-in-any-namespace (ourdevelopment/*patterns still match both<project>/<app>and<project>/<ns>/<app>); bundled Helm 3.19.4 / Kustomize 5.8.1 in the repo-server (KustomizehelmChartsnow getsnamespace:propagated, so tenant Kustomize apps may show a one-time diff); go-oidc verifies signatures before claims (expired token + rotated key lands on the login page instead of auto-redirecting). CRDs v3.2.12 -> v3.4.9 are additive only, so applying them ahead of the controller is safe. Direct 3.2 -> 3.4 is supported by upstream.Verification
helm templatechart 10.2.2 +v3.4.9, old tpl vs new tpl: the only diffs are theIGNORE_FAILUREenv and the proxiedEXTENSION_URLon the init container.timeout.reconciliation.jitter: 60sadded toargocd-cm(already the in-code default), installer image v0.0.9 -> v1.0.1.argocd-cmd-params-cm,argocd-rbac-cm,oidc.config, both Ingresses and allextraObjectsunchanged.quay.repo.gpkg.io/argoproj/argocd:v3.4.9,quay.repo.gpkg.io/argoprojlabs/argocd-extension-installer:v1.0.1,ecr.repo.gpkg.io/docker/library/haproxy:3.3.10-alpine,…/redis:8.2.3-alpine(the pull-through cache briefly auto-blocks after a 429; pre-pull before rollout).Rollout order
pin.argo-cd: v3.4.9, applied server-side (safe against the running 3.2.12).argocd_app_version = "v3.4.9",argocd_helm_chart_version = "10.2.2".🤖 Generated with Claude Code
https://claude.ai/code/session_01FSau4e6nS8Y7eM1nQHwq6k