Skip to content

Switch ARDAC production portal to ardac2prd - #100

Merged
esentuna merged 1 commit into
mainfrom
codex/ardac-portal-cutover
Sep 30, 2026
Merged

esentuna merged 1 commit into
mainfrom
codex/ardac-portal-cutover

Conversation

@alan-walsh

Copy link
Copy Markdown
Contributor

Summary

  • make archive.portal.ardac.org the canonical hostname for ardac1prd
  • make portal.ardac.org the canonical hostname for ardac2prd
  • redirect stale portal traffic on the old ALB to archive
  • redirect new.portal.ardac.org on the new ALB to portal
  • pin both Gen3 Helm revisions for a deterministic cutover
  • explicitly use External Secrets v1beta1 on ardac1prd

Validation

  • git diff --check
  • yamllint on changed YAML (only two pre-existing comment-spacing warnings in values files)
  • client-side Kubernetes dry runs for both load-balancer applications and ingresses
  • full Helm render of ardac1prd at 6c432454d71bac8f86190d38eb5d6a686f47a9df
  • full Helm render of ardac2prd at 2fab13ff7e477a6600f4f18ec05d781cc93d1349
  • confirmed each render has exactly one canonical ingress and no External Secrets v1 resources

Operations

Route 53 remains a manual cutover step. Live AWS secret and Argo updates will be coordinated after this PR is reviewed and merged.

Copilot AI balanced review requested due to automatic review settings September 30, 2026 14:06

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The cutover lacks a mechanism to remove legacy live Argo Applications and their conflicting managed ingresses.

Review effort: Balanced
Findings: None

What changed in this PR

Switches the canonical ARDAC production portal from ardac1prd to ardac2prd, retaining redirects for legacy hostnames.

Changes:

  • Reassigns canonical hostnames and redirects.
  • Pins both Gen3 Helm revisions.
  • Configures External Secrets v1beta1 for ardac1prd.
File Description
ardac2prd/​README.md Documents the new hostname routing.
ardac2prd/​portal.ardac.org/​values.yaml Makes portal.ardac.org canonical.
ardac2prd/​portal.ardac.org/​app.yaml Pins the Gen3 Helm revision.
ardac2prd/​load-balancer/​manifests/​ingress.yaml Redirects new.portal to portal.
ardac1prd/​portal.ardac.org/​values.yaml Makes archive.portal canonical and pins External Secrets API.
ardac1prd/​portal.ardac.org/​app.yaml Pins the Gen3 Helm revision.
ardac1prd/​load-balancer/​manifests/​ingress.yaml Redirects stale portal traffic to archive.
ardac1prd/​load-balancer/​app.yaml Repoints and renames the load-balancer Application.
ardac1prd/​archive.portal.ardac.org/​manifests/​ingress.yaml Removes the obsolete archive redirect manifest.
ardac1prd/​archive.portal.ardac.org/​app.yaml Removes the obsolete Argo Application manifest.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@alan-walsh

Copy link
Copy Markdown
Contributor Author

Copilot review follow-up: the legacy live Applications cannot be removed by deleting these repository manifests because they are bootstrapped independently and automated pruning is disabled. After this PR merges, the cutover runbook explicitly deletes archive-portal-ardac1prd-redirect and new-portal-ardac1prd-redirect with the ardac1prd context, verifies their ingresses are gone, and then applies load-balancer-ardac1prd. This keeps destructive cleanup out of reconciliation until the canonical archive ingress is healthy.

There are no line-level review threads to resolve.

@esentuna
esentuna merged commit 7599f1e into main Sep 30, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants