Some checks failed
validate / lint (push) Failing after 1s
The placeholder targetRevision reached origin/main and broke the Application's comparison (ComparisonError: "improper constraint: REPLACE_ME"), showing as a broken card in the Argo CD UI. The actual Authentik pods were never affected (sync policy has no `automated` block, so nothing was ever applied against the live release) -- confirmed all authentik namespace pods stayed Running 1/1 throughout. Fixed using the real deployed chart version read off the live authentik-server pod's helm.sh/chart=authentik-2026.2.1 label, not a guess. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
32 lines
985 B
YAML
32 lines
985 B
YAML
# targetRevision below is confirmed against the live deployment's
|
|
# helm.sh/chart=authentik-2026.2.1 label on the authentik-server pod (checked
|
|
# 2026-07-23) -- not a guess. Sync is still left manual (no `automated:`
|
|
# block): diff with `kubectl diff` / `argocd app diff` before enabling
|
|
# automated sync, since Authentik is the SSO IdP gating Argo CD/Grafana/Gitea
|
|
# logins.
|
|
apiVersion: argoproj.io/v1alpha1
|
|
kind: Application
|
|
metadata:
|
|
name: authentik
|
|
namespace: argocd
|
|
annotations:
|
|
argocd.argoproj.io/sync-wave: "-1"
|
|
spec:
|
|
project: default
|
|
sources:
|
|
- repoURL: https://charts.goauthentik.io
|
|
chart: authentik
|
|
targetRevision: "2026.2.1"
|
|
helm:
|
|
valueFiles:
|
|
- $values/values/authentik.yaml
|
|
- repoURL: https://gitea.nik4nao.com/nik/homelab.git
|
|
targetRevision: main
|
|
ref: values
|
|
destination:
|
|
server: https://kubernetes.default.svc
|
|
namespace: authentik
|
|
syncPolicy:
|
|
syncOptions:
|
|
- CreateNamespace=true
|