Skip to content

Install with Argo CD

The charts need nothing that only Argo CD provides, and nothing that only Helm provides. With Argo CD you keep the same values files in Git and let it install and upgrade the products.

Put one Argo CD Application per chart in a parent Application (the “app of apps” pattern), and order them with sync waves, the same order as the Helm install:

Wave Application Ready when
-10 the namespace and the Secrets that must exist first (database passwords, encryption keys, registry pull secret) they exist
0 PostgreSQL, if you run it in the cluster (for example a CloudNativePG cluster) the database reports healthy
1 TinyGuard ready
3 TinyVault ready
4 TinyConductor ready
5 the connector runtime ready
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: tinyconductor
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "4"
spec:
project: default
destination:
server: https://kubernetes.default.svc
namespace: tinyblox
source:
repoURL: registry.tinyfactory.ai/tinyblox/charts
chart: tinyconductor
targetRevision: <version>
helm:
valueFiles: []
valuesObject:
publicUrl: conductor.example.com
# … as in conductor.yaml
syncPolicy:
automated: { prune: true, selfHeal: true }
retry: { limit: 5, backoff: { duration: 30s, factor: 2, maxDuration: 5m } }

Add registry.tinyfactory.ai to Argo CD as a Helm OCI repository with your registry login. For a parent Application to wait for each wave, Argo CD must report the health of child Applications; recent Argo CD versions need the Application health check switched on in argocd-cm (resource.customizations.health.argoproj.io_Application).

The Jobs that run before a product’s pods (the database migration, and the sign-in clients once provisioning is released) run as Argo CD PreSync hooks. Two things differ from plain Helm:

  • They run on every sync, not only on install and upgrade. That is safe: each of them changes nothing when there is nothing to do.
  • A rollback in Argo CD syncs the older revision, so its PreSync hooks run again for that revision.

TinyVault’s chart carries the Argo CD hook annotations today; the other products’ charts gain them with their next releases coming. Until then, Argo CD maps their Helm hook annotations to its own phases, with the same effect.

Never commit secret values. Keep in Git only the names of the Secrets the charts read, and create the values with your usual tool: by hand once, or from your secret manager through the External Secrets Operator or a similar operator. A declared file for the platform’s own secrets is coming: see Platform secrets.