Install with Argo CD
The charts need nothing that only Argo CD provides, and nothing that only Helm provides. With Argo CD you keep the same values files in Git and let it install and upgrade the products.
One Application per product, in waves
Section titled “One Application per product, in waves”Put one Argo CD Application per chart in a parent Application (the “app of apps” pattern), and order them with sync waves, the same order as the Helm install:
| Wave | Application | Ready when |
|---|---|---|
| -10 | the namespace and the Secrets that must exist first (database passwords, encryption keys, registry pull secret) | they exist |
| 0 | PostgreSQL, if you run it in the cluster (for example a CloudNativePG cluster) | the database reports healthy |
| 1 | TinyGuard | ready |
| 3 | TinyVault | ready |
| 4 | TinyConductor | ready |
| 5 | the connector runtime | ready |
apiVersion: argoproj.io/v1alpha1kind: Applicationmetadata: name: tinyconductor namespace: argocd annotations: argocd.argoproj.io/sync-wave: "4"spec: project: default destination: server: https://kubernetes.default.svc namespace: tinyblox source: repoURL: registry.tinyfactory.ai/tinyblox/charts chart: tinyconductor targetRevision: <version> helm: valueFiles: [] valuesObject: publicUrl: conductor.example.com # … as in conductor.yaml syncPolicy: automated: { prune: true, selfHeal: true } retry: { limit: 5, backoff: { duration: 30s, factor: 2, maxDuration: 5m } }Add registry.tinyfactory.ai to Argo CD as a Helm OCI repository with your
registry login. For a parent Application to wait for each wave, Argo CD
must report the health of child Applications; recent Argo CD versions need
the Application health check switched on in argocd-cm
(resource.customizations.health.argoproj.io_Application).
One-off Jobs
Section titled “One-off Jobs”The Jobs that run before a product’s pods (the database migration, and the
sign-in clients once provisioning is
released) run as Argo CD PreSync hooks. Two things differ from plain Helm:
- They run on every sync, not only on install and upgrade. That is safe: each of them changes nothing when there is nothing to do.
- A rollback in Argo CD syncs the older revision, so its
PreSynchooks run again for that revision.
TinyVault’s chart carries the Argo CD hook annotations today; the other products’ charts gain them with their next releases coming. Until then, Argo CD maps their Helm hook annotations to its own phases, with the same effect.
Secrets in Git
Section titled “Secrets in Git”Never commit secret values. Keep in Git only the names of the Secrets the charts read, and create the values with your usual tool: by hand once, or from your secret manager through the External Secrets Operator or a similar operator. A declared file for the platform’s own secrets is coming: see Platform secrets.