argo-cd: 10.4.0 (ArgoCD v3.5.1) 추가 + 배포 테스트 스크립트

k8s 1.33 에서 Deployment/ReplicaSet 에 추가된 .status.terminatingReplicas 를
ArgoCD v2.14.5(k8s 라이브러리 0.31/0.32)가 몰라, 클러스터가 1.33 이상이면
ServerSideApply=true 인 Application 이 전부 아래 오류로 죽는다.

  ComparisonError: failed to calculate diff: error calculating structured
  merge diff: .status.terminatingReplicas: field not declared in schema

v3.5.1 은 k8s 라이브러리 0.36.1 을 써서 해소된다. dev 클러스터(1.35.7+rke2r1)
에서 실제 발생·해소를 확인했다.

- manifests/helm/argo-cd/10.4.0/ 추가 (chart_updater 로 생성)
  - custom-values.yaml 을 실제 배포 기준(dipup argo-cd-values.yaml.tpl)에 맞춤:
    kong → apisix, server.extraArgs(--insecure), configs.cm/rbac 추가
  - configs.params.controller.resource.health.persist=true 지정 —
    ArgoCD v3.0 부터 리소스 health 를 CR 에 저장하지 않는 것이 기본값인데,
    dip-console-api 가 .status.resources[].health 를 읽는다
  - CUSTOM-README.md 는 현재 차트 기준 배포 가이드로 재작성.
    승계된 cert-manager 예시가 10.4.0 에 없는 구버전 스키마(hosts/tls 리스트)라
    Ingress 가 생성되지 않는 상태였던 것도 함께 수정
  - breaking_change_check: breaking=false (제거 26건이 전부 미사용 key)

- scripts/deploy-test/deploy-test-argo-cd.sh 신규
  같은 클러스터에 두 번째 argo-cd 를 띄우려면 crds.install=false 가 필수다 —
  CRD 3종이 클러스터 전역이고 운영 릴리스가 소유해 Helm 이 ownership 충돌로
  거부한다. Ingress 도 항상 끈다(운영과 host 충돌).
  검증: 워크로드 롤아웃 / health.persist / api 버전 / admin 로그인

- argo-cd/7.8.11/BUILD-README.md 에 `helm repo add argo ...` 추가
  chart_version_detector 가 이 한 줄을 정규식으로 뽑아 업스트림 레포를 정하는데,
  argo-cd 에는 없어서 신규 버전 자동 감지가 조용히 실패하고 있었다
  (repo: null → latest_version: null). CLAUDE.md 의 "변경 금지" 규정도
  실제 파싱 계약에 맞게 정정했다.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
wbsong111
2026-08-19 11:28:21 +09:00
parent acf7a016e7
commit 3aa69e5eda
181 changed files with 50818 additions and 1 deletions
@@ -0,0 +1,69 @@
{{- if and .Values.server.ingress.enabled (eq .Values.server.ingress.controller "generic") }}
{{- $insecure := index .Values.configs.params "server.insecure" | toString -}}
{{- $servicePort := eq $insecure "true" | ternary .Values.server.service.servicePortHttp .Values.server.service.servicePortHttps -}}
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: {{ include "argo-cd.server.fullname" . }}
namespace: {{ include "argo-cd.namespace" . }}
labels:
{{- include "argo-cd.labels" (dict "context" . "component" .Values.server.name "name" .Values.server.name) | nindent 4 }}
{{- with .Values.server.ingress.labels }}
{{- tpl (toYaml .) $ | nindent 4 }}
{{- end }}
{{- with .Values.server.ingress.annotations }}
annotations:
{{- range $key, $value := . }}
{{ $key }}: {{ tpl (toString $value) $ | quote }}
{{- end }}
{{- end }}
spec:
{{- with .Values.server.ingress.ingressClassName }}
ingressClassName: {{ tpl . $ }}
{{- end }}
rules:
- host: {{ tpl (.Values.server.ingress.hostname) $ | default .Values.global.domain }}
http:
paths:
{{- with .Values.server.ingress.extraPaths }}
{{- tpl (toYaml .) $ | nindent 10 }}
{{- end }}
- path: {{ .Values.server.ingress.path }}
pathType: {{ $.Values.server.ingress.pathType }}
backend:
service:
name: {{ include "argo-cd.server.fullname" . }}
port:
number: {{ $servicePort }}
{{- range .Values.server.ingress.extraHosts }}
- host: {{ tpl .name $ | quote }}
http:
paths:
- path: {{ default $.Values.server.ingress.path .path }}
pathType: {{ default $.Values.server.ingress.pathType .pathType }}
backend:
service:
name: {{ include "argo-cd.server.fullname" $ }}
port:
number: {{ $servicePort }}
{{- end }}
{{- with .Values.server.ingress.extraRules }}
{{- tpl (toYaml .) $ | nindent 4 }}
{{- end }}
{{- if or .Values.server.ingress.tls .Values.server.ingress.extraTls }}
tls:
{{- if .Values.server.ingress.tls }}
- hosts:
- {{ tpl (.Values.server.ingress.hostname) $ | default .Values.global.domain }}
{{- range .Values.server.ingress.extraHosts }}
{{- if .name }}
- {{ tpl .name $ }}
{{- end }}
{{- end }}
secretName: argocd-server-tls
{{- end }}
{{- with .Values.server.ingress.extraTls }}
{{- tpl (toYaml .) $ | nindent 4 }}
{{- end }}
{{- end }}
{{- end }}