Deploy cronjob which periodically refreshes the syn-argocd-tls
secret
#200
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Unfortunately, the argocd-operator currently doesn't refresh the certificate stored in secret
syn-argocd-tls
even when the certificate is expired or expires soon (cf. https://github.com/argoproj-labs/argocd-operator/blob/17e355a31b8e2bb7c2ad9a349818e2940bf22fd8/controllers/argocd/secret.go#L224-L257).To circumvent the certificate expiring (the lifetime is hardcoded to 1 year), we deploy a CronJob which deletes the
syn-argocd-tls
secret every 4 months to force the operator to recreate it with a new certificate.Checklist
changelog.
The PR has a meaningful description that sums up the change. It will be
linked in the changelog.
bug
,enhancement
,documentation
,change
,breaking
,dependency
as they show up in the changelog.