2.3 KiB
Argo CD examples
This directory is excluded from the packaged Helm chart. Its files are examples for managing the chart from Argo CD.
Application
application.yaml deploys:
- three Redis shards;
- one replica per shard;
- authenticated Redis with a chart-generated initial password;
- persistent volumes using the cluster's default StorageClass;
- internal-only Redis Services;
- RedisInsight connected automatically to the balanced bootstrap endpoint.
Apply it once:
kubectl apply -f argocd/application.yaml
Edit the destination namespace, target revision, and inline valuesObject as
needed. Because this file is not a Helm template, changing it in the Redis
Application's own repository does not change the live Application spec during a
normal sync. Reapply it, or manage it from an app-of-apps/ApplicationSet.
Password Secret
For production GitOps, use an externally managed Secret and set:
auth:
enabled: true
existingSecret: redis-auth
existingSecretKey: redis-password
redis-auth-secret.example.yaml documents the
required Secret shape. Do not commit an actual cleartext password.
If the chart generates the password, retain
RespectIgnoreDifferences=true and the Secret ignore rule from
application.yaml; Argo's Helm renderer cannot use lookup to read the live
Secret while comparing desired state.
Enabling external access
Add this to valuesObject:
externalAccess:
enabled: true
loadBalancerClass: ""
loadBalancerSourceRanges:
- 203.0.113.0/24
This creates one balanced bootstrap LoadBalancer and one LoadBalancer per Redis member. Every advertised member address must be routable from external clients.
Exposing RedisInsight with Istio
Add:
redisInsight:
enabled: true
ingress:
enabled: true
host: redisinsight.example.com
tls:
enabled: true
credentialName: redisinsight-tls
certificate:
create: true
issuerName: letsencrypt-production
issuerKind: ClusterIssuer
secretNamespace: istio-system
Replace the hostname, issuer, gateway selector, and Secret namespace with values from your environment. RedisInsight has no built-in ingress authentication; add an identity-aware proxy or Istio authorization policy before exposing it.