diff --git a/.env.example b/.env.example deleted file mode 100644 index afe6aee..0000000 --- a/.env.example +++ /dev/null @@ -1,2 +0,0 @@ -# Generate with: htpasswd -nbBC 10 "" YOUR_PASSWORD | tr -d ':\n' | sed 's/$2y/$2a/' -ARGOCD_ADMIN_PASSWORD_HASH= diff --git a/README.md b/README.md index 6c458a7..71fa09a 100644 --- a/README.md +++ b/README.md @@ -46,27 +46,13 @@ helm version --- -## Phase 2 — Set credentials - -Install tools (one-time): +## Phase 2 — Install tools ```bash -sudo dnf install -y httpd-tools gettext +sudo dnf install -y httpd-tools ``` -Copy and fill in `.env`: - -```bash -cp .env.example .env -``` - -Generate bcrypt hash and set it in `.env`: - -```bash -htpasswd -nbBC 10 "" YOUR_PASSWORD | tr -d ':\n' | sed 's/$2y/$2a/' -``` - -`.env` is gitignored — never commit it. +`htpasswd` is used in Phase 3.1 to generate the admin password hash. No `.env` file, no `envsubst` — the password never touches Git. --- @@ -82,15 +68,13 @@ helm repo add argo https://argoproj.github.io/argo-helm helm repo update ``` -Install ArgoCD (`envsubst` fills `$ARGOCD_ADMIN_PASSWORD_HASH` from `.env` before helm reads the values): +Install ArgoCD: ```bash -source .env +helm install argocd argo/argo-cd -n argocd --create-namespace -f manifests/argocd/values.yaml ``` -```bash -envsubst < manifests/argocd/values.yaml | helm install argocd argo/argo-cd -n argocd --create-namespace -f - -``` +`values.yaml` deliberately has no `configs.secret` block — the chart auto-generates a random admin password, stored in `argocd-initial-admin-secret`. That's replaced with your own in 3.1. Wait for ArgoCD to be ready: @@ -98,30 +82,29 @@ Wait for ArgoCD to be ready: kubectl wait --for=condition=available deployment/argocd-server -n argocd --timeout=120s ``` -Port-forward to access UI (MetalLB + Envoy not running yet): +Check pods are up: ```bash -kubectl port-forward svc/argocd-server -n argocd 8080:443 +kubectl get pods -n argocd ``` -Open `https://localhost:8080` — login with `admin` and the password you chose. +> UI login isn't needed for bootstrap (Phase 4 applies the root Application via `kubectl`). Only port-forward if you want to inspect ArgoCD manually: `kubectl port-forward svc/argocd-server -n argocd 8080:443`, then open `https://localhost:8080` with `admin` / your chosen password. -### 3.1 Bake the hash into values.yaml for self-management +### 3.1 Set your own admin password directly on the Secret -ArgoCD won't run `envsubst` when it self-manages — replace the placeholder with the real hash so future syncs work: +Set it once, straight on `argocd-secret` (the Secret ArgoCD actually reads) — never in `values.yaml`, never committed to Git: ```bash -source .env -sed -i "s|\$ARGOCD_ADMIN_PASSWORD_HASH|$ARGOCD_ADMIN_PASSWORD_HASH|" manifests/argocd/values.yaml +read -s -p "ArgoCD admin password: " PW; echo +HASH=$(htpasswd -nbBC 12 "" "$PW" | tr -d ':\n' | sed 's/$2y/$2a/') +kubectl patch secret argocd-secret -n argocd --type merge -p \ + "{\"stringData\":{\"admin.password\":\"$HASH\",\"admin.passwordMtime\":\"$(date -u +%FT%TZ)\"}}" +unset PW HASH ``` -```bash -git add manifests/argocd/values.yaml && git commit -m "set argocd admin password hash" -``` +**Why this stays stable across self-management:** `values.yaml` never declares `configs.secret.argocdServerAdminPassword`, so the Helm chart's rendered manifest never includes `admin.password`/`admin.passwordMtime`. Once ArgoCD self-manages (wave -1, `selfHeal: true`), it only reconciles fields present in its own rendered output — it has no opinion on keys it never declared, so your patched hash survives every sync, forever. If that block is ever added back to `values.yaml`, the next self-heal overwrites it — don't add it. -```bash -git push origin main -``` +To rotate later: repeat the same `kubectl patch` with a new hash and a new `admin.passwordMtime` (ArgoCD only accepts the change if the Mtime also changes). --- diff --git a/manifests/argocd/values.yaml b/manifests/argocd/values.yaml index a284b5f..b9ab66f 100644 --- a/manifests/argocd/values.yaml +++ b/manifests/argocd/values.yaml @@ -18,9 +18,6 @@ global: configs: params: server.insecure: true # TLS terminated at Envoy Gateway - secret: - argocdServerAdminPassword: "$ARGOCD_ADMIN_PASSWORD_HASH" - argocdServerAdminPasswordMtime: "2025-01-01T00:00:00Z" server: replicas: 1