Fix diff failures on server-side-apply apps: ServerSideDiff

contour, cert-manager and external-secrets could not be compared or
synced:

  error calculating structured merge diff: error building typed value
  from live resource: .status.terminatingReplicas: field not declared
  in schema

The ServerSideApply sync option makes Argo CD compute the diff locally
against a Kubernetes schema compiled into its own binary. Argo CD v2.13
is older than this cluster: GKE runs 1.35, and Deployments there carry
status.terminatingReplicas, which went beta and on-by-default in 1.33.
Argo CD's schema has never heard of the field, so the diff aborts before
any sync can happen. Nothing is wrong with the manifests, and only the
three apps using SSA are affected.

ServerSideDiff asks the API server to compute the diff via a dry-run
apply, so the schema in use is the cluster's own. Beta since v2.10 and
supported on the running version.

The generic chart could not express this — Application metadata had no
annotations block at all — so it gains an optional per-entry
compareOptions list rather than the annotation being hardcoded.

This is a workaround for an out-of-date Argo CD, not a fix. The fix is
upgrading to a build whose bundled schema matches the cluster; every
value key this repo relies on already exists in chart 10.8.4 (Argo CD
v3.5.2), so that upgrade is mostly a vendoring exercise plus the 3.0
breaking changes (logs RBAC now enforced, fine-grained RBAC inheritance,
resource tracking moving from labels to annotations).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LEsTefWWifp4ikvhHF5s6N
This commit is contained in:
Mukul Sharma
2026-09-12 15:19:35 +05:30
co-authored by Claude Opus 5
parent 9c67afd5e0
commit c172756f34
2 changed files with 36 additions and 0 deletions
@@ -24,11 +24,26 @@
{{ $argoAppNamespace := $top.Values.argocdSpec.namespace }}
{{- $compareOptions := $config.compareOptions | default list -}}
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: '{{- if $appNameOverride }}{{ $appNameOverride }}{{- else }}{{ printf "%s-%s-%s" $appName $cluster $env }}{{- end }}'
namespace: {{ $argoAppNamespace }}
{{- if $compareOptions }}
annotations:
# Opt-in per appSpec entry, as a list of Argo CD compare options.
#
# The one that matters here is ServerSideDiff=true, which is the escape
# hatch for "field not declared in schema" diff failures. Argo CD
# normally computes the diff locally against a Kubernetes schema baked
# into its own binary, so a cluster newer than Argo CD has fields Argo
# CD has never heard of and the diff aborts. This option asks the API
# server to compute the diff instead (a dry-run apply), and the API
# server necessarily knows its own fields.
argocd.argoproj.io/compare-options: {{ join "," $compareOptions | quote }}
{{- end }}
labels:
{{ toYaml $labels | indent 4 }}
finalizers: