Mukul Sharma 83f4aa0259 Add the toolshed session signing key from Vault
Only api gets the private half. The gateway is given the public half in
plain Helm values, and that asymmetry is the point: the gateway
terminates traffic for every deployed app, so holding only a verification
key means compromising it cannot forge a session for anyone.

The two halves must be installed together — a private key here that does
not match the public key in the gateway's values means every session api
issues is rejected and every app redirects to login forever.
2026-09-04 17:06:50 +05:30
fix
2026-08-31 00:49:44 +05:30
fix
2026-08-31 00:49:44 +05:30
2026-08-31 13:18:18 +05:30
add
2026-08-31 01:02:22 +05:30
2026-08-31 09:02:30 +05:30
2026-08-26 04:03:34 +05:30

devops-infra-argo-config

GitOps control plane for infrastructure tooling across Meesho's Kubernetes fleet.

This repo manages ArgoCD Application resources for every infrastructure tool (Contour, VictoriaMetrics, Grafana, Kyverno, KEDA, external-secrets, Vault, etc.) deployed across ~19 clusters. It uses an App-of-Applications pattern: one parent Application per cluster renders child Applications from a appSpec[] list via a generic Helm chart.

Each environment tracks a dedicated branch — merging to that branch triggers immediate ArgoCD auto-sync with no staging gate:

Environment Branch
Production (prd) main
Staging (stg) develop
Integration (int) pre-prod

How it works

incubator/<env>/<cluster>.yaml          ← Parent Application (one per cluster)
    └── points at generic-argo-apps-chart/ + values/<env>/<cluster>-values.yaml
            └── renders one child Application per appSpec[] entry
                    └── sources charts + overrides from devops-infra-helm-charts

Directory structure

Directory Purpose
incubator/<env>/ Parent ArgoCD Application YAML, one per cluster
values/<env>/ Values files defining which tools deploy per cluster
generic-argo-apps-chart/ Helm chart that renders child Applications from appSpec[]
projects/ ArgoCD AppProject definitions (sre, sec)
external-name-service-*/ Cross-cluster DNS routing (ExternalName / MCS topology)
docs/ Agent-facing operational documentation
skills/ Parameterized agent tasks for common operations
wiki/ Architecture decisions and entity pages

Getting started

Common operations

Task Procedure
Add a tool to a cluster docs/platform/procedures/add-tool-to-cluster.md
Upgrade a chart version docs/platform/procedures/upgrade-chart-version.md
Onboard a new cluster docs/platform/procedures/add-new-cluster.md
Roll out a tool fleet-wide docs/platform/procedures/fleet-wide-tool-rollout.md
Debug sync failure docs/platform/runbooks/argocd-sync-failure.md
Debug Helm render error docs/platform/runbooks/render-failure.md
Find values inconsistencies across clusters docs/platform/runbooks/values-drift.md
Debug stuck deployment docs/platform/runbooks/deployment-stuck.md

Sister repos

  • devops-infra-helm-charts — Helm charts and custom-values.yaml overrides. Every appSpec[].chartDir and valuesDir must exist here.
  • devops-argo-config — Same pattern for service/application workloads (not infra tooling).
S
Description
No description provided
Readme
223 KiB