89a0aacbd75cb397ad339dca83421a8705d786be
Deliberately separate from harbor-robot-dockerconfig, which is mounted into build pods running arbitrary user Dockerfiles and is scoped to push+pull only. This one is held by builder itself — a trusted platform service that never executes user code directly — and carries a permission the other should never have: delete. A leaked build-pod credential can never delete anything this way, and a leaked cleanup credential can never push. Used by toolshed's cleanupImage (internal/builder/builder.go) to remove an app's Harbor repository when the app itself is deleted. Nothing destructive happens until the Vault path this pulls from is actually populated — builder logs and skips that step otherwise, per its own code comment. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Wajog7nELA3i8JWTjxYGHF
devops-infra-argo-config
GitOps control plane for infrastructure tooling across Meesho's Kubernetes fleet.
This repo manages ArgoCD Application resources for every infrastructure tool (Contour, VictoriaMetrics, Grafana, Kyverno, KEDA, external-secrets, Vault, etc.) deployed across ~19 clusters. It uses an App-of-Applications pattern: one parent Application per cluster renders child Applications from a appSpec[] list via a generic Helm chart.
Each environment tracks a dedicated branch — merging to that branch triggers immediate ArgoCD auto-sync with no staging gate:
| Environment | Branch |
|---|---|
| Production (prd) | main |
| Staging (stg) | develop |
| Integration (int) | pre-prod |
How it works
incubator/<env>/<cluster>.yaml ← Parent Application (one per cluster)
└── points at generic-argo-apps-chart/ + values/<env>/<cluster>-values.yaml
└── renders one child Application per appSpec[] entry
└── sources charts + overrides from devops-infra-helm-charts
Directory structure
| Directory | Purpose |
|---|---|
incubator/<env>/ |
Parent ArgoCD Application YAML, one per cluster |
values/<env>/ |
Values files defining which tools deploy per cluster |
generic-argo-apps-chart/ |
Helm chart that renders child Applications from appSpec[] |
projects/ |
ArgoCD AppProject definitions (sre, sec) |
external-name-service-*/ |
Cross-cluster DNS routing (ExternalName / MCS topology) |
docs/ |
Agent-facing operational documentation |
skills/ |
Parameterized agent tasks for common operations |
wiki/ |
Architecture decisions and entity pages |
Getting started
- Agents: Read CLAUDE.md first.
- New team members: Read index.md for full navigation.
- PR reviewers: Check docs/global/coding-guidelines/infra-argo.md.
Common operations
| Task | Procedure |
|---|---|
| Add a tool to a cluster | docs/platform/procedures/add-tool-to-cluster.md |
| Upgrade a chart version | docs/platform/procedures/upgrade-chart-version.md |
| Onboard a new cluster | docs/platform/procedures/add-new-cluster.md |
| Roll out a tool fleet-wide | docs/platform/procedures/fleet-wide-tool-rollout.md |
| Debug sync failure | docs/platform/runbooks/argocd-sync-failure.md |
| Debug Helm render error | docs/platform/runbooks/render-failure.md |
| Find values inconsistencies across clusters | docs/platform/runbooks/values-drift.md |
| Debug stuck deployment | docs/platform/runbooks/deployment-stuck.md |
Sister repos
devops-infra-helm-charts— Helm charts andcustom-values.yamloverrides. EveryappSpec[].chartDirandvaluesDirmust exist here.devops-argo-config— Same pattern for service/application workloads (not infra tooling).