c172756f340979d35d15ee55c4f1e01b2b03751f
contour, cert-manager and external-secrets could not be compared or synced: error calculating structured merge diff: error building typed value from live resource: .status.terminatingReplicas: field not declared in schema The ServerSideApply sync option makes Argo CD compute the diff locally against a Kubernetes schema compiled into its own binary. Argo CD v2.13 is older than this cluster: GKE runs 1.35, and Deployments there carry status.terminatingReplicas, which went beta and on-by-default in 1.33. Argo CD's schema has never heard of the field, so the diff aborts before any sync can happen. Nothing is wrong with the manifests, and only the three apps using SSA are affected. ServerSideDiff asks the API server to compute the diff via a dry-run apply, so the schema in use is the cluster's own. Beta since v2.10 and supported on the running version. The generic chart could not express this — Application metadata had no annotations block at all — so it gains an optional per-entry compareOptions list rather than the annotation being hardcoded. This is a workaround for an out-of-date Argo CD, not a fix. The fix is upgrading to a build whose bundled schema matches the cluster; every value key this repo relies on already exists in chart 10.8.4 (Argo CD v3.5.2), so that upgrade is mostly a vendoring exercise plus the 3.0 breaking changes (logs RBAC now enforced, fine-grained RBAC inheritance, resource tracking moving from labels to annotations). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LEsTefWWifp4ikvhHF5s6N
devops-infra-argo-config
GitOps control plane for infrastructure tooling across Meesho's Kubernetes fleet.
This repo manages ArgoCD Application resources for every infrastructure tool (Contour, VictoriaMetrics, Grafana, Kyverno, KEDA, external-secrets, Vault, etc.) deployed across ~19 clusters. It uses an App-of-Applications pattern: one parent Application per cluster renders child Applications from a appSpec[] list via a generic Helm chart.
Each environment tracks a dedicated branch — merging to that branch triggers immediate ArgoCD auto-sync with no staging gate:
| Environment | Branch |
|---|---|
| Production (prd) | main |
| Staging (stg) | develop |
| Integration (int) | pre-prod |
How it works
incubator/<env>/<cluster>.yaml ← Parent Application (one per cluster)
└── points at generic-argo-apps-chart/ + values/<env>/<cluster>-values.yaml
└── renders one child Application per appSpec[] entry
└── sources charts + overrides from devops-infra-helm-charts
Directory structure
| Directory | Purpose |
|---|---|
incubator/<env>/ |
Parent ArgoCD Application YAML, one per cluster |
values/<env>/ |
Values files defining which tools deploy per cluster |
generic-argo-apps-chart/ |
Helm chart that renders child Applications from appSpec[] |
projects/ |
ArgoCD AppProject definitions (sre, sec) |
external-name-service-*/ |
Cross-cluster DNS routing (ExternalName / MCS topology) |
docs/ |
Agent-facing operational documentation |
skills/ |
Parameterized agent tasks for common operations |
wiki/ |
Architecture decisions and entity pages |
Getting started
- Agents: Read CLAUDE.md first.
- New team members: Read index.md for full navigation.
- PR reviewers: Check docs/global/coding-guidelines/infra-argo.md.
Common operations
| Task | Procedure |
|---|---|
| Add a tool to a cluster | docs/platform/procedures/add-tool-to-cluster.md |
| Upgrade a chart version | docs/platform/procedures/upgrade-chart-version.md |
| Onboard a new cluster | docs/platform/procedures/add-new-cluster.md |
| Roll out a tool fleet-wide | docs/platform/procedures/fleet-wide-tool-rollout.md |
| Debug sync failure | docs/platform/runbooks/argocd-sync-failure.md |
| Debug Helm render error | docs/platform/runbooks/render-failure.md |
| Find values inconsistencies across clusters | docs/platform/runbooks/values-drift.md |
| Debug stuck deployment | docs/platform/runbooks/deployment-stuck.md |
Sister repos
devops-infra-helm-charts— Helm charts andcustom-values.yamloverrides. EveryappSpec[].chartDirandvaluesDirmust exist here.devops-argo-config— Same pattern for service/application workloads (not infra tooling).