dcd35836569f902f7506e232a8bec706dbe3749f
Registers the new hand-written redis chart (devops-infra-helm-charts, separate commit) and the ExternalSecret feeding its admin password from Vault. Own namespace, addressed over cluster DNS like every other platform component here: redis.redis.svc.cluster.local:6379 Only one consumer for the credential, unlike the Postgres one next door: the server itself, to seed its ACL file on first boot. toolshed's api gets it from the connection an operator configures in the dashboard, encrypted in toolshed's own database — so there is deliberately no second ExternalSecret into the toolshed namespace. Order matters: put the password in Vault at secret/toolshed/redis before syncing, or the init container sits in CreateContainerConfigError. The exact command, the reason the password must be alphanumeric (it is written into an ACL directive where a space or quote would split it), and the manual rotation procedure are all recorded in the ExternalSecret's own header. Nothing here needs to change for Postgres: toolshed's managed database add-on points at the existing postgresql.postgres.svc.cluster.local, whose POSTGRES_USER is the initdb superuser and so already has the CREATEDB and CREATEROLE that provisioning needs. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Wajog7nELA3i8JWTjxYGHF
devops-infra-argo-config
GitOps control plane for infrastructure tooling across Meesho's Kubernetes fleet.
This repo manages ArgoCD Application resources for every infrastructure tool (Contour, VictoriaMetrics, Grafana, Kyverno, KEDA, external-secrets, Vault, etc.) deployed across ~19 clusters. It uses an App-of-Applications pattern: one parent Application per cluster renders child Applications from a appSpec[] list via a generic Helm chart.
Each environment tracks a dedicated branch — merging to that branch triggers immediate ArgoCD auto-sync with no staging gate:
| Environment | Branch |
|---|---|
| Production (prd) | main |
| Staging (stg) | develop |
| Integration (int) | pre-prod |
How it works
incubator/<env>/<cluster>.yaml ← Parent Application (one per cluster)
└── points at generic-argo-apps-chart/ + values/<env>/<cluster>-values.yaml
└── renders one child Application per appSpec[] entry
└── sources charts + overrides from devops-infra-helm-charts
Directory structure
| Directory | Purpose |
|---|---|
incubator/<env>/ |
Parent ArgoCD Application YAML, one per cluster |
values/<env>/ |
Values files defining which tools deploy per cluster |
generic-argo-apps-chart/ |
Helm chart that renders child Applications from appSpec[] |
projects/ |
ArgoCD AppProject definitions (sre, sec) |
external-name-service-*/ |
Cross-cluster DNS routing (ExternalName / MCS topology) |
docs/ |
Agent-facing operational documentation |
skills/ |
Parameterized agent tasks for common operations |
wiki/ |
Architecture decisions and entity pages |
Getting started
- Agents: Read CLAUDE.md first.
- New team members: Read index.md for full navigation.
- PR reviewers: Check docs/global/coding-guidelines/infra-argo.md.
Common operations
| Task | Procedure |
|---|---|
| Add a tool to a cluster | docs/platform/procedures/add-tool-to-cluster.md |
| Upgrade a chart version | docs/platform/procedures/upgrade-chart-version.md |
| Onboard a new cluster | docs/platform/procedures/add-new-cluster.md |
| Roll out a tool fleet-wide | docs/platform/procedures/fleet-wide-tool-rollout.md |
| Debug sync failure | docs/platform/runbooks/argocd-sync-failure.md |
| Debug Helm render error | docs/platform/runbooks/render-failure.md |
| Find values inconsistencies across clusters | docs/platform/runbooks/values-drift.md |
| Debug stuck deployment | docs/platform/runbooks/deployment-stuck.md |
Sister repos
devops-infra-helm-charts— Helm charts andcustom-values.yamloverrides. EveryappSpec[].chartDirandvaluesDirmust exist here.devops-argo-config— Same pattern for service/application workloads (not infra tooling).