f23fc5f03c105f62c67258c418555bd89596c7ed
Environment variables are delivered through a Secret so values never appear in the pod spec, but the ClusterRole was never given the resource — so every deploy with configuration failed on a forbidden error, minutes after the change looked fine. Granted without list or watch. Kubernetes RBAC cannot scope a ClusterRole to a namespace pattern, so this necessarily covers every namespace; withholding list at least stops deployer enumerating the cluster's secrets, leaving only access by a name it already knows. That narrows the blast radius rather than removing it, and is called out in the manifest. The proper fix, once there are tenants who are not the operator, is a RoleBinding created per app namespace. That requires deployer to be able to create RoleBindings, which is its own escalation path and wants deciding deliberately rather than being slipped in here.
devops-infra-argo-config
GitOps control plane for infrastructure tooling across Meesho's Kubernetes fleet.
This repo manages ArgoCD Application resources for every infrastructure tool (Contour, VictoriaMetrics, Grafana, Kyverno, KEDA, external-secrets, Vault, etc.) deployed across ~19 clusters. It uses an App-of-Applications pattern: one parent Application per cluster renders child Applications from a appSpec[] list via a generic Helm chart.
Each environment tracks a dedicated branch — merging to that branch triggers immediate ArgoCD auto-sync with no staging gate:
| Environment | Branch |
|---|---|
| Production (prd) | main |
| Staging (stg) | develop |
| Integration (int) | pre-prod |
How it works
incubator/<env>/<cluster>.yaml ← Parent Application (one per cluster)
└── points at generic-argo-apps-chart/ + values/<env>/<cluster>-values.yaml
└── renders one child Application per appSpec[] entry
└── sources charts + overrides from devops-infra-helm-charts
Directory structure
| Directory | Purpose |
|---|---|
incubator/<env>/ |
Parent ArgoCD Application YAML, one per cluster |
values/<env>/ |
Values files defining which tools deploy per cluster |
generic-argo-apps-chart/ |
Helm chart that renders child Applications from appSpec[] |
projects/ |
ArgoCD AppProject definitions (sre, sec) |
external-name-service-*/ |
Cross-cluster DNS routing (ExternalName / MCS topology) |
docs/ |
Agent-facing operational documentation |
skills/ |
Parameterized agent tasks for common operations |
wiki/ |
Architecture decisions and entity pages |
Getting started
- Agents: Read CLAUDE.md first.
- New team members: Read index.md for full navigation.
- PR reviewers: Check docs/global/coding-guidelines/infra-argo.md.
Common operations
| Task | Procedure |
|---|---|
| Add a tool to a cluster | docs/platform/procedures/add-tool-to-cluster.md |
| Upgrade a chart version | docs/platform/procedures/upgrade-chart-version.md |
| Onboard a new cluster | docs/platform/procedures/add-new-cluster.md |
| Roll out a tool fleet-wide | docs/platform/procedures/fleet-wide-tool-rollout.md |
| Debug sync failure | docs/platform/runbooks/argocd-sync-failure.md |
| Debug Helm render error | docs/platform/runbooks/render-failure.md |
| Find values inconsistencies across clusters | docs/platform/runbooks/values-drift.md |
| Debug stuck deployment | docs/platform/runbooks/deployment-stuck.md |
Sister repos
devops-infra-helm-charts— Helm charts andcustom-values.yamloverrides. EveryappSpec[].chartDirandvaluesDirmust exist here.devops-argo-config— Same pattern for service/application workloads (not infra tooling).