Mukul Sharma f23fc5f03c deployer: permission to manage app configuration Secrets
Environment variables are delivered through a Secret so values never appear
in the pod spec, but the ClusterRole was never given the resource — so every
deploy with configuration failed on a forbidden error, minutes after the
change looked fine.

Granted without list or watch. Kubernetes RBAC cannot scope a ClusterRole to
a namespace pattern, so this necessarily covers every namespace; withholding
list at least stops deployer enumerating the cluster's secrets, leaving only
access by a name it already knows. That narrows the blast radius rather than
removing it, and is called out in the manifest.

The proper fix, once there are tenants who are not the operator, is a
RoleBinding created per app namespace. That requires deployer to be able to
create RoleBindings, which is its own escalation path and wants deciding
deliberately rather than being slipped in here.
2026-09-05 01:49:49 +05:30
fix
2026-08-31 00:49:44 +05:30
fix
2026-08-31 00:49:44 +05:30
2026-08-31 13:18:18 +05:30
add
2026-08-31 01:02:22 +05:30
2026-08-31 09:02:30 +05:30
2026-08-26 04:03:34 +05:30

devops-infra-argo-config

GitOps control plane for infrastructure tooling across Meesho's Kubernetes fleet.

This repo manages ArgoCD Application resources for every infrastructure tool (Contour, VictoriaMetrics, Grafana, Kyverno, KEDA, external-secrets, Vault, etc.) deployed across ~19 clusters. It uses an App-of-Applications pattern: one parent Application per cluster renders child Applications from a appSpec[] list via a generic Helm chart.

Each environment tracks a dedicated branch — merging to that branch triggers immediate ArgoCD auto-sync with no staging gate:

Environment Branch
Production (prd) main
Staging (stg) develop
Integration (int) pre-prod

How it works

incubator/<env>/<cluster>.yaml          ← Parent Application (one per cluster)
    └── points at generic-argo-apps-chart/ + values/<env>/<cluster>-values.yaml
            └── renders one child Application per appSpec[] entry
                    └── sources charts + overrides from devops-infra-helm-charts

Directory structure

Directory Purpose
incubator/<env>/ Parent ArgoCD Application YAML, one per cluster
values/<env>/ Values files defining which tools deploy per cluster
generic-argo-apps-chart/ Helm chart that renders child Applications from appSpec[]
projects/ ArgoCD AppProject definitions (sre, sec)
external-name-service-*/ Cross-cluster DNS routing (ExternalName / MCS topology)
docs/ Agent-facing operational documentation
skills/ Parameterized agent tasks for common operations
wiki/ Architecture decisions and entity pages

Getting started

Common operations

Task Procedure
Add a tool to a cluster docs/platform/procedures/add-tool-to-cluster.md
Upgrade a chart version docs/platform/procedures/upgrade-chart-version.md
Onboard a new cluster docs/platform/procedures/add-new-cluster.md
Roll out a tool fleet-wide docs/platform/procedures/fleet-wide-tool-rollout.md
Debug sync failure docs/platform/runbooks/argocd-sync-failure.md
Debug Helm render error docs/platform/runbooks/render-failure.md
Find values inconsistencies across clusters docs/platform/runbooks/values-drift.md
Debug stuck deployment docs/platform/runbooks/deployment-stuck.md

Sister repos

  • devops-infra-helm-charts — Helm charts and custom-values.yaml overrides. Every appSpec[].chartDir and valuesDir must exist here.
  • devops-argo-config — Same pattern for service/application workloads (not infra tooling).
S
Description
No description provided
Readme
223 KiB