argo-cd: global: image: tag: "v2.13.8" additionalLabels: bu: infra team: devops podLabels: bu: infra team: devops nodeSelector: dedicated: devops tolerations: - key: "dedicated" operator: "Equal" value: "devops" effect: "NoSchedule" dex: enabled: true resources: limits: cpu: 250m memory: 512Mi requests: cpu: 250m memory: 512Mi metrics: enabled: true podAnnotations: prometheus.io/scrape: true prometheus.io/path: /metrics prometheus.io/port: 5558 controller: replicas: 3 enableStatefulSet: true podAnnotations: prometheus.io/scrape: true prometheus.io/path: /metrics prometheus.io/port: 8082 resources: limits: cpu: "7" memory: "12Gi" requests: cpu: "6" memory: "8Gi" env: - name: ARGOCD_CONTROLLER_REPLICAS value: '3' - name: ARGOCD_RECONCILIATION_JITTER valueFrom: configMapKeyRef: key: timeout.reconciliation.jitter name: argocd-cm optional: true redis-ha: enabled: true repoServer: autoscaling: enabled: true maxReplicas: 25 minReplicas: 3 targetMemoryUtilizationPercentage: 60 targetCPUUtilizationPercentage: 60 metrics: enabled: true serviceMonitor: enabled: false interval: 60s podAnnotations: prometheus.io/scrape: true prometheus.io/path: /metrics prometheus.io/port: 8084 resources: limits: cpu: 1500m memory: 3Gi requests: cpu: "1" memory: 2Gi env: - name: ARGOCD_HELM_ALLOW_CONCURRENCY value: 'true' - name: GIT_DEPTH value: '1' - name: ARGOCD_RECONCILIATION_JITTER valueFrom: configMapKeyRef: key: timeout.reconciliation.jitter name: argocd-cm optional: true server: replicas: 3 autoscaling: enabled: true minReplicas: 3 maxReplicas: 15 extraArgs: - --insecure ingress: annotations.nginx.ingress.kubernetes.io/force-ssl-redirect: false annotations.nginx.ingress.kubernetes.io/rewrite-target: / annotations.nginx.ingress.kubernetes.io/ssl-redirect: false enabled: true hostname: "argocd-datascience-prd.meeshogcp.in" ingressClassName: nginx-internal podAnnotations: prometheus.io/scrape: true prometheus.io/path: /metrics prometheus.io/port: 8083 resources: limits: cpu: "2" memory: 3Gi requests: cpu: "1" memory: 2Gi env: - name: ARGOCD_GRPC_KEEP_ALIVE_MIN value: '30s' applicationSet: replicaCount: 2 notifications: metrics: enabled: true serviceMonitor: enabled: false resources: limits: cpu: 500m memory: 1Gi requests: cpu: 300m memory: 512Mi configs: cm: resource.customizations: | keda.sh/ScaledObject: health.lua: | local hs = {} local healthy = false local degraded = false local suspended = false if obj.status ~= nil then if obj.status.conditions ~= nil then for i, condition in ipairs(obj.status.conditions) do if condition.status == "False" and condition.type == "Ready" then degraded = true hs.message = condition.message end if condition.status == "True" and condition.type == "Ready" then healthy = true hs.message = condition.message end if condition.status == "True" and condition.type == "Paused" then suspended = true hs.message = condition.message end end end end if degraded == true then hs.status = "Degraded" return hs elseif healthy == true then hs.status = "Healthy" if suspended == true then hs.message = "ScaledObject is paused as part of normal operations." else hs.message = "ScaledObject is active." end return hs end hs.status = "Progressing" hs.message = "Creating ScaledObject or waiting for conditions." return hs accounts.ringmaster: 'apiKey,login' accounts.readonly: 'apiKey,login' timeout.reconciliation: 4m timeout.reconciliation.jitter: 60s url: https://argocd-datascience-prd.meeshogcp.in statusbadge.enabled: "true" help.chatUrl: "https://meesho.slack.com/archives/C021QNS6JLV" help.chatText: "Chat now!" dex.config: | logger: level: error format: json connectors: - type: github id: github name: GitHub loadAllGroups: true admin.enabled: "true" config: clientID: 37e058fb1915c193747e clientSecret: $github-sso-secret:dex.github.clientSecret orgs: - name: Meesho params: controller.sharding.algorithm: round-robin controller.status.processors: '50' controller.operation.processors: '25' controller.repo.server.timeout.seconds: '90' rbac: policy.csv: | p, role:admins, *, *, */*, allow p, role:admins, *, *, *, allow ## Policy for data-science team p, role:datascience, *, get, */*, allow p, role:datascience, applications, delete, */*, deny p, role:datascience, applications, sync, dsci-*/*, allow p, role:datascience, applications, update, dsci-ml/prd-online-feature-store-api-mp*, allow p, role:datascience, applications, update, dsci-ml/prd-online-feature-store-api-v3*, allow p, role:backend, applications, action/apps/Deployment/restart, dsci-*/prd-predator-*, allow p, role:backend, applications, action/apps/Deployment/restart, dsci-*/prd-model-inference-*, allow p, role:datascience, applications, delete/*/Deployment/*/*, dsci-*/prd-model-inference-*, allow p, role:backend, *, get, */*, allow p, role:data-engineering, applications, *, dsci-ds/prd-ds-airflow*, allow ## Policy for bharatml team p, role:bharatml-role, applications, get, dsci-*/prd-predator-*, allow p, role:bharatml-role, applications, get, dsci-*/prd-model-inference-*, allow p, role:bharatml-role, applications, action/apps/Deployment/restart, dsci-*/prd-predator-*, allow p, role:bharatml-role, applications, action/apps/Deployment/restart, dsci-*/prd-model-inference-*, allow p, role:bharatml-role, applications, delete/*/Pod/*/*, dsci-*/prd-predator-*, allow p, role:bharatml-role, applications, delete/*/Pod/*/*, dsci-*/prd-model-inference-*, allow p, role:bharatml-role, applications, update/keda.sh/ScaledObject/*/*, dsci-*/prd-predator-*, allow p, role:bharatml-role, applications, update/keda.sh/ScaledObject/*/*, dsci-*/prd-model-inference-*, allow ## Policy for Admin-NoDelete role p, role:admin-nodelete, *, get, *, allow p, role:admin-nodelete, *, create, *, allow p, role:admin-nodelete, *, update, *, allow p, role:admin-nodelete, applications, create, */*, allow p, role:admin-nodelete, applications, get, */*, allow p, role:admin-nodelete, applications, override, */*, allow p, role:admin-nodelete, applications, sync, */*, allow p, role:admin-nodelete, applications, update, */*, allow p, role:admin-nodelete, applications, action/*, */*, allow p, role:admin-nodelete, applications, delete/*/Pod/*/*, */*, allow ## Policy for devops intern role p, role:intern, *, get, *, allow p, role:backend-ro, *, get, */*, allow ## Role definition for different Github teams g, Meesho:architects, role:admin-nodelete g, Meesho:devops-new, role:admin-nodelete g, Meesho:devops-interns, role:intern g, Meesho:devops, role:admins g, Meesho:datascience, role:datascience g, Meesho:backend, role:backend g, Meesho:data-engineering, role:data-engineering g, ringmaster, role:admin-nodelete g, bharatml, role:bharatml-role g, readonly, role:backend-ro