From 68073d577dbe6cffcf98e2bee9b901c81642a2b0 Mon Sep 17 00:00:00 2001 From: SmokyZone Date: Fri, 18 Sep 2026 19:42:52 +0200 Subject: [PATCH] Add ArgoCD Applications for External Secrets Operator and OpenBao - external-secrets: deployed directly from its official Helm repo with installCRDs enabled. - openbao: deployed from the new openbao-gitops repo, providing the ClusterSecretStore that binds ESO to OpenBao. Also extends templates/application.yaml to support Helm-repo sources (source.chart) in addition to git path-based sources, and raw Helm values blocks. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- templates/application.yaml | 10 +++++++++- values.yaml | 38 ++++++++++++++++++++++++++++++++++++++ 2 files changed, 47 insertions(+), 1 deletion(-) diff --git a/templates/application.yaml b/templates/application.yaml index 2ba8469..204dfe3 100644 --- a/templates/application.yaml +++ b/templates/application.yaml @@ -12,8 +12,12 @@ spec: source: repoURL: {{ .source.repoURL }} targetRevision: {{ .source.targetRevision }} + {{- if .source.chart }} + chart: {{ .source.chart }} + {{- else }} path: {{ .source.path }} - {{- if or (and .source.helm .source.helm.parameters) (and .source.helm .source.helm.valueFiles) }} + {{- end }} + {{- if or (and .source.helm .source.helm.parameters) (and .source.helm .source.helm.valueFiles) (and .source.helm .source.helm.values) }} helm: {{- if .source.helm.parameters }} parameters: @@ -23,6 +27,10 @@ spec: valueFiles: {{- toYaml .source.helm.valueFiles | nindent 8 }} {{- end }} + {{- if .source.helm.values }} + values: | + {{- .source.helm.values | nindent 8 }} + {{- end }} {{- end }} destination: server: {{ .destination.server }} diff --git a/values.yaml b/values.yaml index 5de5764..6783607 100644 --- a/values.yaml +++ b/values.yaml @@ -32,3 +32,41 @@ applications: selfHeal: true syncOptions: - CreateNamespace=true + + # External Secrets Operator - installed straight from its official Helm + # repo (no git source needed). CRDs are installed by the chart itself. + - name: external-secrets + enabled: true + source: + repoURL: https://charts.external-secrets.io + chart: external-secrets + targetRevision: "2.10.0" + helm: + values: | + installCRDs: true + destination: + server: https://kubernetes.default.svc + namespace: external-secrets + syncPolicy: + automated: + prune: true + selfHeal: true + syncOptions: + - CreateNamespace=true + + # OpenBao secret management backend + its ClusterSecretStore binding for ESO. + - name: openbao + enabled: true + source: + repoURL: https://git.smokyzone.de/SmokyZone/openbao-gitops.git + targetRevision: main + path: . + destination: + server: https://kubernetes.default.svc + namespace: openbao + syncPolicy: + automated: + prune: true + selfHeal: true + syncOptions: + - CreateNamespace=true