add PreSync hook + sync-wave for fully automated on first sync

This commit is contained in:
2026-09-23 18:04:40 +02:00
parent 5d2dce82b7
commit c5d28ee3b5
3 changed files with 13 additions and 0 deletions
+3
View File
@@ -3,6 +3,9 @@ kind: ConfigMap
metadata: metadata:
name: nextgen-be-config name: nextgen-be-config
namespace: nextgen-be namespace: nextgen-be
annotations:
argocd.argoproj.io/hook: PreSync
argocd.argoproj.io/sync-wave: "-1"
data: data:
RADIUS_SERVER_IP: "freeradius.freeradius.svc.cluster.local" RADIUS_SERVER_IP: "freeradius.freeradius.svc.cluster.local"
RADIUS_TIMEOUT_SECONDS: "2" RADIUS_TIMEOUT_SECONDS: "2"
+1
View File
@@ -6,6 +6,7 @@ metadata:
annotations: annotations:
# ArgoCD: run this before the Deployment is synced, on every sync where it changed # ArgoCD: run this before the Deployment is synced, on every sync where it changed
argocd.argoproj.io/hook: PreSync argocd.argoproj.io/hook: PreSync
argocd.argoproj.io/sync-wave: "0"
argocd.argoproj.io/hook-delete-policy: BeforeHookCreation argocd.argoproj.io/hook-delete-policy: BeforeHookCreation
spec: spec:
backoffLimit: 2 backoffLimit: 2
+9
View File
@@ -9,6 +9,9 @@ kind: Secret
metadata: metadata:
name: nextgen-be-db name: nextgen-be-db
namespace: nextgen-be namespace: nextgen-be
annotations:
argocd.argoproj.io/hook: PreSync
argocd.argoproj.io/sync-wave: "-2"
type: Opaque type: Opaque
stringData: stringData:
# Get this value with: # Get this value with:
@@ -20,6 +23,9 @@ kind: Secret
metadata: metadata:
name: nextgen-be-jwt name: nextgen-be-jwt
namespace: nextgen-be namespace: nextgen-be
annotations:
argocd.argoproj.io/hook: PreSync
argocd.argoproj.io/sync-wave: "-2"
type: Opaque type: Opaque
stringData: stringData:
# Generate with: openssl rand -hex 32 # Generate with: openssl rand -hex 32
@@ -30,6 +36,9 @@ kind: Secret
metadata: metadata:
name: nextgen-be-radius name: nextgen-be-radius
namespace: nextgen-be namespace: nextgen-be
annotations:
argocd.argoproj.io/hook: PreSync
argocd.argoproj.io/sync-wave: "-2"
type: Opaque type: Opaque
stringData: stringData:
# Must match the shared secret configured on the FreeRADIUS side # Must match the shared secret configured on the FreeRADIUS side