Platform: re-keyscan Argo CD GitOps SSH host on every apply
The argocd_private_repo provisioner only ran when its static triggers (namespace, repo_url, ssh_key_path) changed. When the Gitea SSH host key rotated (container rebuild / Debian rekey), the trigger set stayed identical so tofu apply never re-ran the ssh-keyscan, silently leaving Argo CD with 'knownhosts: key is unknown' and all Applications in ComparisonError. Add a timestamp()-based scan_revision trigger so the keyscan + configmap/secret merge runs on EVERY apply, self-healing the host key in argocd-ssh-known-hosts-cm. The provisioner is idempotent (reads the existing configmap, merges the fresh scan, sorts, reapplies), so re-running is safe.
This commit is contained in:
parent
dce4fa6022
commit
6dfae38adf
|
|
@ -1301,6 +1301,11 @@ resource "null_resource" "argocd_private_repo" {
|
|||
secret_name = var.argocd.repo_secret_name
|
||||
repo_url = var.gitops_repo_url
|
||||
ssh_key_path = var.gitops_ssh_key_path
|
||||
# Force the keyscan + configmap/secret merge to re-run on EVERY apply.
|
||||
# The GitOps SSH host key can rotate (Gitea container rebuilt, Debian host
|
||||
# rekeyed) and the static triggers above would otherwise never change,
|
||||
# silently leaving Argo CD with `knownhosts: key is unknown`.
|
||||
scan_revision = timestamp()
|
||||
}
|
||||
|
||||
provisioner "local-exec" {
|
||||
|
|
|
|||
Loading…
Reference in New Issue