The argocd_private_repo provisioner only ran when its static triggers (namespace, repo_url, ssh_key_path) changed. When the Gitea SSH host key rotated (container rebuild / Debian rekey), the trigger set stayed identical so tofu apply never re-ran the ssh-keyscan, silently leaving Argo CD with 'knownhosts: key is unknown' and all Applications in ComparisonError. Add a timestamp()-based scan_revision trigger so the keyscan + configmap/secret merge runs on EVERY apply, self-healing the host key in argocd-ssh-known-hosts-cm. The provisioner is idempotent (reads the existing configmap, merges the fresh scan, sorts, reapplies), so re-running is safe. |
||
|---|---|---|
| .. | ||
| grafana-dashboards | ||
| .terraform.lock.hcl | ||
| main.tf | ||
| variables.tf | ||