my-homelab-configs/bootstrap/platform
jv 6dfae38adf Platform: re-keyscan Argo CD GitOps SSH host on every apply
The argocd_private_repo provisioner only ran when its static triggers
(namespace, repo_url, ssh_key_path) changed. When the Gitea SSH host key
rotated (container rebuild / Debian rekey), the trigger set stayed
identical so tofu apply never re-ran the ssh-keyscan, silently leaving
Argo CD with 'knownhosts: key is unknown' and all Applications in
ComparisonError.

Add a timestamp()-based scan_revision trigger so the keyscan +
configmap/secret merge runs on EVERY apply, self-healing the host key
in argocd-ssh-known-hosts-cm. The provisioner is idempotent (reads the
existing configmap, merges the fresh scan, sorts, reapplies), so
re-running is safe.
2026-09-16 11:54:25 -05:00
..
grafana-dashboards Add blockchain devnet metrics dashboard 2026-06-29 19:22:23 -06:00
.terraform.lock.hcl redesign 2026-05-23 21:00:28 -06:00
main.tf Platform: re-keyscan Argo CD GitOps SSH host on every apply 2026-09-16 11:54:25 -05:00
variables.tf Adding limits 2026-07-02 17:32:25 -06:00