diff --git a/cluster-resources/cert-manager-namespace.yaml b/cluster-resources/cert-manager-namespace.yaml index b1fe112..0e07987 100644 --- a/cluster-resources/cert-manager-namespace.yaml +++ b/cluster-resources/cert-manager-namespace.yaml @@ -5,5 +5,3 @@ apiVersion: v1 kind: Namespace metadata: name: cert-manager - labels: - istio-injection: disabled diff --git a/cluster-resources/secrets-namespace.yaml b/cluster-resources/secrets-namespace.yaml new file mode 100644 index 0000000..ac5aa3c --- /dev/null +++ b/cluster-resources/secrets-namespace.yaml @@ -0,0 +1,7 @@ +--- +# Disable Istio sidecar injection for cert-manager namespace +# This is required for cert-manager to function properly with Istio +apiVersion: v1 +kind: Namespace +metadata: + name: secrets diff --git a/infra/cluster-resources-application.yaml b/infra/cluster-resources-application.yaml index e196fbe..dd7955a 100644 --- a/infra/cluster-resources-application.yaml +++ b/infra/cluster-resources-application.yaml @@ -9,7 +9,7 @@ metadata: app.kubernetes.io/managed-by: argocd annotations: argocd.argoproj.io/hook: PreSync - argocd.argoproj.io/sync-wave: "1" + argocd.argoproj.io/sync-wave: "0" finalizers: - resources-finalizer.argocd.argoproj.io spec: diff --git a/infra/kyverno.yaml b/infra/kyverno.yaml index 2c00952..375cfc4 100644 --- a/infra/kyverno.yaml +++ b/infra/kyverno.yaml @@ -9,7 +9,7 @@ metadata: app.kubernetes.io/managed-by: argocd annotations: argocd.argoproj.io/hook: PreSync - argocd.argoproj.io/sync-wave: "0" + argocd.argoproj.io/sync-wave: "-1" finalizers: - resources-finalizer.argocd.argoproj.io spec: