diff --git a/cluster/platform/openviking/application.yaml b/cluster/platform/openviking/application.yaml index aa61a52..bba9165 100644 --- a/cluster/platform/openviking/application.yaml +++ b/cluster/platform/openviking/application.yaml @@ -13,7 +13,11 @@ metadata: name: openviking namespace: argocd annotations: - argocd.argoproj.io/sync-wave: "8" + # Wave 8 (platform-level, apps-of-apps view): OpenViking Application syncs after Harbor (Wave 7) + # NOTE: This annotation controls the Application's position in the apps-of-apps rollout, + # NOT the ordering of resources within the Application. Internal resource ordering is + # controlled by sync-wave annotations on individual resources (ExternalSecret, etc.). + # argocd.argoproj.io/sync-wave: "8" # Platform-level docs - NOT needed as annotation description: | OpenViking Platform Knowledge Infrastructure pilot deployment Pilot scope: Two corpora (hermes/ skills library, personal/homelab/) diff --git a/cluster/platform/openviking/externalsecret.yaml b/cluster/platform/openviking/externalsecret.yaml index 91be7e8..5afd2ea 100644 --- a/cluster/platform/openviking/externalsecret.yaml +++ b/cluster/platform/openviking/externalsecret.yaml @@ -13,7 +13,9 @@ metadata: name: openviking-credentials namespace: openviking annotations: - argocd.argoproj.io/sync-wave: "8" + # Wave -1: Ensure ExternalSecret syncs BEFORE the Deployment (wave 0) + # This guarantees the secret exists before the pod tries to mount it + argocd.argoproj.io/sync-wave: "-1" description: "Phase 1 secrets for OpenViking deployment" spec: refreshInterval: "1h" diff --git a/cluster/platform/openviking/namespace.yaml b/cluster/platform/openviking/namespace.yaml index 88f443e..090fe8d 100644 --- a/cluster/platform/openviking/namespace.yaml +++ b/cluster/platform/openviking/namespace.yaml @@ -3,6 +3,6 @@ kind: Namespace metadata: name: openviking annotations: - # Wave 8: OpenViking deployment (after Harbor at Wave 7) + # Wave 8 (platform-level): OpenViking deployment (after Harbor at Wave 7) + # This is documentation only - sync-wave at Application level, not resource level # Depends on: cert-manager, nginx-ingress, External Secrets Operator - argocd.argoproj.io/sync-wave: "8"