The Option Does Nothing: Reading Settings Before You Ship
Goal
You grow argocd-cm one item at a time and confirm with argocd admin settings validate the values Argo CD read, and see how a typo'd key quietly disappears. You put the repository Secret and the ownership-marking method directly on the kwok cluster.
Why it matters
If you manage Argo CD by declaration, a single argocd-cm decides the behavior of the whole platform. But this file is an ordinary ConfigMap, so it has no schema — even if you get a key name wrong, it is not rejected and that setting just doesn't exist. This quietness lets problems survive for a long time. argocd admin settings validate is not a tool that checks the file but a tool that hands back, section by section, what the tool read from that file. So how you use it matters — not "a ✅ appeared so it's fine" but looking at whether the values I put in come back out. The single habit of attaching a before-and-after diff of this output to a configuration change removes the question "why isn't this option working".
Steps
- Make
/root/ga-settings/argocd-cm.yamlan argocd-cm ConfigMap withdata: {}, and save the output ofargocd admin settings validate --argocd-cm-path /root/ga-settings/argocd-cm.yamlto/root/ga-settings/baseline.txt. All five sections (accounts, general, kustomize, repositories, resource-overrides) must be visible. - In
/root/ga-settings/argocd-cm-accounts.yaml, declare two accounts —accounts.ciisapiKey, loginandaccounts.readonlyisapiKey. Save the output of checking only--group accountsto/root/ga-settings/accounts.txt. See what number the account count comes out as. /root/ga-settings/argocd-cm-kustomize.yamladds to the step 2 accountskustomize.buildOptionsset to--enable-helm. Save the--group kustomizeoutput to/root/ga-settings/kustomize.txt.- Make
/root/ga-settings/argocd-cm-typo.yamlexactly the same as the step 3 file, but write only the key name askustomize.buildOption(the singular, without the final s). Save the--group kustomizeoutput to/root/ga-settings/typo.txtand compare it with the step 3 output. /root/ga-settings/argocd-cm-scope.yamladdsresource.exclusionsto the step 3 content. Put two entries — one is, for apiGroupscilium.io,CiliumIdentity, and the other isEventof the core group (an empty string), and for both,clustersis"*". Save to/root/ga-settings/scope.txtthe output of checking--group kustomizeand--group resource-overridestogether./root/ga-settings/argocd-cm-track.yamladdsapplication.resourceTrackingMethod: annotationandapplication.instanceLabelKey: labhub.io/instanceto the step 5 content. Then put the namespacega-settingsand/root/ga-settings/deploy.yaml(Deploymentweb, imagenginx:1.25) on the kwok cluster, and try attaching the long namegitops-argocd-platform-team-a-production-cluster-seoul-web-frontend-appas a label value — save the output of the command that fails, including standard error, to/root/ga-settings/label-limit.txt. The same value can be attached as the annotationargocd.argoproj.io/tracking-id. Do that./root/ga-settings/argocd-cm-repo.yamladds to the step 6 content arepositorieslist (urlhttps://example.com/ga-manifests.git,namega-manifests,typegit). Save the--group repositoriesoutput to/root/ga-settings/repo.txt. Then, in the currently recommended way, write the same repository in/root/ga-settings/repo-secret.yamlas a Secretga-settings-repo(namespaceargocd) and apply it to the kwok cluster — the labelargocd.argoproj.io/secret-type: repositorymust be present, and instringData, puttype,name, andurl./root/ga-settings/argocd-cm-final.yamladdsurl(https://argocd.example.com) anddex.config(one github connector) to the step 7 content. Save the output of checking all sections to/root/ga-settings/final.txt, and save the output ofdiff /root/ga-settings/baseline.txt /root/ga-settings/final.txtto/root/ga-settings/settings-diff.txt. diff has a non-zero exit code, so be careful that your answer sheet does not stop there.
Notes
- You can pick sections with
--group: accounts, general, kustomize, repositories, resource-overrides. - This command needs a kubeconfig. It is already set in the lab Pod.
- There are settings, like resource.exclusions, that appear in no section — those must be checked in the file.
- Common mistake: getting a key name wrong, like
kustomize.buildOption. It becomes the default with no error. - Common mistake: leaving the
argocd.argoproj.io/secret-typelabel off the repository Secret. Again, no error. - Reference: https://argo-cd.readthedocs.io/en/stable/operator-manual/argocd-cm-yaml/
First look at what an empty configuration gives back
Make /root/ga-settings/argocd-cm.yaml an argocd-cm ConfigMap with data: {}, and save the output of argocd admin settings validate --argocd-cm-path /root/ga-settings/argocd-cm.yaml to /root/ga-settings/baseline.txt. All five sections (accounts, general, kustomize, repositories, resource-overrides) must be visible.
This command gives back, section by section, not "is there a problem with the file" but "what was read from this file". Think about why one account shows even though it is empty — the administrator account exists even without configuration.
Grow accounts by declaration
In /root/ga-settings/argocd-cm-accounts.yaml, declare two accounts — accounts.ci is apiKey, login and accounts.readonly is apiKey. Save the output of checking only --group accounts to /root/ga-settings/accounts.txt. See what number the account count comes out as.
The value of an account key is the list of things that account can do — apiKey is issuing tokens and login is logging in on the screen. For a non-human subject such as CI, it is better not to give login. Also count the fact that there is already one default admin account.
A section that gives back the read values as they are
/root/ga-settings/argocd-cm-kustomize.yaml adds to the step 2 accounts kustomize.buildOptions set to --enable-helm. Save the --group kustomize output to /root/ga-settings/kustomize.txt.
This section gives back not a number but the read value itself. So it is one of the few places where you can compare "what I wrote" and "what the tool read" with your own eyes — you will use this property in the next step.
If you get a key name wrong, nobody tells you
Make /root/ga-settings/argocd-cm-typo.yaml exactly the same as the step 3 file, but write only the key name as kustomize.buildOption (the singular, without the final s). Save the --group kustomize output to /root/ga-settings/typo.txt and compare it with the step 3 output.
A ConfigMap accepts any key — because it has no schema. So a typo becomes not an error but "not configured". The habit of looking at the values this command gives back is the only way to catch such mistakes.
Decide what not to watch at all
/root/ga-settings/argocd-cm-scope.yaml adds resource.exclusions to the step 3 content. Put two entries — one is, for apiGroups cilium.io, CiliumIdentity, and the other is Event of the core group (an empty string), and for both, clusters is "*". Save to /root/ga-settings/scope.txt the output of checking --group kustomize and --group resource-overrides together.
The exclusion list decides which kinds Argo CD will not watch in the cluster at all. If you leave out Events, of which thousands are created per second, or identity objects made by the CNI, the controller load drops greatly. But this setting does not appear in any section of the validate output — check that too.
Why move the ownership mark from a label to an annotation
/root/ga-settings/argocd-cm-track.yaml adds application.resourceTrackingMethod: annotation and application.instanceLabelKey: labhub.io/instance to the step 5 content. Then put the namespace ga-settings and /root/ga-settings/deploy.yaml (Deployment web, image nginx:1.25) on the kwok cluster, and try attaching the long name gitops-argocd-platform-team-a-production-cluster-seoul-web-frontend-app as a label value — save the output of the command that fails, including standard error, to /root/ga-settings/label-limit.txt. The same value can be attached as the annotation argocd.argoproj.io/tracking-id. Do that.
A label value cannot exceed 63 characters. In a large organization where app names get long, the label method hits this limit, and because of truncated names, different apps end up with the same ownership mark. An annotation has no such limit.
Declare a repository as a Secret, not a ConfigMap
/root/ga-settings/argocd-cm-repo.yaml adds to the step 6 content a repositories list (url https://example.com/ga-manifests.git, name ga-manifests, type git). Save the --group repositories output to /root/ga-settings/repo.txt. Then, in the currently recommended way, write the same repository in /root/ga-settings/repo-secret.yaml as a Secret ga-settings-repo (namespace argocd) and apply it to the kwok cluster — the label argocd.argoproj.io/secret-type: repository must be present, and in stringData, put type, name, and url.
The repositories list in the ConfigMap is the old way and cannot hold a password or key together. Now one Secret is one repository, and Argo CD finds repository Secrets by that label. If the label is missing, nothing happens — no error occurs either.
Put the before and after side by side
/root/ga-settings/argocd-cm-final.yaml adds url (https://argocd.example.com) and dex.config (one github connector) to the step 7 content. Save the output of checking all sections to /root/ga-settings/final.txt, and save the output of diff /root/ga-settings/baseline.txt /root/ga-settings/final.txt to /root/ga-settings/settings-diff.txt. diff has a non-zero exit code, so be careful that your answer sheet does not stop there.
A change that alters configuration needs the habit of leaving "what changes" as a file. Only then can the reviewer look not at the lines of the ConfigMap but at the values the tool read. Check how the general section changes.