argoproj/argo-cd
57.0
Adequate · 6 August 2026
144.8k
lines of production code
Go
primary language
3
measurements over time
What this system is
This system is a comprehensive GitOps and application lifecycle management platform that automates the synchronization of desired states across Kubernetes clusters. It provides a modular architecture with dedicated controllers for applications, application sets, and notifications, supported by a robust CLI and API layer. The platform enables users to manage complex multi-source application generation, automated manifest hydration, and granular health monitoring for a wide variety of Kubernetes and third-party resources.
How it got here
2018–2020 — Controller and API expansion
71 changes.
This period focused on introducing the Application Controller for state reconciliation and expanding the API surface with new services for accounts, certificates, and repository credentials. The architecture was significantly refactored to support sharding, modularize the repository server, and standardize CLI commands. Additionally, extensive health checks were added for a wide range of third-party Kubernetes resources.
2021–2022 — ApplicationSet and notification controller expansion
58 changes.
This period focused on significantly expanding the ApplicationSet controller with new SCM providers, modularized internal components, and enhanced cache synchronization. Concurrently, the codebase integrated the notifications controller and introduced dedicated CLI tools for Dex, Git authentication, and resource generation, while adding extensive health check scripts for a wide variety of custom resources.
2023–2024 — Expanded resource health checks and source hydration
58 changes.
This period was dominated by the addition of health check scripts for a wide variety of Kubernetes custom resources, enabling users to monitor the operational status of diverse workloads in the UI. The team also introduced a new commit server and source hydration controller to automate manifest generation and repository commits. Additionally, internal infrastructure improvements included a new HTTP client, plugin service, and consistent hashing for sharding.
2025–2026 — extensive health check coverage
44 changes.
This period was dominated by the addition of health check scripts for a wide variety of custom resources, including Kubernetes, cloud, and platform-specific resources. The work also involved extracting the GitOps engine into a standalone library and fixing synchronization and caching issues.
Features
Add ApplicationSet examples for Git directory generation with Go template support
Added example ApplicationSet manifests in the \applicationset/examples/git-generator-directory\ directory to demonstrate Git directory generation. The update includes both FastTemplate and GoTemplate-based configurations, with the latter enabling \goTemplate: true\ and \goTemplateOptions: \["missingkey=error"\]\ for stricter template error handling. The examples also provide sample Helm charts (Prometheus Operator, Helm Guestbook) and Kustomization files to illustrate how to structure and exclude specific directories during application set generation.
applicationset/examples/git-generator-directory · high confidence
Add ApplicationSet metrics for monitoring reconciliation and status
New Prometheus metrics have been introduced for ApplicationSets, exposing reconciliation performance via a histogram and status information (including resource update status and owned application count) via gauges. The implementation registers collectors that iterate over ApplicationSets, allowing users to monitor the health and performance of ApplicationSet controllers through the standard metrics endpoint.
applicationset/metrics · high confidence
Add Argo CD resource generation CLI tool
A new command-line interface named 'argocd-generator' has been introduced in the hack/gen-resources/cmd/commands package. This tool provides 'generate' and 'clean' subcommands that allow users to programmatically create or remove Argo CD resources—including projects, applications, repositories, and clusters—by reading a configuration file and interacting with the Kubernetes API.
hack/gen-resources/cmd/commands · high confidence
Add CloudNativePG cluster actions and health checks
Users can now perform cluster management operations directly from the UI, including promoting a replica to primary, reloading configuration, performing a rollout restart, and suspending or resuming the reconciliation loop. A custom health check for CloudNativePG clusters has also been added, mapping CNPG cluster phases (such as 'Switchover in progress' or 'Failing over') to standard health statuses (Degraded, Progressing, Suspended) to provide clearer status visibility.
_resource\customizations/postgresql.cnpg.io · high confidence
Add CronJob and Job actions and health checks
Users can now manage CronJobs and Jobs directly from the UI. For CronJobs, new actions allow creating manual Job instances, and suspending or resuming the CronJob. For Jobs, users can suspend, resume, or terminate running Jobs. Additionally, health checks for CronJobs now correctly report 'Healthy' when the CronJob is suspended, and properly reflect the status of active, completed, or failed executions.
_resource\customizations/batch · high confidence
Add GitOps engine core library and supporting files
The gitops-engine module is introduced as a standalone library, including its Apache 2.0 license, build configuration, and Go source files for Kubernetes endpoint utilities and hashing. This provides the core GitOps features—such as Kubernetes resource caching, resource reconciliation, sync planning, and access to Git repositories—for use by Argo CD and other projects.
gitops-engine · high confidence
Add Helm Config Management Plugin example
Added a new example for a Helm-based Config Management Plugin (CMP) in the examples/plugins/helm directory. This includes the plugin configuration (plugin.yaml), shell scripts for parameter discovery and generation (get-parameters.sh, generate.sh), a Kustomization file to bundle the resources, and a deployment patch to install necessary tools (helm, jq, yq) into the Argo CD repo server. This provides a reference implementation for users looking to integrate Helm with Argo CD's CMP framework.
examples/plugins/helm · high confidence
Add MinIO Tenant health check
A new health check script for MinIO Tenants has been added, mapping various tenant states (such as Initialized, Provisioning, Updating, and Restarting) to standard health statuses (Healthy, Progressing, or Degraded) to provide clearer operational visibility.
_resource\customizations/minio.min.io · high confidence
Add Prometheus health status checks
Users can now see the health status of Prometheus resources in the UI. The system evaluates the \Available\ condition on the Prometheus object: if the status is \True\, the resource is marked as Healthy; if \False\ with reason \SomePodsNotReady\, it is Progressing; otherwise, it is Degraded. This logic is implemented in \resource\_customizations/monitoring.coreos.com/Prometheus/health.lua\ and verified by new test cases.
_resource\customizations/monitoring.coreos.com · high confidence
Add automated checksum generation scripts for tooling binaries
The \hack/installers/checksums\ directory now includes new shell scripts (\add-git-lfs-checksums.sh\, \add-helm-checksums.sh\, \add-kustomize-checksums.sh\, \add-oras-checksums.sh\, and \add-protoc-checksums.sh\) that automatically download and generate SHA256 checksums for specific versions of Git LFS, Helm, Kustomize, ORAS, and Protobuf. These scripts streamline the process of updating the project's internal tooling versions by fetching the official release checksums from their respective GitHub releases pages, ensuring that the local checksums in the repository remain synchronized with upstream releases.
hack/installers/checksums · high confidence
Add consistent hashing with bounded loads for sharding
Introduces a new consistent hashing implementation in the sharding controller that supports both standard consistent hashing and a 'bounded loads' algorithm. The new \consistent\ package provides a \Consistent\ struct with methods to add, remove, and update hosts, as well as select hosts using either standard hashing (\Get\) or least-loaded selection (\GetLeast\). This enables more balanced distribution of load across shards by considering host capacity and current load.
controller/sharding/consistent · high confidence
Add custom actions for Argo Rollouts
Added support for managing Argo Rollouts via custom actions, including abort, pause, resume, restart, retry, promote-full, and skip-current-step. The implementation includes Lua scripts for each action and a discovery script that dynamically enables or disables these actions based on the Rollout's current state (e.g., pausing, aborting, or completing). Test cases verify the correct behavior of each action under various conditions.
_resource\customizations/argoproj.io/Rollout/actions · high confidence
Add custom health check for AWS EKS control planes
A new Lua-based health check for AWSManagedControlPlane resources has been introduced to provide more accurate status reporting. The script evaluates the control plane's readiness by checking for stale generations, terminal failure messages, and the specific EKSControlPlaneUpdating condition, ensuring that the status correctly reflects when the EKS control plane is in an updating or degraded state rather than incorrectly reporting as healthy.
_resource\customizations/controlplane.cluster.x-k8s.io · high confidence
Add custom health check for KServe InferenceService resources
A new Lua-based health check has been added for KServe InferenceService resources, enabling the platform to accurately report their status as Healthy, Progressing, Degraded, or Suspended. The logic specifically handles the 'Stopped' condition, ensuring that an InferenceService is not incorrectly marked as degraded when it is intentionally stopped. This change includes the implementation script and a comprehensive set of test cases covering various states including healthy, progressing, degraded, and stopped scenarios.
_resource\customizations/serving.kserve.io · high confidence
Add custom health status checks for Argo Rollouts
Introduces a Lua-based health check script for the Argo Rollouts resource, enabling Argo CD to accurately reflect the status of rollouts. The script handles various rollout states including Progressing, Suspended (paused), Degraded (e.g., invalid spec, timeout, aborted), and Healthy. It supports multiple Argo Rollouts versions (v0.8, v0.9, v0.10, v1.0, v1.1) by checking for specific fields like \status.phase\, \status.pauseConditions\, \status.observedGeneration\, and \status.workloadObservedGeneration\. It also accounts for deprecated fields like \status.canary.stableRS\ in favor of \status.stableRS\. A corresponding test file is added to verify the health status logic against various rollout scenarios.
_resource\customizations/argoproj.io/Rollout · high confidence
Add custom resource actions and health status for Flux source resources
Users can now suspend, resume, and reconcile Flux source resources (Bucket, GitRepository, HelmChart, HelmRepository, and OCIRepository) directly from the UI. The health status of these resources is now accurately reflected in the UI, with specific handling for suspended states and OCI-type Helm repositories which lack standard status conditions.
_resource\customizations/source.toolkit.fluxcd.io · high confidence
Add dev-mounter utility for mounting ConfigMaps locally
A new Go-based utility, hack/dev-mounter, has been added to the repository. This tool allows developers to mount Kubernetes ConfigMaps to local folders during development, automatically syncing file contents and removing stale files when the ConfigMap changes.
hack/dev-mounter · high confidence
Add embedded assets for RBAC policy, Swagger API, and UI badges
The assets package now embeds static files into the binary using Go's embed package, including the RBAC policy definitions (builtin-policy.csv), the Casbin model configuration (model.conf), the OpenAPI/Swagger specification (swagger.json), and UI assets like the status badge SVG. This enables the application to serve these resources directly from the compiled binary rather than relying on external file paths.
assets · high confidence
Add health check for AWS ACK resources
A new health check for AWS ACK (AWS Controllers for Kubernetes) resources has been added. This change introduces a Lua script that evaluates the status conditions of AWS resources, classifying them as Healthy, Progressing, or Degraded based on the presence of specific conditions like 'Ready' and 'ACK.Terminal'. The addition includes the necessary test data files to verify the health check logic.
_resource\customizations/\.services.k8s.aws · high confidence_
Add health check for BanzaiCloud KafkaCluster resources
A new health check script for the BanzaiCloud KafkaCluster custom resource has been added, enabling users to monitor the status of their Kafka clusters. The script evaluates the cluster's state, broker configuration, and CruiseControl readiness to report Healthy, Progressing, or Degraded conditions. This includes specific handling for rolling upgrades and reconciling states, ensuring accurate health reporting during cluster operations.
_resource\customizations/kafka.banzaicloud.io · high confidence
Add health check for ClusterResourceSet
Users will now see the health status of ClusterResourceSet resources in the UI. The system evaluates the 'ResourcesApplied' condition to display 'Healthy' when applied, 'Degraded' if there is an error, or 'Progressing' while initializing.
_resource\customizations/addons.cluster.x-k8s.io · high confidence
Add health check for Crossplane ClusterStackInstall resources
Users will now see accurate health status for Crossplane ClusterStackInstall resources, with the UI reflecting 'Healthy' when the resource is ready and 'Progressing' while it is being created or installed.
_resource\customizations/stacks.crossplane.io · high confidence
Add health check for DNSSDServiceInstance resources
Users can now monitor the health status of DNSSDServiceInstance resources. A new health check script evaluates the resource's conditions (Adopted, Advertised, Discoverable) to report Healthy, Progressing, Degraded, or Unknown states, with corresponding messages for troubleshooting.
_resource\customizations/proclaim.dogmatiq.io · high confidence
Add health check for DatadogMetric resources
Users can now see the health status of DatadogMetric custom resources. A new health check script evaluates the resource's status conditions, reporting 'Healthy' when no errors or validity issues are present, and 'Degraded' if an error condition or invalid state is detected. Test cases are included to verify these health states.
_resource\customizations/datadoghq.com · high confidence
Add health check for FlinkDeployment resources
A new health check script for FlinkDeployment resources has been added, enabling users to monitor the status of their Flink deployments. The script evaluates the \reconciliationStatus\ and \jobManagerDeploymentStatus\ fields to report 'Healthy' when the deployment is running or suspended, 'Progressing' during deployment or when not ready, and 'Degraded' if an error occurs. Test cases have been included to verify these states for both Flink v0.1.x and v1.x versions.
_resource\customizations/flink.apache.org · high confidence
Add health check for Iamrole resources
A new health check script has been added for the Iamrole custom resource, enabling users to monitor the reconciliation status of IAM roles. The script evaluates the resource's state, reporting 'Healthy' when the role is successfully reconciled, 'Degraded' if errors occur (such as missing roles or quota limits), and 'Progressing' while waiting for reconciliation. This change provides visibility into the operational health of IAM role management.
_resource\customizations/iammanager.keikoproj.io · high confidence
Add health check for Knative Serving Service resources
Users can now see the health status of Knative Serving Service resources. A new Lua script evaluates the service's conditions (ConfigurationsReady, RoutesReady, Ready) to report Healthy, Degraded, or Progressing states, with detailed messages for failures or rollouts.
_resource\customizations/serving.knative.dev · high confidence
Add health check for OCS StorageCluster resources
A new health-check script for the \ocs.openshift.io/StorageCluster\ resource has been added, enabling Argo CD to evaluate the health status of OpenShift Container Storage clusters. The Lua script inspects the \status.conditions\ of a StorageCluster and maps the \Degraded\, \Progressing\, and \Available\ conditions to \Degraded\, \Progressing\, or \Healthy\ states respectively. Corresponding test data and a YAML test file are included to verify the health status logic.
_resource\customizations/ocs.openshift.io · high confidence
Add health check for OpenShift DeploymentConfig resources
A new health check script has been added for OpenShift DeploymentConfig resources, enabling the UI to display the deployment status (Healthy, Progressing, or Degraded) based on the availability and progression conditions of the replication controller. This change ensures that users can accurately track the rollout status of their deployments directly in the dashboard.
_resource\customizations/apps.openshift.io · high confidence
Add health check for OpenTelemetryCollector resources
A new health check script for OpenTelemetryCollector resources has been added, enabling the system to report the status of the collector based on its replica count and mode. The script distinguishes between DaemonSet and sidecar modes, correctly handling edge cases such as a DaemonSet with zero eligible nodes (0/0) and sidecar deployments. Test cases are included to verify healthy, degraded, and progressing states.
_resource\customizations/opentelemetry.io · high confidence
Add health check for SparkApplication resources
A new health check script has been added for the \SparkApplication\ custom resource. This script evaluates the \applicationState\ and \executorState\ to determine the resource's health status, including support for dynamic allocation configurations via both the operator API and SparkConf. Test cases have been added to verify the health status for various states such as Healthy, Degraded, and Progressing.
_resource\customizations/sparkoperator.k8s.io · high confidence
Add health check for Spot.io SpotDeployment resources
Added a Lua script that implements health status checks for Spot.io SpotDeployment resources, identifying states such as Healthy, Progressing, Suspended, and Degraded based on the resource's status conditions and phase. The change includes corresponding test data files to validate the health check logic for healthy, degraded, and invalid specification scenarios.
_resource\customizations/spot.io · high confidence
Add health check logic for 3scale resources
Added Lua scripts and test data for health status evaluation across 3scale resources, including APIManager, ActiveDoc, Application, ApplicationAuth, Backend, CustomPolicyDefinition, DeveloperAccount, DeveloperUser, OpenAPI, Product, ProxyConfigPromote, and Tenant. Each resource now has a corresponding health check script that determines its status (Healthy, Degraded, Suspended, or Progressing) based on conditions and deployment states, along with YAML test cases to validate the logic.
_resource\_customizations/apps.3scale.net, resource\customizations/capabilities.3scale.net · high confidence
Add health check logic for SpinApp resources
A new Lua script (health.lua) and associated test data files have been added to define how the health status of SpinApp custom resources is determined. The script evaluates the resource's status conditions (Available, Progressing) and ready replica counts to report a status of Healthy, Progressing, or Degraded. This enables users to see the operational state of their SpinApp deployments directly in the UI.
_resource\customizations/core.spinkube.dev · high confidence
Add health check scripts for AtlasMigration and AtlasSchema resources
New Lua health check scripts and corresponding test data have been added for the \AtlasMigration\ and \AtlasSchema\ custom resources. These scripts evaluate the \Ready\ condition of the resources to report their status as Healthy, Progressing, or Degraded, allowing users to monitor the operational state of their database migrations and schema changes directly in the UI.
_resource\customizations/db.atlasgo.io · high confidence
Add health check scripts for Crossplane and Upbound resources
New Lua health check scripts and test data are added for Crossplane and Upbound resources. For Crossplane, the health check identifies healthy, progressing, and degraded states for types like Composition, ConfigurationRevision, and ProviderConfig, including backwards compatibility for Crossplane v1. For Upbound, the health check evaluates the Ready, Synced, and LastAsyncOperation conditions to determine the health status of managed resources and provider configurations. These changes improve visibility into the status of infrastructure-as-code resources within the Argo CD UI.
_resource\customizations/\.crossplane.io, resource\customizations/\.upbound.io · high confidence_
Add health check scripts for Humio custom resources
Added Lua-based health check scripts and corresponding YAML test data for Humio custom resources (HumioAction, HumioAlert, HumioCluster, HumioIngestToken, HumioParser, HumioRepository, and HumioView). These scripts evaluate the \status.state\ of each resource and map it to a health status (Healthy, Missing, Degraded, Progressing, or Unknown) with descriptive messages. This enables the system to report the operational health of these specific resource types.
_resource\customizations/core.humio.com · high confidence
Add health check scripts for Karmada bindings
New Lua health check scripts and corresponding YAML test data have been added for Karmada's \ClusterResourceBinding\ and \ResourceBinding\ custom resources. These scripts evaluate the \aggregatedStatus\ of each binding to determine if the resource is \Healthy\, \Degraded\, or \Progressing\ based on cluster health states and application status, enabling the dashboard to display accurate health conditions for these resources.
_resource\customizations/work.karmada.io · high confidence
Add health check scripts for Numaplane CRDs
Added Lua scripts and test data for the ISBServiceRollout and NumaflowControllerRollout custom resource definitions. These scripts implement health status checks, allowing the system to report on the health of these resources by evaluating their status conditions and phase. The implementation covers healthy, progressing, and degraded states, with corresponding test cases to verify the logic.
_resource\customizations/numaplane.numaproj.io/ISBServiceRollout · high confidence
Add health check scripts for OpenKruise workloads
Added Lua-based health check scripts and corresponding test data for OpenKruise resources, including AdvancedCronJob, BroadcastJob, CloneSet, DaemonSet, StatefulSet, and Rollout. Each resource now has a \health.lua\ file that evaluates the object's status to determine if it is Healthy, Progressing, Degraded, or Suspended, along with \health\_test.yaml\ and \testdata\ files to verify the logic.
_resource\customizations/apps.kruise.io · high confidence
Add health checks and create-workflow actions for Argo Workflows resources
Users can now see the health status of Argo CronWorkflow and WorkflowTemplate resources, with the system reporting 'Healthy' when no errors are present and 'Degraded' if a SpecError or SubmissionError condition is detected. Additionally, a 'Create Workflow' action is now available for both CronWorkflow and WorkflowTemplate resources, allowing users to manually instantiate a Workflow from these templates directly from the UI.
_resource\customizations/argoproj.io/CronWorkflow · high confidence
Add health checks and suspend/resume actions for MariaDB resources
Adds health check scripts for MariaDB custom resources (MariaDB, Database, Grant, User, Backup, SqlJob) to report status based on Kubernetes conditions. Additionally, implements suspend and resume actions for the MariaDB resource, allowing users to pause or restart the operator's reconciliation loop.
_resource\customizations/k8s.mariadb.com · high confidence
Add health checks and terminate action for AnalysisRun and Experiment resources
Added health check scripts for the \AnalysisRun\ and \Experiment\ custom resources, mapping their \status.phase\ values (Pending, Running, Successful, Failed, Error, Inconclusive) to UI status indicators (Progressing, Healthy, Degraded, Unknown) with descriptive messages. Additionally, a \terminate\ action was implemented for \AnalysisRun\ objects, allowing users to stop a running analysis run; this includes the Lua logic to set the \spec.terminate\ flag and corresponding test cases to verify the action's behavior.
_resource\customizations/argoproj.io/AnalysisRun · high confidence
Add health checks for Ceph and ObjectBucketClaim resources
New health check scripts and test data have been added for CephCluster, CephObjectStore, and ObjectBucketClaim custom resources. The CephCluster health script now reports status based on Ceph cluster health (HEALTH\_OK/WARN/ERR) and Rook state, while CephObjectStore checks the phase status. ObjectBucketClaim health checks now reflect Bound/Failed/Pending states. These changes enable more accurate status reporting for these resources in the UI.
_resource\customizations/ceph.rook.io · high confidence
Add health checks for Cluster API resources
New health check scripts and test data have been added for Cluster API resources, including Cluster, Machine, MachineDeployment, MachineHealthCheck, and MachinePool. Each resource now has a Lua script that evaluates its status based on phase, conditions, and other attributes, allowing users to see the health status of their Cluster API resources in the UI.
_resource\customizations/cluster.x-k8s.io · high confidence
Add health checks for Coralogix Alert and RecordingRuleGroupSet resources
Users can now see the health status of Coralogix Alert and RecordingRuleGroupSet custom resources in the Argo UI. The new Lua scripts evaluate the 'RemoteSynced' condition to report 'Healthy' when synced successfully, 'Degraded' if the remote sync fails, or 'Progressing' while waiting for updates. Corresponding test data and test definitions are included to validate these states.
_resource\customizations/coralogix.com · high confidence
Add health checks for Crossplane providers
A new health check script has been added for Crossplane Provider resources, enabling the system to report their status as Healthy, Degraded, or Progressing based on the provider's conditions. This change introduces the logic to evaluate the 'Installed' and 'Healthy' conditions to determine the provider's health, accompanied by corresponding test cases to verify the behavior.
_resource\customizations/pkg.crossplane.io · high confidence
Add health checks for ExternalSecret resources
Users can now see the health status of ExternalSecret resources, with states for Healthy, Degraded, and Progressing conditions. This change introduces a Lua script that evaluates the status field of an ExternalSecret to determine its health, along with corresponding test data and test cases to verify the health check logic.
_resource\customizations/kubernetes-client.io · high confidence
Add health checks for GitOps Promoter resources
New health check scripts and test data have been added for the Argo CD Commit Status, Change Transfer Policy, Cluster SCM Provider, Commit Status, and Git Commit Status custom resources. These scripts evaluate the status conditions and spec fields of each resource to determine if they are Healthy, Progressing, or Degraded, providing users with clear, actionable status messages about the state of their GitOps promotion workflows.
_resource\customizations/promoter.argoproj.io · high confidence
Add health checks for Grafana operator resources
Added health check scripts and test data for the Grafana, GrafanaDashboard, GrafanaFolder, and GrafanaDatasource custom resources. These scripts evaluate the status of each resource to report Healthy, Degraded, or Progressing states, enabling users to monitor the health of their Grafana operator-managed resources directly in the UI.
_resource\customizations/grafana.integreatly.org · high confidence
Add health checks for KnativeEventing and KnativeServing custom resources
Users can now monitor the health status of KnativeEventing and KnativeServing custom resources. New Lua scripts evaluate the 'Ready', 'InstallSucceeded', 'DependenciesInstalled', and 'DeploymentsAvailable' conditions to report 'Healthy', 'Progressing', or 'Degraded' states, providing clearer visibility into the operational status of these components.
_resource\customizations/operator.knative.dev · high confidence
Add health checks for OpenShift IngressController resources
Added a Lua-based health check script for the IngressController resource type, enabling the platform to report the health status of IngressController instances. The script evaluates the \status.conditions\ field to determine if the controller is Healthy, Degraded, or Progressing based on specific condition types (Available, Progressing, Degraded). Corresponding test cases and sample YAML data files were added to validate the health check logic against various states including initialization, pod rollout, and degraded conditions.
_resource\customizations/operator.openshift.io · high confidence
Add health checks for ServiceBinding and ServiceInstance
Added health check scripts for the ServiceBinding and ServiceInstance custom resources. The new Lua scripts evaluate the resource's status conditions to report Healthy, Progressing, or Degraded states, allowing the platform to monitor the operational status of these services.
_resource\customizations/services.cloud.sap.com · high confidence
Add health checks for Strimzi Kafka custom resources
Custom health checks are now implemented for Strimzi Custom Resource Definitions (CRDs) including Kafka, KafkaConnector, KafkaBridge, KafkaConnect, KafkaTopic, and KafkaUser. Each resource now reports a status of Healthy, Degraded, or Progressing based on the resource's status conditions, allowing users to monitor the operational state of their Kafka infrastructure directly in the dashboard.
_resource\customizations/kafka.strimzi.io · high confidence
Add health checks for TridentOrchestrator and TridentBackendConfig
Users can now see the health status of NetApp Trident resources. Custom health check scripts have been added for the \TridentOrchestrator\ and \TridentBackendConfig\ custom resources. These scripts evaluate the \status\ and \lastOperationStatus\ fields to report the resources as Healthy, Degraded, or Progressing, providing users with clear visibility into the installation and backend creation states.
_resource\customizations/trident.netapp.io · high confidence
Add health checks for VolumeSnapshot and VolumeSnapshotContent resources
Users can now monitor the health status of Kubernetes VolumeSnapshot and VolumeSnapshotContent resources. The system evaluates the \readyToUse\ and \error\ fields in the resource status to report 'Healthy' (ready to use), 'Degraded' (error present), or 'Progressing' (waiting for status).
_resource\customizations/snapshot.storage.k8s.io · high confidence
Add health checks for cert-manager Certificate and Issuer resources
Users can now see the health status of cert-manager Certificate and Issuer resources in the Argo CD UI. This change introduces Lua scripts and corresponding test data that evaluate the 'Ready' condition of these resources, displaying 'Healthy', 'Degraded', or 'Progressing' states based on the cert-manager status conditions.
_resource\customizations/certmanager.k8s.io · high confidence
Add health checks for cert-manager resources
Custom health check scripts and test data have been added for cert-manager's Certificate, ClusterIssuer, and Issuer resources. The Certificate health check now distinguishes between 'Progressing' (when the certificate is being issued), 'Degraded' (when the Ready condition is False), and 'Healthy' states, ensuring consistent status reporting. Similarly, ClusterIssuer and Issuer resources now have health checks that report 'Healthy' when the Ready condition is True and 'Degraded' when it is False. These changes improve visibility into the status of cert-manager managed certificates and issuers within the application's UI.
(repo-wide) · medium confidence
Add health status and force-sync action for PushSecret resources
This change introduces new resource customizations for the PushSecret CRD, enabling Argo CD to monitor its health and perform a force-sync action. The health check (health.lua) evaluates the 'Ready' condition to report Healthy, Degraded, or Progressing states, with corresponding test cases. Additionally, a 'push' action is added that annotates the resource with a 'force-sync' timestamp, and a discovery script (discovery.lua) that disables the push action when the refresh interval is zero. Test data files are also included to validate these behaviors.
_resource\customizations/external-secrets.io/PushSecret · high confidence
Add health status and refresh action for ExternalSecret resources
Argo CD now supports the external-secrets.io/ExternalSecret resource type. The UI will display health status (Healthy, Degraded, or Progressing) based on the resource's conditions, and a 'refresh' action is available to manually trigger a secret update. The refresh action is automatically disabled when the secret is already up to date, preventing unnecessary API calls.
_resource\customizations/external-secrets.io/ExternalSecret · high confidence
Add health status check for Keycloak resources
Introduces a new health check script for Keycloak custom resources that evaluates the 'Ready' and 'HasErrors' conditions to report Healthy, Degraded, or Progressing states. The implementation includes a sorting mechanism that ensures conditions with a nil 'lastTransitionTime' are placed after those with valid timestamps, and is accompanied by corresponding test cases.
_resource\customizations/k8s.keycloak.org · high confidence
Add health status checks for AWS RDS DBCluster and DBInstance resources
Users can now see the health status of AWS RDS DBCluster and DBInstance resources. The system evaluates the 'Ready' and 'Synced' conditions to report states such as Healthy, Progressing, Degraded, or Suspended, providing clear messages about the resource's availability and reconciliation status.
_resource\customizations/rds.aws.crossplane.io · high confidence
Add health status checks for AnsibleJob resources
Users can now see the health status of AnsibleJob custom resources in the Argo CD UI. The new Lua script evaluates the job's lifecycle state: jobs that are 'successful' are marked as Healthy, while 'failed', 'error', or 'canceled' jobs are marked as Degraded. Jobs in transitional states ('new', 'pending', 'running', 'waiting') are marked as Progressing. This provides immediate visibility into the execution status of Ansible automation jobs.
_resource\customizations/tower.ansible.com · high confidence
Add health status checks for Camel K Integration resources
Users will now see the health status of their Camel K Integrations in the UI. The system evaluates the 'Ready' condition in the Integration's status to report 'Healthy', 'Degraded', or 'Progressing' states, providing clear visibility into the deployment and runtime health of these workloads.
_resource\customizations/camel.apache.org · high confidence
Add health status checks for ClickHouse and ClickHouseKeeper installations
Users will now see explicit health status indicators for ClickHouse and ClickHouseKeeper installations. The system evaluates the \status.status\ field of these resources to display 'Healthy' when completed, 'Progressing' while in progress or when status is unavailable, and 'Degraded' for any other status. This change introduces Lua scripts and corresponding test data to define these health conditions.
_resource\_customizations/clickhouse-keeper.altinity.com, resource\customizations/clickhouse.altinity.com · high confidence
Add health status checks for CloudFront Distributions
Users can now see the health status of AWS CloudFront Distributions managed by Crossplane. The system now evaluates the 'Ready' and 'Synced' conditions to report the resource as Healthy, Progressing, Suspended, or Degraded, providing clearer visibility into the state of the distribution.
_resource\customizations/cloudfront.aws.crossplane.io · high confidence
Add health status checks for Contour HTTPProxy and ExtensionService resources
Users can now monitor the health of Contour HTTPProxy and ExtensionService resources. New Lua scripts evaluate the 'Valid' status condition to report Healthy, Degraded, or Progressing states. The HTTPProxy checker includes special handling for parent-child inclusion relationships to prevent deployment blocks, while the ExtensionService checker validates status conditions against the resource generation.
_resource\customizations/projectcontour.io · high confidence
Add health status checks for Kubernetes Gateway API resources
Added health status checks for Kubernetes Gateway API resources, including BackendTLSPolicy, GRPCRoute, Gateway, GatewayClass, and HTTPRoute. Each resource now has a Lua script that evaluates the status conditions (such as Accepted, ResolvedRefs, and Programmed) to determine if the resource is Healthy, Degraded, or Progressing. Test data and test cases have been added to verify the health status logic for each resource type.
_resource\customizations/gateway.networking.k8s.io · high confidence
Add health status checks for Kyverno Policy resources
Users will now see the health status of Kyverno Policy resources, with the system reporting 'Healthy' when the policy is ready and 'Progressing' while it is being applied.
_resource\customizations/kyverno.io · high confidence
Add health status checks for Numaplane PipelineRollout resources
Users will now see accurate health status indicators for Numaplane PipelineRollout resources, with the system evaluating conditions to report whether the resource is Healthy, Progressing, Degraded, or Paused based on the underlying status conditions and phase.
_resource\customizations/numaplane.numaproj.io/PipelineRollout · high confidence
Add health status checks for PostgreSQL and SolrCloud resources
Users can now see accurate health statuses for \acid.zalan.do/postgresql\ and \solr.apache.org/SolrCloud\ custom resources. New Lua scripts evaluate the \PostgresClusterStatus\ and \solrNodes\ fields to report \Healthy\, \Progressing\, or \Degraded\ states, with corresponding messages. Test fixtures and test definitions are included to validate these health checks.
_resource\_customizations/acid.zalan.do, resource\customizations/solr.apache.org · high confidence
Add health status checks for RabbitMQ custom resources
Added health check scripts and test data for RabbitMQ resources, including the RabbitmqCluster, Binding, Exchange, Policy, Queue, Shovel, User, and Vhost. The system now evaluates the status of these resources, reporting Healthy, Degraded, or Unknown states based on specific conditions like 'SuccessfulCreateOrUpdate' or 'FailedCreateOrUpdate'. For the RabbitmqCluster, the health check also distinguishes between 'Progressing' and 'Degraded' states, ensuring that transient 'Unknown' conditions during cluster formation are treated as 'Progressing' rather than 'Degraded'.
_resource\customizations/rabbitmq.com · high confidence
Add health status checks for SealedSecret resources
Users will now see the health status of SealedSecret resources in the UI. The system evaluates the 'Synced' condition in the resource's status: it displays 'Healthy' when synced successfully, 'Degraded' if the sync condition is false (showing the error message), and 'Progressing' while waiting for decryption. This change adds the necessary Lua logic and test data to support this visibility.
_resource\customizations/bitnami.com · high confidence
Add health status checks for external-secrets.io cluster resources
New Lua scripts and test data have been added to define health status checks for ClusterExternalSecret and ClusterSecretStore resources. For ClusterExternalSecret, the system now evaluates the latest status condition to report Healthy, Degraded, or Progressing states. For ClusterSecretStore, the system checks the Ready condition to determine if the store is Healthy, Degraded, or Progressing. This enables users to monitor the operational state of these external secret resources directly in the UI.
_resource\_customizations/external-secrets.io/ClusterExternalSecret, resource\customizations/external-secrets.io/ClusterSecretStore · high confidence
Add health status checks for microgateway policies
A new Lua script and associated test data have been added to the microgateway resource customizations to evaluate the health of various policy kinds (such as AccessControlPolicy, ContentSecurityPolicy, and RateLimitPolicy). The script inspects ancestor conditions to determine if a policy is Healthy, Degraded (e.g., conflicting or unresolved references), or Progressing, providing users with detailed status messages about policy acceptance and resolution.
_resource\customizations/microgateway.airlock.com · high confidence
Add health status reporting for Elasticsearch resources
Users can now see the health status of Elasticsearch resources in the ArgoCD UI. The system evaluates the cluster's health (green, yellow, or red) and phase (Ready, ApplyingChanges, MigratingData, Invalid) to display a corresponding status (Healthy, Progressing, or Degraded) with a descriptive message. This includes checking if the number of available nodes matches the desired count.
_resource\_customizations/argoproj.io/ApplicationSet, resource\_customizations/elasticsearch.k8s.elastic.co, resource\customizations/logstash.k8s.elastic.co · high confidence
Add health status reporting for Flagger Canary resources
A Lua script has been added to define the health status of Flagger Canary resources. The script maps the resource's phase (such as Progressing, Finalising, Promoting, Succeeded, or Failed) to a health status (Progressing, Degraded, Healthy, or Unknown) and constructs a descriptive message. This enables users to see the current state and health of their canary deployments directly in the UI.
_resource\customizations/flagger.app · high confidence
Add health-check scripts for Kruise GameServer and GameServerSet
New Lua health-check scripts and corresponding test data have been added for the \game.kruise.io\ custom resources. For \GameServer\, the health status is now determined by comparing the current and desired states, checking for \KruisePodReady\ conditions, and reporting Healthy, Progressing, or Degraded states. For \GameServerSet\, health is assessed based on rolling update strategies, including paused states, partition-based updates, and replica readiness, reporting Suspended, Progressing, or Healthy states accordingly.
_resource\customizations/game.kruise.io · high confidence
Add health-checks for Percona XtraDB Cluster
Users can now see the health status of Percona XtraDB Cluster resources in Argo CD. A new Lua script in \resource\_customizations/pxc.percona.com/PerconaXtraDBCluster/health.lua\ maps the cluster's \status.state\ to Argo CD health statuses: 'initializing' becomes Progressing, 'ready' becomes Healthy, 'paused' becomes Unknown, 'stopping' and 'error' become Degraded, and any other state defaults to Unknown with a link to the Argo CD issues page. A corresponding test file \health\_test.yaml\ and several YAML test data files are added to verify this behavior.
_resource\customizations/pxc.percona.com · high confidence
Add health-checks for eck elastic beat
Users can now see the health status of their Elastic Beat resources in ArgoCD. The new Lua script evaluates the \status.health\ field of a Beat resource, mapping 'green' to 'Healthy', 'red' to 'Degraded', and 'yellow' or missing status to 'Progressing'. This provides immediate visibility into the operational state of Elastic Beats within the ArgoCD UI.
_resource\customizations/beat.k8s.elastic.co · high confidence
Add internal HTTP client for ApplicationSet services
A new internal HTTP client has been introduced in the ApplicationSet service layer, providing a structured way to make authenticated API requests. The client supports configurable base URLs, bearer token authentication, and custom request timeouts. It handles JSON encoding and decoding, manages HTTP headers (including User-Agent and Authorization), and includes robust error handling that parses API error responses. Comprehensive unit tests verify client creation, request building, response parsing, and error scenarios.
applicationset/services/internal/http · high confidence
Add manual rolling-update action for StrimziPodSet
Users can now trigger a rolling update for a StrimziPodSet by adding the annotation strimzi.io/manual-rolling-update: true. This change introduces the necessary Lua logic to detect this annotation and a corresponding test suite to verify the action's discovery and execution.
_resource\customizations/core.strimzi.io · high confidence
Add new rate limiter implementation for app controllers
A new rate limiter implementation has been added to the codebase, introducing a custom rate limiter for app controllers that supports both overall and per-item rate limiting. The implementation includes a token bucket for global limiting and an exponential backoff mechanism with auto-reset for individual items, allowing for more granular control over queue processing rates.
pkg/ratelimiter · high confidence
Add pause and unpause actions for MonoVertexRollout resources
Users can now pause and resume the processing of MonoVertexRollout resources directly through the UI. The update introduces three new actions: 'pause', 'unpause-gradual', and 'unpause-fast'. Pausing a rollout sets the lifecycle desired phase to 'Paused', while unpausing restores it to 'Running'. The 'unpause-fast' action configures the rollout to resume immediately, whereas 'unpause-gradual' allows for a more controlled, gradual resumption of processing. These actions are governed by the \numaflow.numaproj.io/allowed-resume-strategies\ annotation, which determines which resume strategies are available for a given rollout.
_resource\customizations/numaplane.numaproj.io/MonoVertexRollout/actions · high confidence
Add pause and unpause actions for PerconaServerMongoDB
Users can now pause and unpause a PerconaServerMongoDB cluster directly from the UI. The resource customization adds 'pause' and 'unpause' actions that toggle the cluster's paused state, with the UI dynamically enabling or disabling these buttons based on the current status.
_resource\customizations/psmdb.percona.com · high confidence
Add pause, resume, restart, and scale actions for Deployments
Users can now pause and resume Deployments, restart them to trigger a new rollout, and scale them to a specific number of replicas directly from the UI. The pause action sets the deployment's paused state to prevent updates, while the resume action clears it. The restart action adds a timestamp annotation to trigger a rollout, and the scale action allows adjusting the replica count.
_resource\customizations/apps/Deployment · high confidence
Add pause/resume actions and health checks for KEDA ScaledObject and ScaledJob
Users can now pause and resume KEDA ScaledObject and ScaledJob resources directly from the UI. For ScaledObject, a new 'paused-replicas' action allows specifying the number of replicas to maintain while paused. Health checks for both resources now reflect their operational state, including a new 'Suspended' status for paused resources and a 'Fallback' condition for ScaledObject health assessment.
_resource\customizations/keda.sh · high confidence
Add pull request generators for Azure DevOps, Bitbucket, Gitea, and Bitbucket Server
The ApplicationSet controller now supports generating applications from pull requests in Azure DevOps, Bitbucket Cloud, Bitbucket Server, and Gitea, in addition to existing support for GitHub and GitLab. This adds new service implementations in the \applicationset/services/pull\_request\ directory, each handling the specific API and authentication requirements for their respective platforms. The changes include new files for each provider (e.g., \azure\_devops.go\, \bitbucket\_cloud.go\, \gitea.go\), error handling for missing repositories, and corresponding unit tests.
_applicationset/services/pull\request · high confidence
Add resource generation tools for Argo CD test fixtures
The \hack/gen-resources\ directory now includes a new Go-based tool for generating test resources for Argo CD. This includes generators for Applications, Clusters, Projects, and Repositories. The Application generator creates random source and destination configurations, the Cluster generator provisions vCluster instances and retrieves credentials, the Project generator creates sample projects, and the Repo generator fetches and creates repository secrets. All generated resources are tagged with the label \app.kubernetes.io/generated-by=argocd-generator\ for easy identification and cleanup.
hack/gen-resources/generators · high confidence
Add restart and scale actions for StatefulSet and DaemonSet
Users can now restart workloads by adding a timestamp annotation to trigger a rolling update, and scale StatefulSets by specifying a replica count. The StatefulSet configuration now supports a 'scale' action with a 'replicas' parameter, while both StatefulSet and DaemonSet support a 'restart' action that updates the template metadata.
_resource\customizations/apps/StatefulSet · high confidence
Add script to determine previous release version for release notes
A new Go-based script, get-previous-version-for-release-notes, has been added to the hack/get-previous-release directory. This tool calculates the correct previous release version based on the current version being released, handling various scenarios such as patch releases, release candidates, and major version transitions. The implementation includes comprehensive unit tests to verify the logic for identifying the appropriate previous tag from the git history.
hack/get-previous-release · high confidence
Add template patching support for ApplicationSets
The ApplicationSet controller now supports applying a \templatePatch\ to generated applications. This new capability allows users to override specific fields of the generated Application resources using a JSON or YAML patch, with the \project\ field explicitly protected from modification to maintain security boundaries.
applicationset/controllers/template · high confidence
Add toggle-auto-sync action for ArgoCD Applications
Users can now enable or disable automatic synchronization for an ArgoCD Application via a new 'toggle-auto-sync' action. This adds a dynamic menu item that displays 'Enable Auto-Sync' or 'Disable Auto-Sync' depending on the current state, and updates the \spec.syncPolicy.automated.enabled\ field accordingly, preserving existing \prune\ and \selfHeal\ settings.
_resource\customizations/argoproj.io/Application · medium confidence
Add webhook payload test data for Azure DevOps and GitHub events
Added JSON test fixtures for Azure DevOps pull request and push events, as well as various GitHub webhook payloads (commits, pull requests, and ping events) to the \applicationset/webhook/testdata\ directory. These files provide the sample payloads used by the webhook handlers to parse and process events from these providers.
applicationset/webhook · high confidence
Added GPG public key management API client
The API client now includes generated Go code for the GPG public key service, enabling users to perform CRUD operations on GnuPGPublicKey resources. This adds the \pkg/apiclient/gpgkey\ package, which provides the client-side implementation for listing, getting, creating, and deleting GPG public keys via the gRPC and HTTP/JSON gateway.
pkg/apiclient/gpgkey · high confidence
Added code generation tool for Kubernetes known types
A new Go utility at hack/known\_types has been added to the project. This tool scans Kubernetes API packages to identify and generate Go code that maps known types, facilitating the normalization of CRD fields that use built-in K8S types.
_hack/known\types · high confidence
Added gen-resources command-line tool for generating Argo CD resources
A new Go-based CLI tool has been added at hack/gen-resources/cmd/main.go to generate Argo CD resources. The tool initializes a command structure and executes it, with explicit support for GCP authentication via the k8s.io/client-go GCP plugin, enabling users to generate resources for GKE clusters.
hack/gen-resources/cmd · medium confidence
Added health check for OLM Subscription resources
A new health check script for \operators.coreos.com/Subscription\ resources has been introduced, enabling the system to accurately report the health status of OpenShift operators. The logic evaluates the subscription's \.status.state\ (e.g., \AtLatestKnown\, \UpgradePending\, \UpgradeFailed\) and relevant conditions (such as \InstallPlanPending\ or \CatalogSourcesUnhealthy\) to determine if the resource is Healthy, Progressing, or Degraded. Notably, the check correctly handles manual approval scenarios, treating a pending install plan for an already-installed operator as a healthy, expected state rather than a failure.
_resource\customizations/operators.coreos.com · high confidence
Added health checks for IstioOperator, Jaeger, and ZookeeperCluster resources
Users can now monitor the health status of IstioOperator, Jaeger, and ZookeeperCluster custom resources. The system now reports 'Healthy', 'Progressing', or 'Degraded' states based on the underlying component status (e.g., Istio status codes, Jaeger phase, or Zookeeper ready replicas). This provides clearer visibility into the operational state of these specific workloads.
_resource\_customizations/install.istio.io, resource\_customizations/jaegertracing.io, resource\customizations/zookeeper.pravega.io · high confidence
Added health status checks for AWS Route 53 ResourceRecordSet resources
Users can now see the health status of AWS Route 53 ResourceRecordSet resources in the UI. The system evaluates the resource's conditions to determine if it is Healthy, Progressing, Degraded, or Suspended, providing clear messages about the resource's current state, such as waiting for creation or reporting reconciliation errors.
_resource\customizations/route53.aws.crossplane.io · high confidence
Added health status checks for KeptnMetric and Analysis resources
Users can now see the health status of KeptnMetric and Analysis resources in the UI. The system evaluates the status of these resources and displays 'Healthy', 'Degraded', or 'Progressing' states based on the presence of errors or successful metric collection. This includes specific handling for empty error messages and warning states for Analysis resources.
_resource\customizations/metrics.keptn.sh · high confidence
Added local Kubernetes test environment helper
A new Go utility (hack/k8s/main.go) was added to the project. It initializes a local Kubernetes test environment using controller-runtime's envtest, writes the resulting kubeconfig, and applies manifests from the 'manifests/base/config' directory. This provides a way to spin up a local K8s cluster for testing or development purposes.
hack/k8s · high confidence
Added migration scripts for the gitops-engine
New shell scripts in the hack/migrate-gitops-engine directory facilitate the migration of the gitops-engine. The merge.sh script automates the process of merging a specific branch from a user's forked gitops-engine repository, followed by executing replace-vendor.sh and update-dockerfile.sh. The replace-vendor.sh script updates the build system to use 'go work vendor' instead of 'go mod vendor' across key files like the Makefile and CI workflows. The update-dockerfile.sh script modifies the Dockerfile to copy Go module files into a gitops-engine subdirectory, supporting the new workspace structure.
hack/migrate-gitops-engine · high confidence
Added repository credential management API and CLI
The repository credential management API and CLI are now available, allowing users to list, create, and delete repository credentials via the API. This change introduces the \repocreds\ package with generated Go code for the gRPC and HTTP gateway, enabling programmatic and command-line interaction with repository credentials.
pkg/apiclient/repocreds · high confidence
Application controller command entry point and test suite added
The application controller command entry point is now defined in cmd/argocd-application-controller/commands/argocd\_application\_controller.go, establishing the CLI structure and flag definitions for the controller. A corresponding test suite in argocd\_application\_controller\_test.go validates the presence and default values of the --hydration-processors flag and verifies that metrics label and condition flags are correctly populated from environment variables.
cmd/argocd-application-controller · high confidence
ApplicationSet API client exposes watch, list, get, and generate endpoints
The ApplicationSet API client now includes generated gRPC and HTTP gateway wrappers for the ApplicationSet service, exposing watch, list, get, and generate operations. This enables clients to subscribe to real-time ApplicationSet updates, retrieve or filter sets by name, namespace, or project, and trigger generation of resulting applications via the API.
pkg/apiclient/applicationset · high confidence
ApplicationSet adds GitHub API metrics and refactors Git repository access
The ApplicationSet controller now exposes Prometheus metrics for GitHub API usage, including request counts, durations, and rate-limit status (remaining, limit, reset, and used counters) via the new \github\_metrics.go\ file. Additionally, Git file and directory retrieval has been refactored into a new \repo\_service.go\ implementation that delegates to the repo server, supporting both submodule and safer globbing options, with corresponding tests added for the new service layer.
applicationset/services · high confidence
ApplicationSet controller exposes new CLI flags for concurrency and cache sync
The ApplicationSet controller command now supports the \--concurrent-application-updates\ flag to control the number of concurrent application updates, and the \--cache-sync-period\ flag to configure the Kubernetes cache sync period. These changes allow users to tune the controller's performance and caching behavior via the CLI.
cmd/argocd-applicationset-controller · high confidence
Automate notifications documentation generation
Added a new Go script at hack/gen-docs/main.go that automatically generates documentation for notification services. The script copies service documentation files into the docs directory and updates the mkdocs navigation configuration to include the new notification service pages, ensuring the documentation remains synchronized with the codebase.
hack/gen-docs · high confidence
Automated generation of command reference documentation
A new Go utility in the tools directory generates Markdown documentation for all CLI and server commands. This automation ensures that the user and operator manual command references are kept in sync with the codebase, improving the accuracy and consistency of the documentation.
tools · high confidence
Automated generation of static Kubernetes schema parser
A new shell script, hack/update\_static\_schema.sh, has been added to automate the creation of a static Kubernetes schema parser. This script fetches the internal parser code from the kubernetes/client-go library, adjusts the package and function names, and writes the result to pkg/utils/kube/scheme/parser.go. This change supports the repository's migration to ArgoCD by providing a generated, static schema parser.
gitops-engine/hack · medium confidence
Cassandra Cluster health status reporting
Added a Lua script that evaluates the health of a Cassandra Cluster resource by checking if all rack members are ready. If every rack's ready member count matches its total member count, the cluster is reported as "Healthy"; otherwise, it is reported as "Progressing" with the message "Waiting for Cassandra Cluster". This change introduces the health check logic and corresponding test data for both healthy and progressing states.
_resource\customizations/cassandra.rook.io · high confidence
Centralized toolchain management for development and codegen utilities
The \hack/installers\ directory has been restructured into a set of dedicated, reusable shell scripts that handle the download, checksum verification, and installation of development tools. This includes a new \compare-chksum.sh\ script for validating downloaded artifacts, and specific installers for \gotestsum\, \golangci-lint\, \mockery\, \protoc\, \git-lfs\, \helm\, and \kustomize\. The Go-based codegen tools are now installed via a unified \install-codegen-go-tools.sh\ script that leverages \go install\ with versions pinned in \go.mod\ or explicit version variables, ensuring consistent tooling across the development environment.
hack/installers · high confidence
Centralizes Argo CD constants and versioning logic in the common package
The \common\ package now serves as the single source of truth for Argo CD component names, default service addresses, Kubernetes resource names, and port configurations. The \version.go\ file has been moved into this package, introducing \KubectlVersion\ and \ExtraBuildInfo\ fields to the version information, and providing a \LogStartupInfo\ helper to log startup details. Additionally, the \common\ package now includes tests for gRPC keep-alive configuration and Redis credential handling.
common · high confidence
Configurable mTLS for the Argo CD API server
The Argo CD API server now supports mutual TLS (mTLS) for connections to the repository server. This change introduces three new command-line flags and environment variables (REPO\_SERVER\_CA\_CERT\_PATH, REpo\_server\_CLIENT\_CERT\_PATH, REPO\_SERVER\_CLIENT\_CERT\_KEY\_PATH) that allow users to specify the CA certificate, client certificate, and private key for secure communication with the repo-server. The implementation includes default paths for the client certificate and key, and ensures that explicit flag values take precedence over embedded certificates. Tests verify that these flags are correctly registered and that environment variables can override the defaults.
cmd/argocd-server · high confidence
Custom resource actions and health status for Flux resources
Users can now suspend and resume Flux resources (HelmRelease, ImageRepository, ImageUpdateAutomation, and Kustomization) via custom actions, and the system displays a 'Suspended' status for these resources when they are paused. Additionally, health status checks have been added for Flux resources (HelmRelease, ImagePolicy, ImageRepository, ImageUpdateAutomation, and Kustomization) to accurately reflect their state (Healthy, Progressing, Degraded, or Suspended) in the UI.
(repo-wide) · high confidence
Extracted sync engine and sync logic into a standalone gitops-engine package
The sync engine and all related logic (including hooks, reconciliation, and common types) have been extracted into a new \gitops-engine\ package. This refactors the codebase by separating the core GitOps synchronization logic from the main Argo CD application, making the sync functionality available as a reusable library for external consumers.
gitops-engine/pkg/sync · high confidence
Generated API client for repository certificate management
Added generated Go code for the Certificate Service API, enabling programmatic management of repository certificates. The new files in pkg/apiclient/certificate define the gRPC and HTTP gateway handlers for listing, creating, and deleting certificates, exposing the certificate CRUD operations to API consumers.
pkg/apiclient/certificate · high confidence
Generated Go clientset and informers for Argo CD v3 API types
The \pkg/client\ directory now contains automatically generated Go code for interacting with Argo CD's \v1alpha1\ API resources (Applications, AppProjects, and ApplicationSets). This includes the typed clientset (\clientset/versioned\), corresponding fake clients for testing, and shared informer factories (\informers/externalversions\) that enable efficient, watch-based synchronization of these resources. This scaffolding provides the programmatic interface for managing these specific resource types within the Argo CD v3 module.
pkg/client · high confidence
Health checks added for Keptn lifecycle resources
Health check scripts and test data have been added for KeptnAppVersion, KeptnEvaluation, KeptnTask, KeptnWorkloadInstance, and KeptnWorkloadVersion resources. Each script evaluates the resource's status field to determine if it is Healthy, Degraded, or Progressing, allowing the dashboard to display accurate status indicators for these custom resources.
_resource\customizations/lifecycle.keptn.sh · high confidence
Improved health checks and custom actions for Numaplane CRDs
Added health check scripts and custom actions for Numaplane resources, including InterStepBufferService and MonoVertex. The health checks now properly report 'Degraded' status for failed progressive upgrades and subresource issues, and 'Healthy' for paused states. Custom actions such as 'pause', 'unpause-gradual', 'unpause-fast', and 'force-promote' are now available for MonoVertex resources, with logic to disable pause/unpause actions when the resource is a child of a rollout. The 'force-promote' action is conditionally enabled based on upgrade state labels.
_resource\customizations/numaflow.numaproj.io · high confidence
Initial implementation of the Argo CD Application Controller
The application controller, responsible for reconciling the desired state of applications against the live cluster state, is introduced as a new component. This includes the core controller logic, cluster information updater, and associated unit tests, establishing the foundation for automated application synchronization and health monitoring.
controller · high confidence
Initialize API rules violation exceptions list
A new file, pkg/apis/api-rules/violation\_exceptions.list, has been added to the codebase. This file, currently empty, establishes the configuration for API rules violation exceptions, allowing users to define specific API rule violations that should be ignored or handled differently.
pkg/apis/api-rules · high confidence
Introduce Account Service for Password and Permission Management
The server now exposes a new Account service that allows users to update their own or other users' local passwords, list all configured accounts, and check RBAC permissions for specific resources and actions. This introduces the backend implementation for account management, including password complexity validation, SSO token age checks, and fine-grained RBAC enforcement for account operations.
server · high confidence
Introduce AppProject and ApplicationSet CRD type definitions
The codebase now includes the Go type definitions for the AppProject and ApplicationSet custom resources. AppProject defines the logical grouping of applications with controls for cluster whitelisting, repository access, and RBAC policies, including JWT token management for roles. ApplicationSet introduces the structure for generating multiple applications from a single template, supporting various generators, sync policies, and progressive rollout strategies. These types form the API contract for managing project-scoped access and automated application generation.
pkg/apis/application/v1alpha1 · high confidence
Introduce ArgoCD Config Management Plugin (CMP) Server
A new \argocd-cmp-server\ command is introduced, serving as the internal sidecar for the reposerver. It supports configurable log format and level, and provides OpenTelemetry tracing with support for secured endpoints, custom headers, extra attributes, and configurable sampling ratios.
cmd/argocd-cmp-server · high confidence
Introduce Config Management Plugin (CMP) API client
Added the \cmpserver/apiclient\ package, which provides the Go client for communicating with the Config Management Plugin server. This new clientset manages gRPC connections with configurable retry policies, OpenTelemetry tracing, and adjustable message size limits, enabling the system to interact with CMPs via Unix sockets.
cmpserver/apiclient · high confidence
Introduce Config Management Plugin (CMP) server implementation
The cmpserver/plugin directory now contains the core implementation for the Config Management Plugin server, including the gRPC service definition, configuration parsing, and plugin execution logic. This adds the necessary Go code and test fixtures to support CMP plugins, enabling Argo CD to manage and generate manifests from various configuration management tools.
cmpserver/plugin · high confidence
Introduce a localized toolchain and build infrastructure
The \hack\ directory now contains a comprehensive set of scripts and configuration files that establish a localized toolchain for building and testing the project. This includes a \Dockerfile.dev-tools\ and \install.sh\ script to manage tool versions (defined in \tool-versions.sh\), a \.dockerignore\ to optimize builds, and various helper scripts for code generation, release management, and CI/CD integration. These changes support a more robust and portable development and release environment.
hack · high confidence
Introduce commit server to handle manifest hydration commits
A new commit server service has been added to the codebase, providing a dedicated gRPC service for committing hydrated manifests to a repository. This service, located in the \commitserver/commit\ package, manages the logic for cloning repositories, writing manifest files, and pushing changes. The implementation includes a new \CommitService\ with a \CommitHydratedManifests\ RPC, supported by helper functions for writing metadata, README templates, and handling git credentials. The change also introduces a race-condition test (\addnote\_race\_test.go\) to ensure concurrent note additions are safe, and includes unit tests for the commit and credential helper logic.
commitserver/commit · high confidence
Introduce dedicated argocd-dex CLI for Dex server management
The \argocd-dex\ command-line interface is now available, providing \rundex\ and \gendexcfg\ subcommands. The \rundex\ command manages the Dex server lifecycle, including TLS configuration, logging format/level, and automatic restarts on config changes. The \gendexcfg\ command generates Dex configuration YAML from Argo CD settings. This change consolidates Dex-related CLI functionality into a dedicated binary.
cmd/argocd-dex · high confidence
Introduce dedicated commit-server binary and configurable TLS for repo-server
Argo CD now ships a separate \argocd-commit-server\ binary responsible for committing and pushing hydrated manifests to Git, decoupling this workload from the main Argo CD process. The \argocd-repo-server\ gains a new \--disable-tls\ flag that allows administrators to disable TLS for the repo-server's gRPC and health-check endpoints, while also supporting configurable OTLP headers for OpenTelemetry tracing. Additionally, the repo-server now supports configurable mTLS for health checks and allows disabling TLS entirely, providing more flexibility in internal service communication.
cmd/argocd-repo-server · high confidence
Introduce dedicated git ask-pass CLI command
A new \argocd-git-ask-pass\ command has been added to the CLI, serving as a dedicated helper for passing Git credentials. The command connects via a configurable Unix socket to the ask-pass service to retrieve username and password based on environment variables, replacing the previous approach of passing git credentials directly to git/kustomize.
cmd/argocd-git-ask-pass · high confidence
Introduce gen-catalog CLI for notifications catalog and docs generation
A new \hack/gen-catalog\ tool is added to generate the built-in notifications catalog (templates and triggers) into a ConfigMap and to produce Markdown documentation for the operator manual. The tool reads from \notifications\_catalog/templates\ and \notifications\_catalog/triggers\ directories, marshals the data using \sigs.k8s.io/yaml\, and writes the resulting ConfigMap to \notifications\_catalog/install.yaml\. It also generates documentation pages for triggers, templates, and admin commands, utilizing the \tablewriter\ library for formatted output. This change supports the migration of Argo CD notifications to the main Argo CD codebase by providing a centralized way to manage and document built-in notification resources.
hack/gen-catalog · high confidence
Introduce new CLI utility commands for managing applications, clusters, and projects
The \cmd/util\ package now provides new command-line utilities for generating and managing Argo CD resources. Users can now use \argocd-util app generate-spec\ to create Application specs with support for Helm, Kustomize, and Jsonnet options, as well as multi-source applications. New commands allow generating AppProject specs with resource restrictions and destination configurations. Additionally, cluster management utilities have been added to handle kubeconfig contexts, retrieve the public Kubernetes endpoint, and construct cluster objects with TLS, AWS, and exec-provider configurations. These utilities streamline the creation and validation of Argo CD configuration objects via the CLI.
cmd/util · high confidence
Introduce new Config Management Plugin (CMP) server
A new gRPC server implementation for Config Management Plugins has been added, providing the runtime environment for plugin execution. The server configures gRPC options including logging, metrics collection via Prometheus, and OpenTelemetry tracing support. It also registers the plugin service, health checks, and version endpoints, enabling the Argo CD server to communicate with CMPs over a Unix socket.
cmpserver · high confidence
Introduce new Notification Service API and gRPC proxy client implementation
The API client package now includes generated protobuf code for the Notification Service, exposing ListTriggers, ListServices, and ListTemplates endpoints via both gRPC and a RESTful JSON gateway. The core client implementation has been refactored to use a new executeRequest method that handles HTTP/HTTPS requests with proper header parsing and error handling. A gRPC proxy server is now started to forward requests, with improvements to prevent connection leaks by ensuring response bodies are closed on errors. The client also supports additional headers via the --additional-headers CLI flag, and the proxy ensures full header reading to avoid issues with colons in header values.
pkg/apiclient · high confidence
Introduce new sharding cache and sharding algorithm implementations
The sharding package now includes a new cache implementation (cache.go) that maintains in-memory maps of clusters and applications to track shard assignments, alongside updated sharding logic (sharding.go) that supports multiple distribution algorithms including a new consistent hashing with bounded loads algorithm. The cache handles cluster and application lifecycle events (Add, Delete, Update) and provides methods to retrieve shard distributions. Tests (cache\_test.go, sharding\_test.go, shuffle\_test.go) verify the behavior of the legacy, round-robin, and consistent hashing sharding algorithms.
controller/sharding · high confidence
Introduce new utility packages for Kubernetes resource management and IO operations
The gitops-engine now includes new utility packages in the \pkg/utils\ directory to support Kubernetes resource operations and IO handling. The \pkg/utils/io\ package provides helper functions for temporary directory management and file deletion. The \pkg/utils/json\ package adds functions to remove non-existent fields from live objects for diffing purposes. The \pkg/utils/kube\ package introduces a new \Kubectl\ interface and its \KubectlCmd\ implementation, which encapsulates Kubernetes client operations such as converting resource versions, loading OpenAPI schemas, and managing resources. Additionally, mock implementations (\kubetest\ and \mocks\) are provided to facilitate testing of these new components.
gitops-engine/pkg/utils · high confidence
Introduce notifications controller with namespace filtering and self-service support
The notifications controller is introduced, implementing the core logic for processing and delivering notifications. The controller filters applications based on configured namespaces and supports a self-service mode that allows notifications to be configured across all namespaces. The implementation includes cache synchronization, certificate resolution, and integration with the notifications-engine library.
_notification\controller · high confidence
Introduce plugin service for external plugin execution
Added a new plugin service implementation that enables external plugins to be executed via an HTTP client. The service constructs requests to a plugin's API endpoint, handling authentication tokens and timeouts, and returns structured responses containing parameters. This change introduces the core service logic, utility functions for parsing secret keys, and corresponding unit tests to verify the plugin service's behavior.
applicationset/services/plugin · high confidence
Introduce resource status tracking for ApplicationSets
Added new Go code in the applicationset/status package to manage and track the status of individual resources within an ApplicationSet. The implementation includes functions to build a map of resource statuses from a list of applications, retrieve existing statuses from the ApplicationSet's current state, and clean up statuses for applications that have been deleted.
applicationset/status · high confidence
Introduce shared Renovate configuration presets
The \renovate-presets\ directory now contains a suite of reusable Renovate configuration presets, including \commons.json5\ for default rules and labels, \devtool.json5\ for CI and dev environment updates, \production-binaries.json5\ for runtime binaries like Helm and Kustomize, and custom managers for shell scripts, YAML files, and the Renovate GitHub Action. These presets allow repositories to extend a single configuration file to manage dependency updates, automate post-upgrade tasks (such as running \make mockgen\ or updating checksums), and apply consistent labeling and grouping across the project.
renovate-presets · high confidence
Introduce source hydration for GitOps applications
The controller now includes a new \controller/hydrator\ package that implements the core logic for automatically generating and committing manifests for applications configured with a \SourceHydrator\. This change introduces the \Hydrator\ struct and its \Dependencies\ interface, enabling the system to detect source changes, generate manifests via the repo-server, and commit the resulting YAML files to a target repository. The implementation includes queue management for deduplication, status tracking, and integration with the commit server to push hydrated content.
controller/hydrator · high confidence
Introduce standalone GitOps Agent for direct cluster synchronization
A new standalone GitOps Agent is introduced, providing a simple CLI interface to the GitOps Engine. The agent synchronizes a Git repository into the same cluster where it is installed, supporting both namespaced and full cluster modes. Users can deploy the agent via provided Kubernetes manifests (install-namespaced.yaml, install.yaml) or through Kustomize overlays, enabling core GitOps features like reconciliation, syncing, and sync hooks directly from the command line or as a sidecar container.
gitops-engine/agent · high confidence
Introduce standalone argocd-k8s-auth CLI for generating Kubernetes authentication tokens
A new standalone CLI tool, \argocd-k8s-auth\, is introduced to generate authentication tokens for Kubernetes clusters. It provides subcommands for AWS, GCP, and Azure (via kubelogin) to produce the necessary tokens. The AWS implementation includes a retry mechanism for STS requests, while the Azure command supports optional POP (Proof of Possession) tokens for hybrid AKS clusters. The GCP command retrieves default credentials. This change consolidates authentication logic into a dedicated binary, improving modularity and build isolation (e.g., CGO handling for Darwin).
cmd/argocd-k8s-auth · high confidence
Introduces a new gRPC clientset for the repo server with configurable TLS and caching
The \reposerver/apiclient\ package now provides a \Clientset\ interface and implementation for managing connections to the repo server. This new clientset supports configurable TLS settings, including optional mTLS with client certificate caching that automatically reloads certificates when the underlying files change. It also configures gRPC options for message size limits, retry policies, and OpenTelemetry tracing, providing a robust and secure way for the Argo CD controller to communicate with the repo server.
reposerver/apiclient · high confidence
Introduces a reusable interactive prompt utility for CLI confirmations
A new \Prompt\ utility is added to \cmd/argocd/commands/utils\ to standardize user confirmation flows in the CLI. The \prompt.go\ file implements a \Prompt\ struct with methods \Confirm\, \ConfirmAll\, and \ConfirmBaseOnCount\ that wrap the existing \cli.AskToProceed\ and \cli.AskToProceedS\ functions. The utility respects a global \enabled\ flag, allowing prompts to be bypassed when disabled. Corresponding tests in \prompt\_test.go\ verify the behavior of these confirmation methods, including edge cases like disabled prompts and multi-selection ('all') confirmations.
cmd/argocd/commands/utils · high confidence
Introduction of headless mode for in-process API server and local cache forwarding
A new \headless\ package is introduced in \cmd/argocd/commands/headless\, enabling the Argo CD CLI to run an in-process API server when in 'core' mode. This allows the CLI to operate without a separate server process, handling local cache forwarding via port-forwarding to Redis and repo-server components. The implementation includes a \forwardCacheClient\ and \forwardRepoClientset\ to manage these local connections, alongside a \MaybeStartLocalServer\ function to conditionally start the server. Tests verify that the correct Kubernetes context is resolved and applied to the REST config, ensuring the CLI connects to the right cluster and namespace.
cmd/argocd/commands/headless · high confidence
Introduction of the commit server with gRPC client and metrics
The commit server is now exposed via a new gRPC client in the apiclient package, allowing the system to connect to the commit server service. The client configuration now supports a configurable maximum gRPC message size, controlled by the environment variable common.EnvGRPCMaxSizeMB. Additionally, the commit server exposes a Prometheus metrics endpoint that tracks git request counts and durations, as well as commit request metrics, providing observability into the commit server's performance.
commitserver/apiclient · high confidence
Major CLI refactoring and new account management commands
The CLI has been restructured into dedicated command files for each subcommand (e.g., \account.go\, \app.go\), improving code organization. New \argocd account\ commands have been added to manage user accounts, including \update-password\, \get-user-info\ (alias \whoami\), \can-i\ for RBAC checks, \list\, \generate-token\, \get\, \delete-token\, and \session-token\. Additionally, the \argocd app actions\ command allows users to list and run custom resource actions on applications, providing a way to execute custom logic on managed resources.
cmd/argocd/commands · high confidence
New Prometheus metrics for Git and OCI repository server operations
The repository server now exposes detailed Prometheus metrics for Git and OCI operations. For Git, it tracks request counts, durations, and failures for fetch and ls-remote operations, and introduces a configurable parallelism limit via the ARGOCD\_GIT\_LS\_REMOTE\_PARALLELISM\_LIMIT environment variable to control concurrent ls-remote requests. For OCI, it adds metrics for extract, resolve-revision, digest-metadata, get-tags, and test-repo requests, including duration and failure counters. These metrics are available on the repo server's /metrics endpoint.
reposerver/metrics · high confidence
New SCM providers for AWS CodeCommit, Azure DevOps, Bitbucket Cloud, Bitbucket Server, and Gitea
The ApplicationSet controller now supports five new SCM providers for the ApplicationSet SCM generator: AWS CodeCommit, Azure DevOps, Bitbucket Cloud, Bitbucket Server, and Gitea. These providers implement the \SCMProviderService\ interface, enabling users to generate applications from repositories hosted on these platforms. Each provider handles listing repositories, checking for file paths, and retrieving branch information, with corresponding unit tests added to verify their behavior.
_applicationset/services/scm\provider · high confidence
New actions for pausing, resuming, and managing data loss on PipelineRollouts
Users can now pause and unpause Numaplane PipelineRollouts using new 'pause', 'unpause-fast', and 'unpause-gradual' actions, which modify the pipeline's lifecycle phase and resume strategy. Additionally, new 'allow-data-loss' and 'disallow-data-loss' actions allow users to control whether data loss is permitted during rollouts. These changes introduce new UI actions and corresponding Lua scripts that modify the PipelineRollout spec and status conditions.
_resource\customizations/numaplane.numaproj.io/PipelineRollout/actions · high confidence
New cluster metrics collector for Argo CD controller
The controller now exposes a new set of Prometheus metrics about each managed Kubernetes cluster, including connection status, cache age, API resource counts, and cluster labels. These metrics are collected periodically and exposed via the standard /metrics endpoint, allowing users to monitor cluster connectivity and cache health directly from the controller.
controller/metrics · high confidence
New environment variables for tuning cluster cache behavior
The application controller's cache subsystem now exposes several new environment variables to control cache synchronization, retry, and batching behavior. These include ARGOCD\_CLUSTER\_CACHE\_RESyncDURATION, ARGOCD\_CLUSTER\_CACHE\_WATCH\_RESYNCDURATION, ARGOCD\_CLUSTER\_SYNC\_RETRY\_TIMEOUTDURATION, ARGOCD\_CLUSTER\_CACHE\_LIST\_Pagesize, ARGOCD\_CLUSTER\_CACHE\_LISTPAGEBUFSiZE, ARGOCD\_CLUSTER\_CACHE\_LISTSEMPHORE, ARGOCD\_CLUSTER\_CACHEATTEMPTLIMIT, ARGOCD\_CLUSTER\_CACHE\_RETRYUSEBACKOFF, ARGOCD\_CLUSTER\_CACHEBATCHEVENTSPeCESSING, and ARGOCD\_CLUSTER\_CACHEEVENTSPROCESSingINTERVAL. These settings allow operators to adjust how the controller manages cluster state, handles errors, and processes events.
controller/cache · high confidence
New health check implementation for Kubernetes resources
The \gitops-engine/pkg/health\ package has been refactored to provide explicit health assessment functions for a wide range of Kubernetes resources, including Deployments, StatefulSets, DaemonSets, ReplicaSets, Jobs, Pods, Services, Ingresses, PersistentVolumeClaims, HorizontalPodAutoscalers, APIServices, and Argo Workflows. This change introduces a structured \HealthStatus\ and \HealthStatusCode\ system that evaluates the current state of each resource type, enabling more granular and accurate health reporting in the UI and API.
gitops-engine/pkg/health · high confidence
New resource generation utilities and concurrency support
Added new utility files in the resource generator to support concurrent cluster creation and provide helper functions for configuration parsing, Kubernetes client connections, progress tracking, and random string generation. This enables the resource generator to process clusters in parallel, improving generation speed.
hack/gen-resources/util · high confidence
Pulumi Stack health check added
A new health check script for the Pulumi Stack resource has been added, enabling the system to report the status of a stack as Healthy, Progressing, or Degraded based on its conditions. Test data and a corresponding test file have also been added to verify the health check logic.
_resource\customizations/pulumi.com · high confidence
Redesign of HA installation manifests with Kustomize overlays and security hardening
The HA installation manifests have been restructured into a modular Kustomize layout under \manifests/ha/base/\, separating base definitions from overlays. This includes new deployment manifests for the application controller, repo server, and API server, alongside a reorganized Redis HA chart integration that applies security context overlays (e.g., \readOnlyRootFilesystem\, \allowPrivilegeEscalation: false\) and label modifications. The change also introduces network policies for Redis HA components and updates the \argocd-cmd-params-cm\ ConfigMap to include Redis server configuration.
manifests/ha · high confidence
Register Application, AppProject, and ApplicationSet CRDs
The system now registers the core Application, AppProject, and ApplicationSet custom resource definitions (CRDs) with the Kubernetes API server. This enables the platform to manage these resources as first-class citizens, allowing users to create, update, and delete Application, AppProject, and ApplicationSet objects through the CLI or API.
pkg/apis/application · high confidence
Repo server now supports configurable TLS and mTLS with automatic health-check certificate management
The repo server now allows TLS to be configured and made optional, and when mTLS is enabled, the server automatically generates an ephemeral client certificate for its own liveness probe self-connection. This ensures that the health check can succeed even when the server requires client certificates, while still allowing the server to run without TLS if needed. Tests verify that TLS is disabled when explicitly requested, that mTLS enforces client certificate verification, and that the generated health-check certificate is properly registered in the server's ClientCAs pool.
reposerver · high confidence
Restructure and expand the \`argocd admin\` CLI subcommand suite
The \argocd admin\ command has been reorganized into a modular structure with new subcommands for managing applications, clusters, and backups. The \argocd admin app\ command now supports generating declarative configuration specs and comparing reconciliation results. The \argocd admin cluster\ command provides utilities for cluster configuration, stats, and sharding. The \argocd admin export\ and \import\ commands have been enhanced to support exporting and importing applications and application sets from multiple namespaces, with the ability to specify which namespaces to include via flags or configuration. Additionally, the \argocd admin dashboard\ command now supports starting the Argo CD web UI locally with configurable port and address, and handles graceful shutdown on signal. The \argocd admin initial-password\ command allows resetting the initial admin password.
cmd/argocd/commands/admin · high confidence
API
Updated repository service API code generation
The generated Go code for the repository service client and gateway has been regenerated, introducing new query types such as RepoAppsQuery, AppInfo, and RepoAppDetailsQuery. This update reflects changes to the underlying protocol buffer definitions, ensuring the client library remains compatible with the current API contract.
pkg/apiclient/repository · high confidence
Architecture
Refactored repository server codebase into new package structure
The repository server's internal implementation has been reorganized into a new \reposerver/repository\ package. This refactoring introduces dedicated modules for managing repository locks (\lock.go\), parsing Helm chart metadata (\chart.go\), and the core service logic (\repository.go\), along with their corresponding unit tests. This structural change improves code modularity and maintainability within the repo server.
reposerver/repository · high confidence
Behavioural changes
Add custom health checks for KubeVirt resources
Custom health check scripts and test data are added for KubeVirt's DataVolume, VirtualMachine, and VirtualMachineInstance resources. This enables the UI to accurately reflect the operational status of these resources, distinguishing between healthy, degraded, suspended, and progressing states based on their specific conditions and phases.
_resource\_customizations/cdi.kubevirt.io, resource\customizations/kubevirt.io · high confidence
Add health check for GKE ManagedCertificate resources
Users will now see the health status of GKE ManagedCertificate resources in the UI. The system evaluates the certificate status to display 'Healthy' when all certificates are active, 'Degraded' if any certificate fails to be provisioned, or 'Progressing' while certificates are being provisioned.
_resource\customizations/networking.gke.io · high confidence
Add health check for OnePasswordItem resources
Users can now see the health status of OnePasswordItem resources, with the system reporting Healthy, Degraded, or Progressing states based on the resource's Ready condition. This includes the implementation of the health check logic and corresponding test data to validate the different status outcomes.
_resource\customizations/onepassword.com · high confidence
Add health check for SecretStore resources
Users will now see the health status of SecretStore resources in the UI. The system evaluates the 'Ready' condition in the resource's status: if the condition is 'True', the resource is marked as 'Healthy'; if 'False', it is 'Degraded' with the associated error message; otherwise, it is 'Progressing'.
_resource\customizations/external-secrets.io/SecretStore · high confidence
Add health checks for MariaDB resources
The system now evaluates the health of MariaDB custom resources by inspecting their status conditions. A MariaDB is marked as Healthy when all conditions are True, Degraded if any condition is False with reason 'Failed', and Progressing otherwise. This change introduces the Lua script that performs this logic, along with the corresponding test data and test cases to verify the health status mapping.
_resource\customizations/mariadb.mmontes.io · high confidence
Add health status checks for MonoVertexRollout resources
Users will now see accurate health status indicators for MonoVertexRollout resources. The system evaluates the resource's status to determine if it is Healthy, Progressing, Degraded, or Unknown, providing specific messages for each state (e.g., 'Not yet reconciled', 'Update in progress', 'MonoVertex Failed'). This includes support for paused states and progressive upgrade failures.
_resource\customizations/numaplane.numaproj.io/MonoVertexRollout · medium confidence
Add health status checks for PodDisruptionBudget resources
A new health check script has been added for PodDisruptionBudget resources, enabling the system to evaluate their status based on Kubernetes conditions. The logic distinguishes between healthy, progressing, and degraded states, and specifically excludes the 'InsufficientPods' reason from triggering a degraded status, ensuring that this condition does not incorrectly mark the resource as unhealthy.
_resource\customizations/policy · medium confidence
Add health status checks for the Grafana Org Operator
Users can now see the operational health of the Grafana Org Operator resources directly in their dashboard. A new health check script evaluates the 'Ready' condition on the operator's status, reporting 'Healthy' when the instance is reconciled, 'Degraded' if the instance is unreachable or misbehaving, and 'Progressing' while waiting for the status to be established. This is accompanied by test data and test cases to verify these health states.
_resource\customizations/grafana-org-operator.kubitus-project.gitlab.io · high confidence
Add health status mapping for nmstate.io NodeNetworkConfigurationPolicy
Users will now see accurate health statuses for NodeNetworkConfigurationPolicy resources, with the system reporting Healthy, Degraded, Progressing, or Suspended states based on the underlying Kubernetes conditions (Available, Degraded, Progressing, or Ignored).
_resource\customizations/nmstate.io · high confidence
Add health status reporting for Gardener Shoot resources
A new Lua script has been added to define health check logic for Gardener 'Shoot' resources. The script maps the 'shoot.gardener.cloud/status' label to specific health states: 'healthy' maps to 'Healthy', 'progressing' to 'Progressing', 'unhealthy' to 'Degraded', and 'unknown' to 'Unknown'. This change introduces the mechanism for displaying the component state in the UI, supported by corresponding test cases and sample data files.
_resource\customizations/core.gardener.cloud · high confidence
ApplicationSet controller gains cache synchronization and improved spec comparison
The ApplicationSet controller now uses a cache-syncing client wrapper that automatically updates the Kubernetes informer cache after Create, Update, Patch, and Delete operations on Application objects. This prevents stale cache entries from blocking deletion and ensures the controller sees the latest state. Additionally, the controller now uses a dedicated \SpecsEquivalent\ function for comparing Application specs, which applies the same normalization and \ignoreDifferences\ rules as the write path. This ensures that the status path and the write path agree on whether a spec has changed, preventing progressive sync loops when fields are ignored or normalized differently.
applicationset/utils · high confidence
ApplicationSet controller refactored into modular components with enhanced progressive sync support
The ApplicationSet controller logic has been restructured into separate files: the main reconciler is now in applicationset/controllers/applicationset\_controller.go, while progressive sync dependencies are isolated in progressive\_sync\_dependencies.go and clustereventhandler.go handles cluster secret events. This refactoring supports configurable requeue times for different generator types, allows limiting cluster resource whitelists by name, and introduces a cache layer for Argo Projects to speed up application validation. The controller also now preserves specified annotations and labels on generated applications, and implements a configurable maximum for status resources.
applicationset/controllers · medium confidence
ApplicationSet generators refactored to use controller-runtime client
The ApplicationSet generators (Cluster, DuckType, Git, List) have been refactored to use the controller-runtime client instead of the standard Kubernetes client. This change improves consistency with the rest of the codebase and allows for better integration with the controller-runtime framework. The refactoring includes updates to the generator interface and implementation to support the new client type, ensuring that all generators can interact with the Kubernetes API in a more standardized way.
applicationset/generators · high confidence
Argo CD Notifications Controller CLI and configuration updates
The Argo CD Notifications Controller command-line interface has been updated to expose the controller's processor count via the new --processors-count flag (and ARGOCD\_NOTIFICATION\_CONTROLLER\_PROCESSors\_COUNT environment variable), allowing users to tune concurrency. The CLI also now supports configuring TLS settings for the repository server connection, including plaintext mode and strict TLS validation, with the deprecated --argocd-repo-server-strict-tls flag directing users to use --argocd-repo-server-ca-cert-path instead. Additionally, the controller can now be configured to pull notification settings from the resource's namespace for self-service notifications, and the command structure has been simplified by unifying CLI names via common constants.
cmd/argocd-notification · high confidence
ArgoEvents EventBus health checks
The system now evaluates the health of ArgoEvents EventBus resources by inspecting their status conditions. A 'Deployed' condition of 'True' marks the resource as Healthy, while 'False' marks it as Degraded, allowing users to monitor the operational state of their EventBuses directly in the UI.
_resource\customizations/argoproj.io/EventBus · high confidence
CRD generation script refactored to use controller-gen and output YAML
The hack/gen-crd-spec tool has been rewritten to generate Custom Resource Definitions (CRDs) using the controller-gen library, replacing the previous implementation. The script now invokes controller-gen to produce CRD objects, which are then converted to YAML and written to specific paths (e.g., manifests/crds/application-crd.yaml). This change also includes logic to remove specific validation fields (such as creationTimestamp and status) and descriptions from the generated CRDs to address known issues.
hack/gen-crd-spec · high confidence
Fix username claims extraction for RBAC role expansion
The RBAC role has been expanded to allow the creation of application events. Additionally, a bug in the extraction of username claims has been fixed, ensuring that user identity is correctly resolved for authorization checks.
(repo-wide) · high confidence
Generated API client code for settings service moved to pkg/apiclient/settings
The generated Go code for the Argo CD settings service API client has been relocated to the \pkg/apiclient/settings\ package. This change updates the internal structure of the API client, ensuring that the \SettingsService\ and its associated message types (such as \SettingsQuery\ and \Settings\) are now generated and stored in this specific location, which may affect internal imports and build paths for any code depending on the previous location.
pkg/apiclient/settings · high confidence
Generated API client code moved to pkg/apiclient/account
The generated Go code for the account service, including the CanI, UpdatePassword, and ListAccounts endpoints, has been relocated to the pkg/apiclient/account directory. This change updates the internal package structure for the API client, ensuring that the generated protobuf and gRPC gateway stubs are organized under the new path.
pkg/apiclient/account · high confidence
Hide unsupported kubectl REST flags from the Argo CD CLI
The Argo CD CLI now filters out kubectl REST flags that are not supported by the Argo CD command-line interface. Specifically, the following flags are hidden from users: disable-compression, certificate-authority, client-certificate, client-key, as, as-group, as-uid, and tls-server-name. This prevents users from passing these unsupported flags, which previously caused errors or unexpected behavior when using the CLI in headless mode.
cmd/argocd/commands/initialize · high confidence
Improved reliability and security in Git, Helm, and OIDC utilities
The util package received numerous fixes and enhancements that improve reliability and security. Git operations now include better error handling for 'git ls-remote' failures and branch checkout states, while Helm commands are hardened against path traversal attacks and include improved error messages for registry authentication. OIDC and authentication utilities now enforce the 'aud' claim by default and handle token expiration and refresh more robustly. Additionally, Redis cache usage is optimized with gzip compression and reduced traffic, and various race conditions and memory leaks in the controller and repo-server utilities are resolved.
util · medium confidence
Migrate resource customizations to Go embed
The resource\_customizations package now uses Go's built-in embed directive to include all files in the directory, replacing the previous method of bundling these resources. This change simplifies the build process by removing the need for external packing tools.
_resource\customizations · high confidence
OpenFaaS Function health status monitoring
Added health status evaluation for OpenFaaS Function resources. The system now inspects the Function's status conditions to report a 'Healthy' state when the deployment is reconciled and has available replicas, 'Degraded' if conditions indicate a stall or missing secrets, 'Suspended' if no replicas are available, and 'Progressing' while the function is being created.
_resource\customizations/openfaas.com · high confidence
Optimized application list API to reduce memory and CPU usage
The application list API now streams JSON responses directly to the HTTP writer instead of buffering the entire list in memory. This change significantly reduces memory consumption and CPU usage when listing applications, addressing a reported performance issue where the application list page consumed too much CPU. The implementation uses a streaming encoder to process applications one by one, and includes tests to verify the new behavior.
pkg/apiclient/application · high confidence
Refactored repo-server cache implementation
The cache implementation in the reposerver has been refactored, introducing a new \Cache\ struct and associated test suite. This change updates the internal mechanics of how the repo-server caches repository metadata, application details, and manifest generation results, likely to improve reliability or performance, though the external interface remains consistent.
reposerver/cache · high confidence
Regenerate API client code for project and session services
The generated Go code for the project and session API clients has been regenerated. This update includes the new \forwarder\_overwrite.go\ file which configures HTTP forwarding for the project service, and updates to \project.pb.go\ and \project.pb.gw.go\ to reflect the current protobuf definitions, ensuring the client-side stubs and gRPC-Gateway handlers are synchronized with the server-side API contracts.
pkg/apiclient/project · medium confidence
Regenerate cluster API client code for v3
The generated Go code for the cluster API client has been regenerated, introducing a new \ClusterID\ message type that supports identifying clusters by name in addition to the API server URL. This change updates the \ClusterQuery\ message to include an \id\ field of the new \ClusterID\ type, allowing the API client to query clusters using either their server URL or their assigned name.
pkg/apiclient/cluster · high confidence
Regenerated SessionServiceClient and SessionServiceServer mocks
The mock implementations for SessionServiceClient and SessionServiceServer in pkg/apiclient/session/mocks have been regenerated using the testify template. This update aligns the generated code with the current interface definitions, ensuring that test suites using these mocks can properly simulate gRPC session service interactions.
pkg/apiclient/session/mocks · high confidence
Regenerated cluster API client and server mocks
The mock implementations for the cluster service client and server in the API client package have been regenerated using the updated mockery code generation tooling. This update ensures the test doubles align with the current interface definitions, incorporating the latest method signatures and parameter types for cluster operations.
pkg/apiclient/cluster/mocks · high confidence
Removal of global error-checking utility
The \errors\ package containing the \CheckError\ convenience function has been removed from the codebase. This function previously provided a global mechanism to log and terminate the application on any non-nil error, and its removal indicates a shift away from this specific error-handling pattern.
errors · high confidence
Removal of legacy ArgoCD server and version service implementations
The legacy ArgoCD server implementation, including the HTTP 1.1+JSON and gRPC serving logic in \argocd/server/server.go\, has been removed. Additionally, the \argocd/version\ package containing the \VersionService\ implementation and its associated protobuf-generated code (\version.pb.go\) have been deleted. This change eliminates the previous method of serving the version API via both gRPC and HTTP/JSON on the same port in insecure mode, indicating a shift in how the API server is structured or which components are responsible for these endpoints.
argocd · medium confidence
Removed main.go entry point for argocd command
The main.go entry point for the argocd command has been removed from the codebase. This change eliminates the previous Go file that initialized and executed the CLI commands, likely as part of a larger refactoring or build system consolidation.
cmd/argocd · high confidence
Support GitHub App authentication without a pre-configured installation ID
The GitHub App client now automatically discovers the GitHub App's installation ID when one is not explicitly provided. Previously, the client required an explicit installation ID to function; the new logic uses a shared utility to discover the ID dynamically, enabling authentication for GitHub App setups where the installation ID was previously unknown or required manual configuration.
_applicationset/services/internal/github\app · high confidence
Unify CLI entry point to support plugin execution and multiple subcommands
The main entry point for the Argo CD binary has been consolidated into a single dispatcher that routes execution to specific subcommands (such as the CLI, CMP server, and others) based on the binary's name or environment variable. This change enables the CLI to handle plugin execution errors gracefully and ensures that all subcommands are routed through a unified command structure, improving how the CLI interacts with external plugins and internal server components.
cmd · medium confidence
Updated ApplicationServiceClient mock to use typed Argo CD EventList for event-listing APIs
The mock for ApplicationServiceClient has been regenerated to reflect the switch to a typed Argo CD EventList for event-listing APIs. This update ensures that tests using this mock correctly handle the new return types and request structures associated with the event-listing endpoints.
pkg/apiclient/application/mocks · medium confidence
Updated Kiali health check logic
The custom health check for the Kiali resource has been updated to more accurately reflect the resource's status by evaluating specific conditions in the Kiali status. The new logic maps 'Successful' conditions to a 'Healthy' state, 'Failure' conditions to 'Degraded', and 'Running' conditions to 'Progressing'. Test cases have been added to verify these states.
_resource\customizations/kiali.io · medium confidence
Updated ProjectServiceClient mock to match current API signatures
The mock for ProjectServiceClient in the apiclient package has been regenerated to align with the latest interface definitions. This update ensures that test suites using these mocks can correctly simulate gRPC calls for project management operations, such as Create and CreateToken, reflecting the current state of the API client contract.
pkg/apiclient/project/mocks · medium confidence
Updated mock generation for repo server API clients
The mock implementations for the repository server's API client interfaces have been regenerated using the latest version of the mockery code generation tool. This update ensures that the test doubles for \RepoServerServiceClient\ and related streaming client interfaces accurately reflect the current gRPC service definitions, providing developers with up-to-date scaffolding for unit testing components that interact with the repository server.
reposerver/apiclient/mocks · high confidence
Updated mock implementations for AWS and Azure DevOps clients
The mock files for AWS CodeCommit, AWS Tagging, and Azure DevOps clients have been regenerated using the \testify\ template from the \vektra/mockery\ tool. This update aligns the generated mocks with the current \aws-sdk-go-v2\ API signatures and incorporates the \Expecter\ struct pattern from \mockery\ v3.7.1, ensuring that test code can more accurately simulate client behavior for SCM provider services.
_applicationset/services/scm\provider/mocks · high confidence
Updated mock implementations for Generator and Renderer
The autogenerated mock files for the Generator and Renderer interfaces have been regenerated using the updated mockery codegen tool. This update ensures that the test doubles in applicationset/generators/mocks and applicationset/utils/mocks remain compatible with the current test framework and interface definitions, resolving deprecation warnings and aligning with the project's v3 module structure.
applicationset/generators/mocks, applicationset/utils/mocks · high confidence
Version API endpoint and client moved to new package location
The generated Go code for the version service has been moved from the \argocd/version\ package to \pkg/apiclient/version\. This change updates the import paths and internal references for clients and reverse-proxy handlers, ensuring the version information endpoint is correctly located within the shared \pkg/apiclient\ module.
pkg/apiclient/version · high confidence
Fixes
Add health check for CustomResourceDefinitions
A new Lua-based health check for CustomResourceDefinitions (CRDs) has been introduced, providing accurate status reporting for CRD lifecycle states. The implementation distinguishes between 'Healthy', 'Degraded' (for issues like unaccepted names, schema violations, or lack of establishment), and 'Progressing' (for installing, terminating, or missing conditions). This ensures users see correct health statuses during CRD installation and deletion, rather than incorrect degradation signals.
_resource\customizations/apiextensions.k8s.io · high confidence
Add health status checks for ConfigConnector and ConfigConnectorContext resources
A new Lua script and associated test data have been added to define health status for ConfigConnector and ConfigConnectorContext resources. The script evaluates the health of these resources by checking the 'status.healthy' field and 'observedGeneration' to determine if the resource is Healthy, Degraded, Suspended, or Progressing. This ensures that the health status correctly reflects the state of ConfigConnector and ConfigConnectorContext resources, addressing previous issues where health checks did not properly utilize the observedGeneration.
_resource\customizations/\.cnrm.cloud.google.com · medium confidence_
Customizes Table of Contents title in English
Adds a new override file for the English language that customizes the 'Table of Contents' label, ensuring the correct capitalization in the table of contents title.
overrides · high confidence
Fix ApplicationSet progressive sync termination and status reporting bugs
Resolves several issues in the ApplicationSet progressive sync logic. The reverse deletion process now correctly handles 'phantom' applications that have been deleted from the API server but remain in the informer cache, preventing the ApplicationSet from getting stuck in a Terminating state. It also ensures that genuinely slow-terminating children are not skipped, and that missing API readers are handled gracefully. Additionally, the status reporting for spec changes now correctly ignores fields managed by the controller (like \automated.enabled\) and respects \ignoreApplicationDifferences\ rules, preventing false-positive 'spec changed' states that could cause infinite reconciliation loops.
applicationset/progressivesync · high confidence
Fix Go embed and CI build issues with gitkeep files
The ui/dist/app directory now contains a non-hidden 'gitkeep' file, which is required for Go's embed directive to function correctly during backend-only CI jobs. The previous hidden '.gitkeep' file was ignored by Go's embed, causing compilation failures. Additionally, a '.gitkeep' file has been added to the images directory to ensure proper directory tracking.
ui/dist · high confidence
Fix cluster cache panic on failed resource listing
The cache now handles Kubernetes API list failures gracefully by returning an empty list instead of nil, preventing a panic when the client returns (nil, error). This fix ensures that the cache initialization and synchronization remain stable even when the API server returns errors during resource listing, improving reliability for cluster state observation.
gitops-engine/pkg/cache · high confidence
Fixes for UI crashes, layout issues, and broken filters
This update resolves numerous stability and usability issues within the Argo CD UI. It addresses multiple crashes caused by undefined values in the application list, pod view, and resource tree. Several filter components have been repaired, including the cluster filter, orphaned resource filter, and application status filters. Layout and styling fixes correct overlapping elements, text truncation, and incorrect positioning of tooltips and icons. Additionally, the pod logs viewer and resource details panels have been hardened against edge cases that previously caused rendering errors.
ui · high confidence
Improved server-side diff accuracy and stability
The diff engine now more accurately reflects the state of resources by correcting several issues in server-side and structured merge diff calculations. Users will see fewer false-positive differences caused by webhook mutations, duplicate container ports, and the presence of transient fields like creationTimestamp and resourceVersion. Additionally, sensitive data in Secrets and ConfigMaps is now properly hidden in the diff output, and the engine is more resilient against nil pointer errors.
gitops-engine/pkg/diff · medium confidence
Introduce thread-safe ID generation for controllers
Added a new \controller/syncid\ package that provides a thread-safe method for generating unique controller IDs. The implementation uses an atomic counter combined with a random suffix to ensure uniqueness across concurrent goroutines, addressing a race condition in ID generation. A corresponding test suite verifies that concurrent calls to the generator produce unique, correctly formatted IDs without data races.
controller/syncid · high confidence
Test coverage
Added ClusterCache mock for testing; Added Gitea API response data for tests; Added RBAC test data for admin commands; Added mock cache implementation for testing; Added mock implementations for commit server API clients; Added mock implementations for hydrator dependencies; Added test data fixtures for controller diff and health check scenarios; Added test fixtures for CLI plugin and configuration scenarios; Generated mock for RepoClientFactory; New e2e test fixture for application tests; Regenerated LiveStateCache mock for updated interface; Updated Azure DevOps Git client mock to support new Git operations; Updated GPG key service mock for testing; Updated Repos mock to support source integrity checks; Updated test container base images and Go toolchain.
Dependencies
Updated dependencies across 9 manifests
This update refreshes the project's dependency tree, including Go modules, Node.js packages, and documentation tools. Key updates include bumping golang.org/x/net, golang.org/x/crypto, and golang.org/x/oauth2 to address security vulnerabilities and improve stability. The gitops-engine dependency is upgraded to pull in performance improvements and bug fixes. Additionally, the notification engine and various AWS SDK libraries have been updated to their latest compatible versions.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 57.
Lenses
- Code Health 63
- Architecture 100
- Maturity 76
- Readiness 86
- Security 61
- Accessibility 45
Changes since last survey
- 300 commits — 201 feature/other, 99 fixes
By area
- .github/workflows — 63 commits
- (root) — 52 commits
- ui/src — 26 commits
- ui/package.json — 13 commits
- gitops-engine/pkg — 12 commits
- cmd/argocd — 8 commits
- docs/operator-manual — 8 commits
- test/e2e — 8 commits
- controller/appcontroller.go — 7 commits
- reposerver/repository — 7 commits
- hack/installers — 6 commits
- applicationset/progressivesync — 5 commits
- docs/snyk — 5 commits
- manifests/ha — 5 commits
- test/container — 5 commits
- (repo) — 3 commits
- docs/developer-guide — 3 commits
- docs/proposals — 3 commits
- docs/requirements.txt — 3 commits
- resource_customizations/numaflow.numaproj.io — 3 commits
Notable commits
- fix: Merge branch 'master' into react-compiler-rules-of-react-fixes
- fix: Merge pull request #28417 from jwinters01/react-compiler-rules-of-react-fixes
- fix: Merge remote-tracking branch 'origin/master' into react-compiler-rules-of-react-fixes
- fix: chore(ci): fix Renovate PR attribution (#28428)
- fix: chore(ui): fix Rules-of-React violations for React Compiler readiness
- fix: chore(ui): fix additional Rules-of-React violations
- fix: chore(ui): fix lint errors surfaced by React Compiler ruleset
- fix: chore: fix broken test (#29057)
- fix: ci(renovate): fix - make renovate update itself correctly, fix network failures (#28985)
- fix: fix(UI): display sync option dropdowns on separate lines (#28438)
- fix: fix(appset): don't release finalizer while children still terminate (#28999)
- fix: fix(appset): fall back to create when patch returns NotFound (#17312) (#28645)
- fix: fix(appset): stop progressive sync reconciling in a tight loop (#27577) (#29044)
- fix: fix(appset): throw error when generated apps have empty name (#28833)
- fix: fix(appset): verify terminating Applications against the API server (#29042) (#29043)
- fix: fix(chore): bump argo-ui for React 19 toast compatibility (#28874)
- fix: fix(ci): exclude generated workflow from dependabot (#28774)
- fix: fix(ci): expand image tag in staging deploy commit message (#28773)
- fix: fix(ci): explicitly check out base repo and default branch for cherry-pick job (#28413)
- fix: fix(ci): fix CI breakage: remove dependabot's changes to an agentic workflow compiled file (#28772)
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
argoproj/argo-cd was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 6 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit cb99c80a553aa3eb25b38a8216ddac0b16aa3013 — the exact code this score is about.
- Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer latest.