GitOps and RHACM¶
Use two phases. Do not apply the 3scale operator and in-cluster databases at the same time on an empty cluster. APIManager 2.15 must create embedded PostgreSQL and Redis first. Resources in 3scale-db enter during the externalization window.
Replace placeholders before sync:
REPLACE_REPO_URLin ApplicationSets undergitops/andgitops/rhacm/REPLACE_WILDCARD_DOMAINinkustomize/overlays/lab-apimanager/kustomization.yamlREPLACE_EFS_FILESYSTEM_IDinkustomize/overlays/lab-efs/kustomization.yaml
Before the APIManager, you need an RWX StorageClass. On AWS lab: create the EFS filesystem, set fileSystemId in kustomize/overlays/lab-efs, and apply that overlay (cluster-scoped; it is not in the ApplicationSet).
Phase 1 — 3scale operator 2.15 + APIManager¶
oc apply -k gitops/
| Wave | Application | Path |
|---|---|---|
| 0 | threescale-operator |
kustomize/overlays/lab-operator |
| 5 | threescale-apimanager |
kustomize/overlays/lab-apimanager |
Destination: namespace 3scale. SkipDryRunOnMissingResource covers the APIManager CRD until the CSV is ready.
Phase 2 — PostgreSQL 15 + Redis 7 (after dump)¶
Create secret system-database in 3scale-db first (DB_USER, DB_PASSWORD). Template: kustomize/bases/postgresql/secret.example.yaml.
oc apply -k gitops/external-db
| Wave | Application | Path |
|---|---|---|
| 0 | threescale-ext-namespace |
kustomize/bases/namespace |
| 1 | threescale-ext-postgresql |
kustomize/bases/postgresql |
| 1 | threescale-ext-redis-config |
kustomize/bases/redis-config-restore |
| 2 | threescale-ext-redis-backend |
kustomize/bases/redis-backend |
| 2 | threescale-ext-redis-system |
kustomize/bases/redis-system |
Destination: 3scale-db. prune: false avoids deleting PVCs.
After Redis restore, change redis-config.path to kustomize/bases/redis-config-persist in the external-db ApplicationSet. Leave it there on day 2. selfHeal: true reverts a manual ConfigMap edit. See Day 2 operations.
GitOps pitfalls¶
Three common cutover mistakes
| Risk | What to do |
|---|---|
ApplicationSet still lists redis-config-restore |
Change the path to redis-config-persist after cutover. selfHeal: true reverts a manual ConfigMap edit and a restart drops Redis data. |
prune: true on external-db Applications |
Keep prune: false so a sync cannot delete PVCs. |
| Mixing in-cluster GitOps and RHACM | Use one controller per destination cluster. |
Full steady-state checklist: Day 2 operations. Rollback paths: Rollback.
RHACM (hub)¶
Same separation:
oc apply -k gitops/rhacm/ # Placement + 3scale operator PUSH
oc apply -k gitops/rhacm/external-db # prod overlay → 3scale-db on managed cluster
Do not mix controllers
Do not use in-cluster GitOps (gitops/) and RHACM against the same destination cluster.
Fallback without Argo CD¶
oc apply -k kustomize/overlays/lab-operator
oc apply -k kustomize/overlays/lab-efs
oc apply -k kustomize/overlays/lab-apimanager
# later:
oc apply -k kustomize/overlays/lab