raflyalk opened a new issue, #6861:
URL: https://github.com/apache/camel-k/issues/6861
### Requirement
## Description
When Camel K generates a `CamelCatalog` from an `IntegrationPlatform`, it
propagates the annotations and labels from the `IntegrationPlatform` to the
generated `CamelCatalog`.
This is problematic for annotations intended only for the
`IntegrationPlatform`, especially GitOps/controller tracking annotations such
as Argo CD resource-tracking metadata.
For example, when an `IntegrationPlatform` is managed by Argo CD, its
tracking annotation is copied to the generated `CamelCatalog`. Argo CD then
sees the generated catalog as belonging to the application, despite it not
being defined in Git. This can cause the Application to remain `OutOfSync`
and/or ask to prune the `CamelCatalog`.
## Environment
- Camel K version: `2.10.1`
- GitOps controller: Argo CD 3.4.4
- Argo CD resource tracking: annotation-based
## Current behavior
Given an `IntegrationPlatform` such as:
```yaml
apiVersion: camel.apache.org/v1
kind: IntegrationPlatform
metadata:
name: camel-k
namespace: camel-k
annotations:
argocd.argoproj.io/tracking-id:
my-app:camel.apache.org/IntegrationPlatform:camel-k/camel-k
```
Camel K creates a `CamelCatalog` and copies the annotation:
```yaml
apiVersion: camel.apache.org/v1
kind: CamelCatalog
metadata:
annotations:
argocd.argoproj.io/tracking-id:
my-app:camel.apache.org/IntegrationPlatform:camel-k/camel-k
```
The `CamelCatalog` is operator-generated and not present in the Git
repository, but it becomes associated with the Argo CD Application because of
the inherited annotation.
## Expected behavior
There should be a way to control which annotations and labels are propagated
from `IntegrationPlatform` to generated resources, particularly `CamelCatalog`.
At minimum, users should be able to exclude specific annotations/labels from
propagation.
## Proposed solution
Add optional include/exclude filters to IntegrationPlatform, for example:
```yaml
apiVersion: camel.apache.org/v1
kind: IntegrationPlatform
metadata:
name: camel-k
spec:
generatedResourceMetadata:
annotations:
exclude:
- argocd.argoproj.io/tracking-id
- argocd.argoproj.io/*
labels:
exclude:
- argocd.argoproj.io/*
```
Alternatively, a simpler mechanism could be:
```yaml
spec:
camelCatalog:
metadata:
propagateAnnotations: false
propagateLabels: false
```
Or support explicit metadata for the generated `CamelCatalog`:
```yaml
spec:
camelCatalog:
metadata:
annotations:
argocd.argoproj.io/compare-options: IgnoreExtraneous
```
## Why this is needed
Annotations and labels are frequently used by external controllers and
tools, including:
- Argo CD resource tracking
- Flux ownership/tracking
- policy engines
- backup tools
- observability agents
- cost allocation and inventory systems
Blindly copying all metadata from a parent resource to an operator-generated
child can unintentionally make the child managed by another controller or
trigger undesired automation.
A configurable allowlist/denylist would preserve the current default
behavior while allowing GitOps users to prevent ownership/tracking annotations
from leaking into generated resources.
## Workarounds
Current workarounds are not ideal:
1. Globally exclude `CamelCatalog` from Argo CD resource discovery.
- This affects all `CamelCatalog` resources and prevents declarative
management if needed later.
2. Add Argo CD ignore/prune annotations to the `IntegrationPlatform`.
- Those annotations are also applied to the `IntegrationPlatform`, where
they may not be desired.
3. Use an admission webhook/policy engine to mutate generated `CamelCatalog`
resources.
- This adds operational complexity for a behavior that could be handled
by Camel K directly.
## Request
Could Camel K provide a supported configuration option to include or exclude
selected annotations and labels when creating/generated `CamelCatalog`
resources from an `IntegrationPlatform`?
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]