raflyalk opened a new issue, #6861:
URL: https://github.com/apache/camel-k/issues/6861

   ### Requirement
   
   ## Description
   
   When Camel K generates a `CamelCatalog` from an `IntegrationPlatform`, it 
propagates the annotations and labels from the `IntegrationPlatform` to the 
generated `CamelCatalog`.
   
   This is problematic for annotations intended only for the 
`IntegrationPlatform`, especially GitOps/controller tracking annotations such 
as Argo CD resource-tracking metadata.
   
   For example, when an `IntegrationPlatform` is managed by Argo CD, its 
tracking annotation is copied to the generated `CamelCatalog`. Argo CD then 
sees the generated catalog as belonging to the application, despite it not 
being defined in Git. This can cause the Application to remain `OutOfSync` 
and/or ask to prune the `CamelCatalog`.
   
   ## Environment
   
   - Camel K version: `2.10.1`
   - GitOps controller: Argo CD 3.4.4
   - Argo CD resource tracking: annotation-based
   
   ## Current behavior
   
   Given an `IntegrationPlatform` such as:
   
   ```yaml
   apiVersion: camel.apache.org/v1
   kind: IntegrationPlatform
   metadata:
     name: camel-k
     namespace: camel-k
     annotations:
       argocd.argoproj.io/tracking-id: 
my-app:camel.apache.org/IntegrationPlatform:camel-k/camel-k
   ```
   
   Camel K creates a `CamelCatalog` and copies the annotation:
   ```yaml
   apiVersion: camel.apache.org/v1
   kind: CamelCatalog
   metadata:
     annotations:
       argocd.argoproj.io/tracking-id: 
my-app:camel.apache.org/IntegrationPlatform:camel-k/camel-k
   ```
   
   The `CamelCatalog` is operator-generated and not present in the Git 
repository, but it becomes associated with the Argo CD Application because of 
the inherited annotation.
   
   ## Expected behavior
   There should be a way to control which annotations and labels are propagated 
from `IntegrationPlatform` to generated resources, particularly `CamelCatalog`.
   
   At minimum, users should be able to exclude specific annotations/labels from 
propagation.
   
   ## Proposed solution
   Add optional include/exclude filters to IntegrationPlatform, for example:
   ```yaml
   apiVersion: camel.apache.org/v1
   kind: IntegrationPlatform
   metadata:
     name: camel-k
   spec:
     generatedResourceMetadata:
       annotations:
         exclude:
           - argocd.argoproj.io/tracking-id
           - argocd.argoproj.io/*
       labels:
         exclude:
           - argocd.argoproj.io/*
   ```
   Alternatively, a simpler mechanism could be:
   
   ```yaml
   spec:
     camelCatalog:
       metadata:
         propagateAnnotations: false
         propagateLabels: false
   ```
   
   Or support explicit metadata for the generated `CamelCatalog`:
   
   ```yaml
   spec:
     camelCatalog:
       metadata:
         annotations:
           argocd.argoproj.io/compare-options: IgnoreExtraneous
   ```
   
   ## Why this is needed
   
   Annotations and labels are frequently used by external controllers and 
tools, including:
   
   - Argo CD resource tracking
   - Flux ownership/tracking
   - policy engines
   - backup tools
   - observability agents
   - cost allocation and inventory systems
   
   Blindly copying all metadata from a parent resource to an operator-generated 
child can unintentionally make the child managed by another controller or 
trigger undesired automation.
   
   A configurable allowlist/denylist would preserve the current default 
behavior while allowing GitOps users to prevent ownership/tracking annotations 
from leaking into generated resources.
   
   ## Workarounds
   
   Current workarounds are not ideal:
   
   1. Globally exclude `CamelCatalog` from Argo CD resource discovery.
      - This affects all `CamelCatalog` resources and prevents declarative 
management if needed later.
   
   2. Add Argo CD ignore/prune annotations to the `IntegrationPlatform`.
      - Those annotations are also applied to the `IntegrationPlatform`, where 
they may not be desired.
   
   3. Use an admission webhook/policy engine to mutate generated `CamelCatalog` 
resources.
      - This adds operational complexity for a behavior that could be handled 
by Camel K directly.
   
   ## Request
   
   Could Camel K provide a supported configuration option to include or exclude 
selected annotations and labels when creating/generated `CamelCatalog` 
resources from an `IntegrationPlatform`?


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to