The Tyk Helm charts bootstrap a deployment with Helm hooks: a pre-install job prepares credentials, a post-install job creates the initial Organisation and users, and a pre-delete job cleans up on uninstall. Argo CD does not run these hooks through Helm’s lifecycle. It applies hook resources at the wrong point, skips them, or recreates them on every sync. The worst case is the pre-delete job, which runs its cleanup at sync time and deletes the Tyk Operator secret.
This page shows how to configure the charts so that your GitOps tool, not Helm, owns bootstrap ordering.
Configure The Charts For GitOps
Available from Tyk Helm Chart v5.4.0. SetdisableHelmHooks on the bootstrap chart, then place the bootstrap resources in sync waves:
disableHelmHooks: trueremoves everyhelm.sh/hookannotation from the bootstrap jobs and their RBAC resources. The jobs become ordinary resources that your GitOps tool applies and orders.rbacAnnotationsmust place the RBAC resources in an earlier wave than the jobs that use them.backoffLimitdefaults to1for each job. Set it to0to make a sync fail on the first error.- Quote sync-wave values. Kubernetes requires annotation values to be strings, and an unquoted
-1in YAML is an integer.
Private Registries
Available from Tyk Helm Chart v5.3.0. The bootstrap jobs pull their images with secrets attached to the bootstrap ServiceAccount. The rendered job manifests do not contain animagePullSecrets field, which is expected.
imagePullSecrets covers both the portal pod and its bootstrap job. Set bootstrapJob.image to mirror the job’s curl image into your registry:
securityContext and containerSecurityContext. On clusters that assign their own UIDs and GIDs, see Deploy Tyk on OpenShift.
Complete Argo CD Example
ThePrune=false annotation keeps Argo CD from pruning and recreating the completed bootstrap jobs. See Upgrade And Re-Run Safety.
Upgrade And Re-Run Safety
With hooks disabled, the bootstrap jobs are ordinary release resources. Two problems follow. A Job’s pod template is immutable. Any change to it, including an image tag bump, makeshelm upgrade fail:
helm.sh/resource-policy: keep and helm upgrade --force do not avoid this.
The post-install job is not idempotent. A second run deletes and recreates the Tyk Operator and Tyk Developer Portal secrets with empty TYK_AUTH and TYK_ORG values, so Tyk Operator can no longer authenticate against Tyk Dashboard. The job still reports Success, so your GitOps tool shows no problem. A second run happens when your GitOps tool prunes and recreates completed jobs, when you delete the jobs to clear the upgrade error, or when a sync recreates a job because its pod template changed. This is a limitation of the tyk-k8s-bootstrap image v2.2.0 and v2.2.1, and chart values cannot avoid it.
Upgrade A Bootstrapped Deployment
-
Back up the Tyk Operator secret:
-
Set
global.components.bootstrap: falsein your values. This suppresses the post-install and pre-delete jobs. It does not suppress the pre-install job, or the bootstrap ServiceAccount, Role and RoleBinding. -
Delete the pre-install job, then upgrade: