Deploy
Deploy from the ACM hub.
Requirements
Review Requirements before applying the Argo CD application.
Label a target managed cluster:
oc label managedcluster <cluster-name> spo=true --overwrite
Apply the Argo CD Application
oc apply -f apps/hub/argocd-application.yaml
The application is created in:
openshift-gitops/spo-acm-policies-test
It syncs this repository:
https://github.com/turbra/acm-foil.git
Synced Hub Resources
Argo CD syncs the ACM hub resources from policies/overlays/test-spo-cluster-scoped:
Namespace/acm-spo-policies
ManagedClusterSetBinding/default
Placement/placement-spo-test
PlacementBinding/binding-policyset-blastwall-test
PlacementBinding/binding-policyset-spo-test
PolicySet/policyset-blastwall-test
PolicySet/policyset-spo-test
Policy/policy-install-spo-operator
Policy/policy-spo-rawselinuxprofile-crd
Policy/policy-blastwall-v2-raw-profiles
Policy/policy-blastwall-v2-profile-usage
Policy/policy-blastwall-v2-runtime-bindings
Policy/policy-prevent-copy-fail-cve-ds
The Argo CD application keeps automated sync, pruning, and self-healing enabled so the hub state returns to the Git-defined policy set after manual drift.
Expected Result
Argo CD should report:
Synced / Healthy
The ACM policies should report:
Compliant
If Argo CD reports Degraded, check Troubleshooting before changing policy content.