Skip to main content

Deploy

Deploy from the ACM hub.

Requirements​

Review Requirements before applying the Argo CD application.

Label a target managed cluster:

oc label managedcluster <cluster-name> spo=true --overwrite

Apply the Argo CD Application​

oc apply -f apps/hub/argocd-application.yaml

The application is created in:

openshift-gitops/spo-acm-policies-test

It syncs this repository:

https://github.com/turbra/acm-foil.git

Synced Hub Resources​

Argo CD syncs the ACM hub resources from policies/overlays/test-spo-cluster-scoped:

Namespace/acm-spo-policies
ManagedClusterSetBinding/default
Placement/placement-spo-test
PlacementBinding/binding-policyset-blastwall-test
PlacementBinding/binding-policyset-spo-test
PolicySet/policyset-blastwall-test
PolicySet/policyset-spo-test
Policy/policy-install-spo-operator
Policy/policy-spo-rawselinuxprofile-crd
Policy/policy-blastwall-v2-raw-profiles
Policy/policy-blastwall-v2-profile-usage
Policy/policy-blastwall-v2-runtime-bindings
Policy/policy-prevent-copy-fail-cve-ds

The Argo CD application keeps automated sync, pruning, and self-healing enabled so the hub state returns to the Git-defined policy set after manual drift.

Expected Result​

Argo CD should report:

Synced / Healthy

The ACM policies should report:

Compliant

If Argo CD reports Degraded, check Troubleshooting before changing policy content.