Explicitly own the keel.sh/policy annotation in TF (was relying on the Kyverno-stamped `patch` default). Set policy=all + trigger=poll + pollSchedule, expand ignore_changes per KEEL_LIFECYCLE_V1 to cover Keel-written runtime annotations (change-cause, update-time, revision, match-tag). |
||
|---|---|---|
| .. | ||
| main.tf | ||
| providers.tf | ||
| secrets | ||
| terragrunt.hcl | ||