You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在OpenShift/ArgoCD中排除ConfigMap内容同步

OpenShift证书注入ConfigMap导致ArgoCD不同步的解决方法

问题场景

在ArgoCD中部署的应用包含一个用于OpenShift证书注入的ConfigMap,清单定义如下:

apiVersion: v1
data: {}
kind: ConfigMap
metadata:
  labels:
    config.openshift.io/inject-trusted-cabundle: "true"
  name: ca-inject 
  namespace: apache

该ConfigMap的data字段为空,通过config.openshift.io/inject-trusted-cabundle: "true"标签,OpenShift会自动向其填充预定义的CA证书集合,实际集群中的ConfigMap内容如下:

$ oc get ca-inject -o yaml

apiVersion: v1
kind: ConfigMap
metadata:
  labels:
    config.openshift.io/inject-trusted-cabundle: "true"
  name: ca-inject 
  namespace: apache
data: 
  ca-bundle.crt: "-----BEGIN CERTIFICATE-----
 etc." 

这一自动填充行为导致该ConfigMap在ArgoCD中始终无法处于“同步”状态,因为ArgoCD检测到实际清单与期望清单的data.ca-bundle.crt字段存在差异。

尝试通过Application的ignoreDifferences配置排除该字段,但未生效,原配置如下:

apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: test-app-cm
  namespace: openshift-gitops
spec:
  destination:
    namespace: test-app-cm
    server: [redacted]
  ignoreDifferences:
  - group: core
    kind: ConfigMap
    managedFieldsManagers:
    - ca-bundle.crt
  project: test-app-cm
  source:
    path: .
    repoURL: [redacted]
    targetRevision: main
  syncPolicy:
    automated:
      prune: true
      selfHeal: true
    syncOptions:
    - CreateNamespace=false
    - Prune=true
    - RespectIgnoreDifferences=true

解决方案

修正后的ignoreDifferences配置

原配置错误使用了managedFieldsManagers,正确做法是通过jsonPointers指定要忽略的字段路径,同时注意Core组的group字段为空字符串。修正后的Application配置如下:

apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: test-app-cm
  namespace: openshift-gitops
spec:
  destination:
    namespace: test-app-cm
    server: [redacted]
  ignoreDifferences:
  - group: ""
    kind: ConfigMap
    name: ca-inject
    jsonPointers:
    - /data/ca-bundle.crt
  project: test-app-cm
  source:
    path: .
    repoURL: [redacted]
    targetRevision: main
  syncPolicy:
    automated:
      prune: true
      selfHeal: true
    syncOptions:
    - CreateNamespace=false
    - Prune=true
    - RespectIgnoreDifferences=true

关键配置说明

  • group: "":Kubernetes Core API组的group字段为空,不能填写core
  • name: ca-inject:指定具体要忽略差异的ConfigMap名称,避免影响同命名空间内其他ConfigMap
  • jsonPointers: - /data/ca-bundle.crt:明确指定忽略的字段路径,ArgoCD会跳过该字段的差异校验

内容的提问来源于stack exchange,提问作者El_Muntagnin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 18:15:13