You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法为ArgoCD用户设置新密码的问题求助与解决方案咨询

问题解决:ArgoCD CLI更新用户密码报错"unable to extract token claims"

问题根源

你使用--core参数登录ArgoCD CLI时进入了离线模式——该模式直接操作本地Kubernetes资源,不会与ArgoCD API Server建立连接。而更新用户密码需要与服务器交互验证权限、同步配置,离线模式下没有有效的服务器token,因此触发报错。

解决方案1:通过在线CLI模式更新密码

  1. 重新登录ArgoCD,去掉--core参数,建立与服务器的正常连接:
argocd login argocd.k8s.local --username admin --password <admin-password>
  1. 再次执行密码更新命令:
argocd account update-password --account testuser --current-password <admin-password> --new-password <new-user-password>

解决方案2:通过ConfigMap直接配置密码哈希(适合自动化/批量场景)

如果需要批量创建用户或自动化配置,可以直接在argocd-cm中设置密码的bcrypt哈希:

  1. 生成密码的bcrypt哈希值:
    可以用htpasswd命令生成(需安装apache2-utils包):
    htpasswd -bnBC 10 "" <your-password> | tr -d ':\n'
    
  2. 修改argocd-cm.yaml配置文件,添加密码哈希字段:
apiVersion: v1
kind: ConfigMap
metadata:
  labels:
    app.kubernetes.io/name: argocd-cm
    app.kubernetes.io/part-of: argocd
  name: argocd-cm
  namespace: argocd
data:
  accounts.testuser: login
  accounts.testuser.password: "$2a$10$xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" # 替换为你的哈希值
  1. 应用配置并重启ArgoCD Server使变更生效:
kubectl rollout restart deployment argocd-server -n argocd

注意事项

  • --core模式仅适用于无需服务器交互的操作(如查看本地缓存的应用清单、直接操作K8s资源),用户管理、密码更新等需要API交互的操作必须使用在线登录模式。
  • 确保执行操作的用户(如admin)拥有ArgoCD的管理员权限,否则会出现权限不足的报错。

内容的提问来源于stack exchange,提问作者Sotiri Sotiriou

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 02:36:12