You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ArgoCD 2.4升级至2.11+AVP+AWS Secrets Manager配置错误

ArgoCD升级至2.11后Argocd-Vault-Plugin (AVP) 报错:Must provide a supported Vault Type

问题背景

我们正将ArgoCD从2.4版本升级至2.11版本,由于2.7+版本不再支持通过argocd-cm配置AVP插件,于是创建了指定ConfigMap并对argocd-repo-server Deployment打补丁,执行后出现以下错误:

Failed to load target state: failed to generate manifest for source 1 of 1: rpc error: code = Unknown desc = plugin sidecar failed. error generating manifests in cmp: rpc error: code = Unknown desc = error generating manifests: argocd-vault-plugin generate . failed exit status 1: Error: Must provide a supported Vault Type, received Usage: argocd-vault-plugin generate [flags] Flags: -c, --config-path string path to a file containing Vault configuration (YAML, JSON, envfile) to use -h, --help help for generate -s, --secret-name string name of a Kubernetes Secret in the argocd namespace containing Vault configuration data in the argocd namespace of your ArgoCD host (Only available when used in ArgoCD). The namespace can be overridden by using the format : --verbose-sensitive-output enable verbose mode for detailed info to help with debugging. Includes sensitive data (credentials), logged to stderr

当前使用的ConfigMap

apiVersion: v1
kind: ConfigMap
metadata:
  name: cmp-plugin
data:
  avp.yaml: |
    apiVersion: argoproj.io/v1alpha1
    kind: ConfigManagementPlugin
    metadata:
      name: argocd-vault-plugin
    spec:
      allowConcurrency: true
      discover:
        find:
          command:
            - sh
            - "-c"
            - "find . -name '*.yaml' | xargs -I {} grep \"<path\\|avp\\.kubernetes\\.io\" {} | grep ."
      generate:
        command:
          - argocd-vault-plugin
          - generate
          - "."
      lockRepo: false
---

当前使用的Deployment补丁

apiVersion: apps/v1
kind: Deployment
metadata:
  name: argocd-repo-server
spec:
  template:
    spec:
      automountServiceAccountToken: true
      volumes:
        - configMap:
            name: cmp-plugin
          name: cmp-plugin
        - name: custom-tools
          emptyDir: {}
      initContainers:
      - name: download-tools
        image: registry.access.redhat.com/ubi8
        env:
          - name: AVP_VERSION
            value: 1.16.1
        command: [sh, -c]
        args:
          - >-
            curl -L https://github.com/argoproj-labs/argocd-vault-plugin/releases/download/v$(AVP_VERSION)/argocd-vault-plugin_$(AVP_VERSION)_linux_amd64 -o argocd-vault-plugin &&
            chmod +x argocd-vault-plugin &&
            mv argocd-vault-plugin /custom-tools/
        volumeMounts:
          - mountPath: /custom-tools
            name: custom-tools
      containers:
      - name: avp
        command: [/var/run/argocd/argocd-cmp-server]
        image: registry.access.redhat.com/ubi8
        securityContext:
          runAsNonRoot: true
          runAsUser: 999
        volumeMounts:
          - mountPath: /var/run/argocd
            name: var-files
          - mountPath: /home/argocd/cmp-server/plugins
            name: plugins
          - mountPath: /tmp
            name: tmp

          # Register plugins into sidecar
          - mountPath: /home/argocd/cmp-server/config/plugin.yaml
            subPath: avp.yaml
            name: cmp-plugin

          # Important: Mount tools into $PATH
          - name: custom-tools
            subPath: argocd-vault-plugin
            mountPath: /usr/local/bin/argocd-vault-plugin

问题原因

错误提示说明AVP无法获取Vault的核心配置信息(比如Vault类型、地址、认证方式等)。在CMP模式下,AVP需要通过Kubernetes Secret或环境变量加载这些配置,但当前部署中既没有挂载对应的配置Secret,也未传递必要的环境变量,导致插件无法初始化。

解决步骤

1. 创建存储AVP配置的Secret

在ArgoCD命名空间下创建Secret,填入你的实际Vault配置:

apiVersion: v1
kind: Secret
metadata:
  name: avp-secret
  namespace: argocd
type: Opaque
stringData:
  type: vault  # 替换为你的Vault类型,如awssecretsmanager、gcpsecretsmanager等
  vault_addr: "https://your-vault-server:8200"
  vault_auth_method: kubernetes
  vault_role: "argocd-vault-plugin-role"
  # 根据认证方式添加其他配置,如token、aws_access_key_id等

2. 更新Deployment补丁,挂载AVP配置Secret

修改argocd-repo-server的Deployment补丁,添加Secret卷和挂载:

  • 在volumes节点下新增:
- name: avp-secret
  secret:
    secretName: avp-secret
  • 在avp容器的volumeMounts节点下新增:
- mountPath: /home/argocd/.avp
  name: avp-secret

或者,如果你偏好通过环境变量传递配置,可在avp容器的env节点下添加:

env:
  - name: AVP_TYPE
    valueFrom:
      secretKeyRef:
        name: avp-secret
        key: type
  - name: AVP_VAULT_ADDR
    valueFrom:
      secretKeyRef:
        name: avp-secret
        key: vault_addr
  # 按需添加其他环境变量,如AVP_VAULT_AUTH_METHOD、AVP_VAULT_ROLE等

3. 修改CMP插件配置,指定Secret名称

更新ConfigMap中的AVP插件配置,在generate命令中添加--secret-name参数指向刚创建的Secret:

generate:
  command:
    - argocd-vault-plugin
    - generate
    - "."
    - "--secret-name"
    - "avp-secret"

4. 应用更新并验证

重新应用ConfigMap和Deployment补丁:

kubectl apply -f cmp-plugin-configmap.yaml -n argocd
kubectl patch deployment argocd-repo-server -n argocd --patch-file repo-server-patch.yaml

等待argocd-repo-server滚动更新完成后,触发ArgoCD同步操作,验证错误是否消失。

额外说明

  • 确保AVP版本(1.16.1)与你的Vault版本兼容,避免版本不匹配引发问题。
  • 使用Kubernetes认证方式时,需确保argocd-repo-server的ServiceAccount具备访问Vault认证端点的权限。
  • 所有敏感配置(如token、密钥)必须存储在Kubernetes Secret中,禁止硬编码。

内容的提问来源于stack exchange,提问作者Dan Zaltsman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 15:54:55