You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在CI流水线(Tekton/GitHub Actions)中执行argocd app create时遭遇PermissionDenied错误求助

Fixing ArgoCD PermissionDenied for argocd app create in Tekton Pipelines

Got it, let's get this permission issue sorted out! The root problem here is that even though you created the tekton user in ArgoCD and generated an API key, you haven't granted that user the RBAC permissions needed to create and sync applications in the default namespace. ArgoCD uses its own internal RBAC system separate from Kubernetes' RBAC, so just enabling the user isn't enough.

Here's how to fix it step by step:

1. Understand the Required Permissions

You need to grant the tekton user two key permissions for your use case:

  • applications, create (to create new ArgoCD applications)
  • applications, sync (to trigger syncs for those applications)
  • Scope these permissions to the default namespace (or use */* if you need access across all namespaces)

The easiest way to manage ArgoCD RBAC is directly through the CLI, which avoids manual ConfigMap edits:

# Create a custom role for Tekton pipeline operations
argocd policy role create tekton-pipeline-role

# Add permission to create applications in the default namespace
argocd policy role add-permission tekton-pipeline-role applications create default/*

# Add permission to sync applications in the default namespace
argocd policy role add-permission tekton-pipeline-role applications sync default/*

# Assign the role to your tekton user
argocd policy role add-user tekton-pipeline-role tekton

3. Alternative: Update the ArgoCD RBAC ConfigMap

If you prefer editing the ConfigMap directly (e.g., in a CI/CD pipeline or as part of infrastructure-as-code), use this kubectl patch command:

kubectl patch configmap argocd-rbac-cm -n argocd -p '{"data": {"policy.csv": "p, role:tekton-pipeline-role, applications, create, default/*, allow\np, role:tekton-pipeline-role, applications, sync, default/*, allow\ng, tekton, role:tekton-pipeline-role"}}'

Breakdown of the policy.csv rules:

  • p, role:tekton-pipeline-role, applications, create, default/*, allow: Grants the role permission to create any application in the default namespace
  • p, role:tekton-pipeline-role, applications, sync, default/*, allow: Grants sync access for those applications
  • g, tekton, role:tekton-pipeline-role: Associates the tekton user with the custom role

4. Verify the Changes & Restart (If Needed)

To make sure the RBAC rules take effect, you can restart the ArgoCD server deployment:

kubectl rollout restart deployment argocd-server -n argocd

Then test the permissions locally first (before re-running your Tekton pipeline) to confirm:

# Log in as the tekton user
argocd login <your-argocd-server-hostname> --username=tekton --password=<your-tekton-token>

# Try creating your test application
argocd app create microservice-api-spring-boot --repo https://gitlab.com/jonashackt/microservice-api-spring-boot-config.git --path deployment --dest-server https://kubernetes.default.svc --dest-namespace default --revision argocd --sync-policy auto

Bonus: Broader Permissions (If Needed)

If your Tekton pipeline needs to manage applications across all namespaces, replace default/* with */* in the permission rules. You can also add additional permissions like applications, update or applications, delete if your workflow requires them.


内容的提问来源于stack exchange,提问作者jonashackt

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 11:37:45