在CI流水线(Tekton/GitHub Actions)中执行argocd app create时遭遇PermissionDenied错误求助
argocd app create in Tekton Pipelines Got it, let's get this permission issue sorted out! The root problem here is that even though you created the tekton user in ArgoCD and generated an API key, you haven't granted that user the RBAC permissions needed to create and sync applications in the default namespace. ArgoCD uses its own internal RBAC system separate from Kubernetes' RBAC, so just enabling the user isn't enough.
Here's how to fix it step by step:
1. Understand the Required Permissions
You need to grant the tekton user two key permissions for your use case:
applications, create(to create new ArgoCD applications)applications, sync(to trigger syncs for those applications)- Scope these permissions to the
defaultnamespace (or use*/*if you need access across all namespaces)
2. Assign Permissions via ArgoCD CLI (Recommended)
The easiest way to manage ArgoCD RBAC is directly through the CLI, which avoids manual ConfigMap edits:
# Create a custom role for Tekton pipeline operations argocd policy role create tekton-pipeline-role # Add permission to create applications in the default namespace argocd policy role add-permission tekton-pipeline-role applications create default/* # Add permission to sync applications in the default namespace argocd policy role add-permission tekton-pipeline-role applications sync default/* # Assign the role to your tekton user argocd policy role add-user tekton-pipeline-role tekton
3. Alternative: Update the ArgoCD RBAC ConfigMap
If you prefer editing the ConfigMap directly (e.g., in a CI/CD pipeline or as part of infrastructure-as-code), use this kubectl patch command:
kubectl patch configmap argocd-rbac-cm -n argocd -p '{"data": {"policy.csv": "p, role:tekton-pipeline-role, applications, create, default/*, allow\np, role:tekton-pipeline-role, applications, sync, default/*, allow\ng, tekton, role:tekton-pipeline-role"}}'
Breakdown of the policy.csv rules:
p, role:tekton-pipeline-role, applications, create, default/*, allow: Grants the role permission to create any application in thedefaultnamespacep, role:tekton-pipeline-role, applications, sync, default/*, allow: Grants sync access for those applicationsg, tekton, role:tekton-pipeline-role: Associates thetektonuser with the custom role
4. Verify the Changes & Restart (If Needed)
To make sure the RBAC rules take effect, you can restart the ArgoCD server deployment:
kubectl rollout restart deployment argocd-server -n argocd
Then test the permissions locally first (before re-running your Tekton pipeline) to confirm:
# Log in as the tekton user argocd login <your-argocd-server-hostname> --username=tekton --password=<your-tekton-token> # Try creating your test application argocd app create microservice-api-spring-boot --repo https://gitlab.com/jonashackt/microservice-api-spring-boot-config.git --path deployment --dest-server https://kubernetes.default.svc --dest-namespace default --revision argocd --sync-policy auto
Bonus: Broader Permissions (If Needed)
If your Tekton pipeline needs to manage applications across all namespaces, replace default/* with */* in the permission rules. You can also add additional permissions like applications, update or applications, delete if your workflow requires them.
内容的提问来源于stack exchange,提问作者jonashackt

