ArgoCD+Image Updater:跟踪特定版本而非分支时如何更新镜像
ArgoCD + argocd-image-updater 配置问题:锁定Chart版本同时更新镜像
需求
- dev环境跟随main分支中的最新Helm Chart
- staging环境锁定main分支的特定版本,自主选择使用的Helm Chart版本
- 当出现带有
:dev或:stg标签的新Docker镜像时,对应环境的镜像需同步更新
当前ApplicationSet配置
apiVersion: argoproj.io/v1alpha1 kind: ApplicationSet metadata: name: my-app namespace: argocd spec: goTemplate: true generators: - matrix: generators: # generate application for each config file in subdirectories - git: repoURL: https://github.com/my-company/my-app-cluster revision: main files: - path: 'cluster/common/apps/my-app/config.yaml' - list: elements: - project: my-app-dev stage: dev destinationNamespace: my-app-dev targetRevision: main # <-------------------------works perfectly fine imageName: ghcr.io/my-company/my-app-frontend:dev allowImageTags: 'regexp:\bdev\b' updateStrategy: digest - project: my-app-stg stage: stg destinationNamespace: my-app-stg targetRevision: my-app-0.1.5 # <-----------------troublemaker imageName: ghcr.io/my-company/my-app-frontend:stg allowImageTags: 'regexp:\bstg\b' updateStrategy: digest template: metadata: name: '{{ .path.basename }}-{{ .stage }}' annotations: argocd-image-updater.argoproj.io/image-list: 'app={{ .imageName }}' argocd-image-updater.argoproj.io/app.allow-tags: '{{ .allowImageTags }}' argocd-image-updater.argoproj.io/app.update-strategy: '{{ .updateStrategy }}' argocd-image-updater.argoproj.io/write-back-method: 'git:secret:argocd/gitops-imageupdater-credentials-git' argocd-image-updater.argoproj.io/app.pull-secret: 'secret:argocd/gitops-imageupdater-credentials-image-repository#credentials' # argocd-image-updater.argoproj.io/git-branch: 'main:argocd/image-updater-{{.SHA256}}' # <---- can't make it work in any combination spec: project: '{{ .project }}' source: repoURL: https://github.com/my-company/my-app-manifests targetRevision: '{{ .targetRevision }}' path: '{{ .pathInRepository }}' helm: ignoreMissingValueFiles: true valueFiles: - values.yaml - 'values-{{ .stage }}.yaml' destination: name: in-cluster namespace: '{{ .destinationNamespace }}'
问题与尝试
FluxCD可直接更新GitOps仓库中的HelmRelease(对应ArgoCD的Application),但argocd-image-updater是更新Helm仓库,导致staging环境锁定特定Chart版本后无法正常工作。
尝试通过官方文档的动态分支方案解决:
- 使用
argocd-image-updater.argoproj.io/git-branch: 'main:argocd/image-updater-{{.SHA256}}'时,{{.SHA256}}占位符无值 - 使用官方示例模板
argocd-image-updater.argoproj.io/git-branch: main:image-updater-{{range .Images}}-{{.Name}}-{{.NewTag}}{{end}},最终生成的分支名为image-updater-,无有效内容
使用静态分支名时,出现以下错误:
Updates were rejected because the tip of your current branch is behind
hint: its remote counterpart. Integrate the remote changes.
需要正确的git-branch及targetRevision配置方式,或更优实现方案。
内容的提问来源于stack exchange,提问作者pp_1
相关产品推荐
相关产品推荐

