You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ArgoCD+Image Updater:跟踪特定版本而非分支时如何更新镜像

ArgoCD + argocd-image-updater 配置问题:锁定Chart版本同时更新镜像

需求

  • dev环境跟随main分支中的最新Helm Chart
  • staging环境锁定main分支的特定版本,自主选择使用的Helm Chart版本
  • 当出现带有:dev或:stg标签的新Docker镜像时,对应环境的镜像需同步更新

当前ApplicationSet配置

apiVersion: argoproj.io/v1alpha1
kind: ApplicationSet
metadata:
  name: my-app
  namespace: argocd
spec:
  goTemplate: true
  generators:
    - matrix:
        generators:
          # generate application for each config file in subdirectories
          - git:
              repoURL: https://github.com/my-company/my-app-cluster
              revision: main
              files:
                - path: 'cluster/common/apps/my-app/config.yaml'
          - list:
              elements:
                - project: my-app-dev
                  stage: dev
                  destinationNamespace: my-app-dev
                  targetRevision: main # <-------------------------works perfectly fine
                  imageName: ghcr.io/my-company/my-app-frontend:dev
                  allowImageTags: 'regexp:\bdev\b'
                  updateStrategy: digest
                - project: my-app-stg
                  stage: stg
                  destinationNamespace: my-app-stg
                  targetRevision: my-app-0.1.5 # <-----------------troublemaker
                  imageName: ghcr.io/my-company/my-app-frontend:stg
                  allowImageTags: 'regexp:\bstg\b'
                  updateStrategy: digest
  template:
    metadata:
      name: '{{ .path.basename }}-{{ .stage }}'
      annotations:
        argocd-image-updater.argoproj.io/image-list: 'app={{ .imageName }}'
        argocd-image-updater.argoproj.io/app.allow-tags: '{{ .allowImageTags }}'
        argocd-image-updater.argoproj.io/app.update-strategy: '{{ .updateStrategy }}'
        argocd-image-updater.argoproj.io/write-back-method: 'git:secret:argocd/gitops-imageupdater-credentials-git'
        argocd-image-updater.argoproj.io/app.pull-secret: 'secret:argocd/gitops-imageupdater-credentials-image-repository#credentials'
        # argocd-image-updater.argoproj.io/git-branch: 'main:argocd/image-updater-{{.SHA256}}' # <---- can't make it work in any combination
    spec:
      project: '{{ .project }}'
      source:
        repoURL: https://github.com/my-company/my-app-manifests
        targetRevision: '{{ .targetRevision }}'
        path: '{{ .pathInRepository }}'
        helm:
          ignoreMissingValueFiles: true
          valueFiles:
            - values.yaml
            - 'values-{{ .stage }}.yaml'
      destination:
        name: in-cluster
        namespace: '{{ .destinationNamespace }}'

问题与尝试

FluxCD可直接更新GitOps仓库中的HelmRelease(对应ArgoCD的Application),但argocd-image-updater是更新Helm仓库,导致staging环境锁定特定Chart版本后无法正常工作。

尝试通过官方文档的动态分支方案解决:

  • 使用argocd-image-updater.argoproj.io/git-branch: 'main:argocd/image-updater-{{.SHA256}}'时,{{.SHA256}}占位符无值
  • 使用官方示例模板argocd-image-updater.argoproj.io/git-branch: main:image-updater-{{range .Images}}-{{.Name}}-{{.NewTag}}{{end}},最终生成的分支名为image-updater-,无有效内容

使用静态分支名时,出现以下错误:

Updates were rejected because the tip of your current branch is behind
hint: its remote counterpart. Integrate the remote changes.

需要正确的git-branch及targetRevision配置方式,或更优实现方案。


内容的提问来源于stack exchange,提问作者pp_1

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 11:38:21