ArgoCD创建应用时连接私有Helm仓库失败:TLS套件未配置
技术环境
- K8S版本:v1.24.9
- ArgoCD版本:v2.6.7+5bcd846
- GitLab
- 私有Helm仓库(Artifactory)
- Helm版本:3.10.3
问题描述
已在ArgoCD「仓库」板块完成GitLab仓库与私有Artifactory Helm仓库的配置,但创建应用时ArgoCD无法添加该私有Helm仓库。手动从argocd-repo-server和argocd-server容器内发起helm repo add调用可成功,且已为ArgoCD配置私有仓库的证书及CA文件。
错误日志
level=error msg="finished unary call with code Unknown" error="`helm repo add --username ****** --password ****** --ca-file /app/config/tls/xxx.xxxx.xx helm-virtual https://xxxx/helm-virtual/` failed exit status 1: Error: looks like \"https://xxxxx//helm-virtual/\" is not a valid chart repository or cannot be reached: Get \"https://xxxx/helm-virtual/index.yaml\": tls: server chose an unconfigured cipher suite" grpc.code=Unknown grpc.method=GenerateManifest grpc.service=repository.RepoServerService grpc.start_time="2023-05-20T19:03:51Z" grpc.time_ms=695.406 span.kind=server system=grpc
tls: server chose an unconfigured cipher suite
问题解答
1. 调用涉及的组件
从日志的grpc.service=repository.RepoServerService和grpc.method=GenerateManifest可以明确:
- 首先是ArgoCD Server组件与ArgoCD Repo Server组件之间的gRPC调用,触发Manifest生成逻辑;
- 随后Repo Server执行
helm repo add命令,发起对私有Artifactory Helm仓库的HTTPS请求,TLS握手失败发生在ArgoCD Repo Server与私有Artifactory Helm仓库的网络通信环节。
2. 问题原因及解决方法
原因分析
手动执行helm repo add成功但ArgoCD内部执行失败,核心原因是:
ArgoCD进程启动时的TLS cipher suite配置,与容器内手动执行命令时的环境配置不一致,私有Artifactory仓库启用的cipher suite不在ArgoCD Repo Server进程允许的列表中,导致TLS握手协商失败。
解决方法
方法一:调整ArgoCD Repo Server的TLS配置
修改argocd-repo-server的Deployment,添加环境变量指定支持的TLS版本和cipher suite,确保覆盖Artifactory使用的套件:
- 编辑Deployment:
kubectl edit deploy argocd-repo-server -n argocd
- 在
spec.template.spec.containers[0].env下新增配置:
- name: ARGOCD_TLS_MIN_VERSION value: "VersionTLS12" - name: ARGOCD_TLS_CIPHER_SUITES value: "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
注:上述cipher suite为示例,需根据Artifactory实际支持的套件调整,可通过openssl s_client -connect <artifactory-host>:443命令查询Artifactory的可用套件
方法二:验证CA证书配置有效性
- 确认CA证书文件已正确挂载到Repo Server容器的
/app/config/tls/目录,且文件权限为644; - 检查ArgoCD Helm仓库配置中,CA证书路径是否与容器内实际路径一致;
- 重新同步ArgoCD仓库配置,确保修改生效。
方法三:调整Artifactory的TLS配置
确认Artifactory的TLS配置中,启用了与ArgoCD兼容的cipher suite,避免使用过于特殊或老旧的加密套件。
内容的提问来源于stack exchange,提问作者NoWay

