You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ArgoCD创建应用时连接私有Helm仓库失败:TLS套件未配置

技术环境

  • K8S版本:v1.24.9
  • ArgoCD版本:v2.6.7+5bcd846
  • GitLab
  • 私有Helm仓库(Artifactory)
  • Helm版本:3.10.3

问题描述

已在ArgoCD「仓库」板块完成GitLab仓库与私有Artifactory Helm仓库的配置,但创建应用时ArgoCD无法添加该私有Helm仓库。手动从argocd-repo-server和argocd-server容器内发起helm repo add调用可成功,且已为ArgoCD配置私有仓库的证书及CA文件。

错误日志

level=error msg="finished unary call with code Unknown" error="`helm repo add --username ****** --password ****** --ca-file /app/config/tls/xxx.xxxx.xx helm-virtual https://xxxx/helm-virtual/` failed exit status 1: Error: looks like \"https://xxxxx//helm-virtual/\" is not a valid chart repository or cannot be reached: Get \"https://xxxx/helm-virtual/index.yaml\": tls: server chose an unconfigured cipher suite" grpc.code=Unknown grpc.method=GenerateManifest grpc.service=repository.RepoServerService grpc.start_time="2023-05-20T19:03:51Z" grpc.time_ms=695.406 span.kind=server system=grpc
tls: server chose an unconfigured cipher suite

问题解答

1. 调用涉及的组件

从日志的grpc.service=repository.RepoServerService和grpc.method=GenerateManifest可以明确:

  • 首先是ArgoCD Server组件与ArgoCD Repo Server组件之间的gRPC调用,触发Manifest生成逻辑;
  • 随后Repo Server执行helm repo add命令,发起对私有Artifactory Helm仓库的HTTPS请求,TLS握手失败发生在ArgoCD Repo Server与私有Artifactory Helm仓库的网络通信环节。

2. 问题原因及解决方法

原因分析

手动执行helm repo add成功但ArgoCD内部执行失败,核心原因是:
ArgoCD进程启动时的TLS cipher suite配置,与容器内手动执行命令时的环境配置不一致,私有Artifactory仓库启用的cipher suite不在ArgoCD Repo Server进程允许的列表中,导致TLS握手协商失败。

解决方法

方法一:调整ArgoCD Repo Server的TLS配置

修改argocd-repo-server的Deployment,添加环境变量指定支持的TLS版本和cipher suite,确保覆盖Artifactory使用的套件:

  1. 编辑Deployment:
kubectl edit deploy argocd-repo-server -n argocd
  1. 在spec.template.spec.containers[0].env下新增配置:
- name: ARGOCD_TLS_MIN_VERSION
  value: "VersionTLS12"
- name: ARGOCD_TLS_CIPHER_SUITES
  value: "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256"

注:上述cipher suite为示例,需根据Artifactory实际支持的套件调整,可通过openssl s_client -connect <artifactory-host>:443命令查询Artifactory的可用套件

方法二:验证CA证书配置有效性
  • 确认CA证书文件已正确挂载到Repo Server容器的/app/config/tls/目录,且文件权限为644;
  • 检查ArgoCD Helm仓库配置中,CA证书路径是否与容器内实际路径一致;
  • 重新同步ArgoCD仓库配置,确保修改生效。
方法三:调整Artifactory的TLS配置

确认Artifactory的TLS配置中,启用了与ArgoCD兼容的cipher suite,避免使用过于特殊或老旧的加密套件。


内容的提问来源于stack exchange,提问作者NoWay

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 05:00:32