ArgoCD部署于EKS集群子路径后,CLI登录失败求助
解决ArgoCD CLI登录问题的方案
问题分析
argocd login example.com返回503:根路径Ingress规则未正确路由gRPC请求,当前配置中argogrpc服务的匹配逻辑与实际CLI请求不匹配,导致后端服务无法响应。argocd login example.com/argocd无效:CLI的login命令仅接受主机名参数,带路径的写法会被当作无效主机解析。
步骤1:修正ArgoCD Server配置
ArgoCD Server需要知晓请求的路径前缀为/argocd,才能正确处理gRPC和HTTP请求。修改argocd-server的Deployment,添加启动参数:
kubectl edit deployment argocd-server -n argocd
在spec.template.spec.containers[0].args中加入:
--rootpath=/argocd
保存后等待Deployment滚动更新完成。
步骤2:调整Ingress配置
当前Ingress的路径顺序和gRPC路由逻辑存在问题,修改后的配置如下:
resource "kubernetes_ingress_v1" "argocd_ingress" { metadata { name = "argocd-ingress" namespace = "argocd" annotations = { "alb.ingress.kubernetes.io/backend-protocol" = "HTTPS" # 匹配gRPC请求的Content-Type头 "alb.ingress.kubernetes.io/conditions.argocd-grpc" = "[{\"field\":\"http-header\",\"httpHeaderConfig\":{\"httpHeaderName\": \"Content-Type\", \"values\":[\"application/grpc\"]}}]" "alb.ingress.kubernetes.io/listen-ports" = "[{\"HTTP\": 80}, {\"HTTPS\": 443}]" "alb.ingress.kubernetes.io/ssl-redirect" = "443" "alb.ingress.kubernetes.io/scheme" = "internet-facing" "alb.ingress.kubernetes.io/target-type" = "ip" # 根路径重定向到UI入口 "alb.ingress.kubernetes.io/actions.redirect-to-argocd" = "{\"type\":\"redirect\",\"redirectConfig\":{\"host\":\"#{host}\",\"path\":\"/argocd/\",\"port\":\"443\",\"protocol\":\"HTTPS\",\"statusCode\":\"HTTP_302\"}}" } } spec { ingress_class_name = "aws-application-load-balancer-controller" rule { host = join("", var.domain_name) http { # 优先匹配/argocd前缀的请求(UI和CLI) path { backend { service { name = "argocd-server" port { number = 443 } } } path = "/argocd" path_type = "Prefix" } # 根路径重定向到/argocd/ path { backend { service { name = "redirect-to-argocd" port { name = "use-annotation" } } } path = "/" path_type = "Prefix" } } } tls { hosts = var.domain_name } } }
配置说明:
- 移除多余的
argogrpc服务路径:ArgoCD Server的443端口同时处理HTTP(UI)和gRPC(CLI)请求,无需单独路由。 - 调整路径顺序:将
/argocd前缀的路径放在最前面,确保优先匹配所有相关请求。 - 保留根路径重定向:访问根域名时自动跳转到UI入口。
- 保留gRPC请求条件:确保ALB能识别并正确路由CLI的gRPC请求。
步骤3:正确执行CLI登录命令
使用以下命令登录,适配Ingress的路径前缀和HTTP路由模式:
argocd login example.com --grpc-web --path-prefix /argocd
参数说明:
--grpc-web:让CLI通过HTTP/HTTPS发送gRPC请求,适配ALB的HTTP路由机制。--path-prefix /argocd:指定ArgoCD服务的路径前缀,与Ingress和Server配置保持一致。
执行命令后,按照提示输入用户名和密码即可完成登录。
内容的提问来源于stack exchange,提问作者mathrixx
相关产品推荐
相关产品推荐

