You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ArgoCD部署于EKS集群子路径后,CLI登录失败求助

解决ArgoCD CLI登录问题的方案

问题分析

  1. argocd login example.com返回503:根路径Ingress规则未正确路由gRPC请求,当前配置中argogrpc服务的匹配逻辑与实际CLI请求不匹配,导致后端服务无法响应。
  2. argocd login example.com/argocd无效:CLI的login命令仅接受主机名参数,带路径的写法会被当作无效主机解析。

步骤1:修正ArgoCD Server配置

ArgoCD Server需要知晓请求的路径前缀为/argocd,才能正确处理gRPC和HTTP请求。修改argocd-server的Deployment,添加启动参数:

kubectl edit deployment argocd-server -n argocd

在spec.template.spec.containers[0].args中加入:

--rootpath=/argocd

保存后等待Deployment滚动更新完成。

步骤2:调整Ingress配置

当前Ingress的路径顺序和gRPC路由逻辑存在问题,修改后的配置如下:

resource "kubernetes_ingress_v1" "argocd_ingress" {
  metadata {
    name      = "argocd-ingress"
    namespace = "argocd"
    annotations = {
      "alb.ingress.kubernetes.io/backend-protocol" = "HTTPS"
      # 匹配gRPC请求的Content-Type头
      "alb.ingress.kubernetes.io/conditions.argocd-grpc" = "[{\"field\":\"http-header\",\"httpHeaderConfig\":{\"httpHeaderName\": \"Content-Type\", \"values\":[\"application/grpc\"]}}]"
      "alb.ingress.kubernetes.io/listen-ports"        = "[{\"HTTP\": 80}, {\"HTTPS\": 443}]"
      "alb.ingress.kubernetes.io/ssl-redirect" = "443"
      "alb.ingress.kubernetes.io/scheme"              = "internet-facing"
      "alb.ingress.kubernetes.io/target-type"         = "ip"
      # 根路径重定向到UI入口
      "alb.ingress.kubernetes.io/actions.redirect-to-argocd" = "{\"type\":\"redirect\",\"redirectConfig\":{\"host\":\"#{host}\",\"path\":\"/argocd/\",\"port\":\"443\",\"protocol\":\"HTTPS\",\"statusCode\":\"HTTP_302\"}}"
    }
  }

  spec {
    ingress_class_name = "aws-application-load-balancer-controller"
    rule {
      host = join("", var.domain_name)
      http {
        # 优先匹配/argocd前缀的请求(UI和CLI)
        path {
          backend {
            service {
              name = "argocd-server"
              port {
                number = 443
              }
            }
          }
          path      = "/argocd"
          path_type = "Prefix"
        }
        # 根路径重定向到/argocd/
        path {
          backend {
            service {
              name = "redirect-to-argocd"
              port {
                name = "use-annotation"
              }
            }
          }
          path      = "/"
          path_type = "Prefix"
        }
      }
    }
    tls {
      hosts = var.domain_name
    }
  }
}

配置说明:

  • 移除多余的argogrpc服务路径:ArgoCD Server的443端口同时处理HTTP(UI)和gRPC(CLI)请求,无需单独路由。
  • 调整路径顺序:将/argocd前缀的路径放在最前面,确保优先匹配所有相关请求。
  • 保留根路径重定向:访问根域名时自动跳转到UI入口。
  • 保留gRPC请求条件:确保ALB能识别并正确路由CLI的gRPC请求。

步骤3:正确执行CLI登录命令

使用以下命令登录,适配Ingress的路径前缀和HTTP路由模式:

argocd login example.com --grpc-web --path-prefix /argocd

参数说明:

  • --grpc-web:让CLI通过HTTP/HTTPS发送gRPC请求,适配ALB的HTTP路由机制。
  • --path-prefix /argocd:指定ArgoCD服务的路径前缀,与Ingress和Server配置保持一致。

执行命令后,按照提示输入用户名和密码即可完成登录。

内容的提问来源于stack exchange,提问作者mathrixx

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 21:17:46