You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ArgoCD集成Github SSO遇错:查询provider失败(400/404)

解决ArgoCD集成Github SSO(Dex)时的400/404错误

以下是针对你遇到的错误的排查和修复步骤:

1. 替换ConfigMap中的占位符变量

你的dex.config里的${clientID}和${clientSecret}是占位符,必须替换为Github OAuth应用的真实ID和密钥。如果保留这些占位符,Dex无法完成OAuth认证流程,会直接返回400错误。

修改后的配置示例:

dex.config: |
  connectors:
    - type: github
      id: github
      name: Github
      config:
        clientID: "your-github-oauth-client-id"
        clientSecret: "your-github-oauth-client-secret"
        hostName: github.example.net
        orgs:
        - name: example

2. 验证Github OAuth应用的回调URL

确保你在Github(企业版)创建的OAuth应用的回调URL设置为:
https://argo.example.net/api/dex/callback
如果回调URL不匹配,Github会拒绝认证请求,导致ArgoCD返回400错误。

3. 检查Github企业版域名配置

如果使用的是公共Github而非企业版,需要删除hostName字段;如果是企业版,确认github.example.net是你的企业Github实例的正确域名(比如通常是github.company.com这类格式),域名错误会导致Dex无法连接Github认证服务,触发400或404。

4. 确认ArgoCD和Dex服务的连通性

404错误可能是ArgoCD无法访问Dex服务导致的:

  • 检查ArgoCD的Dex Deployment是否正常运行:kubectl get pods -n argocd | grep dex
  • 确认ArgoCD的API服务能正确路由到Dex:Dex默认通过argocd-dex-server服务暴露,ArgoCD会自动代理/api/dex路径到该服务,若服务名称或端口被修改,需要同步调整ArgoCD的配置。

5. 重新加载ArgoCD配置

修改ConfigMap后,需要重启ArgoCD相关Pod让配置生效:

kubectl rollout restart deployment argocd-server argocd-dex-server -n argocd

内容的提问来源于stack exchange,提问作者dev1993

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 06:42:17