You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为何ArgoCD无法通过CLI经由Ingress访问?

问题描述

执行以下ArgoCD CLI登录命令:

argocd login $(kubectl get ingress argocd-server-ingress -n argocd -o jsonpath='{.spec.rules[0].host}') --username admin --password $(kubectl -n argocd get secret  argocd-initial-admin-secret -o jsonpath="{.data.password}" | base64 -d; echo) --insecure

收到错误提示:

dial tcp IP_ADDRESS operation was canceled

当前使用的Ingress配置如下:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: argocd-server-ingress
  namespace: argocd
  annotations:
    custom.nginx.org/backend: https
    kubernetes.io/ingress.class: nginx
    nginx.ingress.kubernetes.io/backend-protocol: HTTPS
    nginx.ingress.kubernetes.io/proxy-body-size: 600m
    nginx.ingress.kubernetes.io/proxy-http-version: '1.1'
    nginx.ingress.kubernetes.io/ssl-redirect: 'true'
    nginx.ingress.kubernetes.io/use-regex: 'true'
    nginx.ingress.kubernetes.io/ssl-passthrough: "true"
spec:
  tls: 
  - hosts:
    - example.com
    secretName: secret
  rules:
  - host: example.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: argocd-server
            port:
              name: http

此前将argocd-server Service改为LoadBalancer类型时可正常CLI登录,但该方式不适用于生产环境,因此配置了自定义主机名的Ingress,请问为何无法通过Ingress实现CLI登录?


问题排查与解决

针对你的情况,无法通过Ingress登录ArgoCD CLI的核心问题集中在Ingress配置冲突和端口匹配上,以下是具体修复方案:

1. 修正后端端口配置

你启用了nginx.ingress.kubernetes.io/ssl-passthrough: "true",该注解会让Ingress直接透传TLS流量到后端服务,而ArgoCD Server处理HTTPS请求的是https端口(443),但当前Ingress配置的后端端口是http(80端口),导致流量无法正确到达服务。

修复:将Ingress后端端口改为https:

backend:
  service:
    name: argocd-server
    port:
      name: https

2. 移除冲突的SSL注解

你同时配置了nginx.ingress.kubernetes.io/backend-protocol: HTTPS和ssl-passthrough,这两个注解存在逻辑冲突:

  • ssl-passthrough要求Ingress不终止SSL,直接转发原始TLS流量
  • backend-protocol: HTTPS则是让Ingress终止SSL后,用HTTPS协议和后端通信

修复:保留ssl-passthrough的前提下,删除nginx.ingress.kubernetes.io/backend-protocol: HTTPS注解。

3. 验证DNS与网络连通性

  • 执行nslookup example.com确认本地机器能正确解析主机名到Ingress Controller的公网IP
  • 用telnet example.com 443测试端口连通性,确保集群防火墙/安全组已开放443端口

4. 调整登录命令参数

由于启用了SSL Passthrough,ArgoCD Server自行处理SSL证书,可调整登录命令参数适配Ingress的GRPC转发:

argocd login $(kubectl get ingress argocd-server-ingress -n argocd -o jsonpath='{.spec.rules[0].host}') --username admin --password $(kubectl -n argocd get secret argocd-initial-admin-secret -o jsonpath="{.data.password}" | base64 -d) --grpc-web

内容的提问来源于stack exchange,提问作者dev1993

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 15:17:49