为何ArgoCD无法通过CLI经由Ingress访问?
执行以下ArgoCD CLI登录命令:
argocd login $(kubectl get ingress argocd-server-ingress -n argocd -o jsonpath='{.spec.rules[0].host}') --username admin --password $(kubectl -n argocd get secret argocd-initial-admin-secret -o jsonpath="{.data.password}" | base64 -d; echo) --insecure
收到错误提示:
dial tcp IP_ADDRESS operation was canceled
当前使用的Ingress配置如下:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: argocd-server-ingress namespace: argocd annotations: custom.nginx.org/backend: https kubernetes.io/ingress.class: nginx nginx.ingress.kubernetes.io/backend-protocol: HTTPS nginx.ingress.kubernetes.io/proxy-body-size: 600m nginx.ingress.kubernetes.io/proxy-http-version: '1.1' nginx.ingress.kubernetes.io/ssl-redirect: 'true' nginx.ingress.kubernetes.io/use-regex: 'true' nginx.ingress.kubernetes.io/ssl-passthrough: "true" spec: tls: - hosts: - example.com secretName: secret rules: - host: example.com http: paths: - path: / pathType: Prefix backend: service: name: argocd-server port: name: http
此前将argocd-server Service改为LoadBalancer类型时可正常CLI登录,但该方式不适用于生产环境,因此配置了自定义主机名的Ingress,请问为何无法通过Ingress实现CLI登录?
针对你的情况,无法通过Ingress登录ArgoCD CLI的核心问题集中在Ingress配置冲突和端口匹配上,以下是具体修复方案:
1. 修正后端端口配置
你启用了nginx.ingress.kubernetes.io/ssl-passthrough: "true",该注解会让Ingress直接透传TLS流量到后端服务,而ArgoCD Server处理HTTPS请求的是https端口(443),但当前Ingress配置的后端端口是http(80端口),导致流量无法正确到达服务。
修复:将Ingress后端端口改为https:
backend: service: name: argocd-server port: name: https
2. 移除冲突的SSL注解
你同时配置了nginx.ingress.kubernetes.io/backend-protocol: HTTPS和ssl-passthrough,这两个注解存在逻辑冲突:
ssl-passthrough要求Ingress不终止SSL,直接转发原始TLS流量backend-protocol: HTTPS则是让Ingress终止SSL后,用HTTPS协议和后端通信
修复:保留ssl-passthrough的前提下,删除nginx.ingress.kubernetes.io/backend-protocol: HTTPS注解。
3. 验证DNS与网络连通性
- 执行
nslookup example.com确认本地机器能正确解析主机名到Ingress Controller的公网IP - 用
telnet example.com 443测试端口连通性,确保集群防火墙/安全组已开放443端口
4. 调整登录命令参数
由于启用了SSL Passthrough,ArgoCD Server自行处理SSL证书,可调整登录命令参数适配Ingress的GRPC转发:
argocd login $(kubectl get ingress argocd-server-ingress -n argocd -o jsonpath='{.spec.rules[0].host}') --username admin --password $(kubectl -n argocd get secret argocd-initial-admin-secret -o jsonpath="{.data.password}" | base64 -d) --grpc-web
内容的提问来源于stack exchange,提问作者dev1993

