You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Kustomize忽略带argocd-dex-server标签的ArgoCD资源?

如何在ArgoCD部署中忽略/禁用Dex Server相关资源

一、基于标签忽略资源:完全可行

Dex Server的所有关联资源(ServiceAccount、Deployment、Role等)都带有app.kubernetes.io/name=argocd-dex-server标签,你可以直接用ArgoCD自带的资源排除规则来过滤这些资源,比$patch delete更省心。

全局配置(所有ArgoCD应用生效)

修改argocd-cm ConfigMap,添加资源排除规则:

data:
  resource.exclusions: |
    - apiGroups: ["*"]
      kinds: ["ServiceAccount", "Deployment", "Role", "RoleBinding"]
      namespaces: ["argocd"] # 限定到ArgoCD命名空间,避免误删其他资源
      selector:
        matchLabels:
          app.kubernetes.io/name: argocd-dex-server

单个应用配置(仅当前ArgoCD应用生效)

如果只想针对部署ArgoCD的这个应用排除资源,在Application的syncPolicy里加规则:

apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: argocd
  namespace: argocd
spec:
  destination:
    namespace: argocd
    server: https://kubernetes.default.svc
  project: default
  source:
    chart: argo-cd
    repoURL: https://argoproj.github.io/argo-helm
    targetRevision: v2.10.0
  syncPolicy:
    resourceExclusions:
    - apiGroups: ["*"]
      kinds: ["ServiceAccount", "Deployment", "Role", "RoleBinding"]
      selector:
        matchLabels:
          app.kubernetes.io/name: argocd-dex-server

二、用$patch delete可行,但不推荐

用Kustomize的$patch: delete确实能删掉Dex相关资源,但有几个明显的坑:

  • 每次ArgoCD同步都会触发删除操作,资源变动日志会变得冗余
  • 上游ArgoCD Helm Chart更新时,可能会重新创建Dex资源,导致同步冲突
  • 需要额外维护补丁文件,不如直接用ArgoCD的资源排除配置简洁

三、最优方案:直接禁用Dex Server(强烈推荐)

如果你的场景不需要Dex做认证(比如用ArgoCD本地用户、直接对接企业OIDC等),从部署源头禁用Dex是最彻底的方式,完全避免后续的资源同步问题:

Helm部署时禁用

执行helm安装/升级命令时加上参数:

helm upgrade --install argocd argo/argo-cd --namespace argocd \
  --set dex.enabled=false \
  --set configs.cm.dex.config=""

Kustomize部署时禁用

在kustomization.yaml里添加补丁,直接关闭Dex:

patches:
# 清空Dex配置
- target:
    kind: ConfigMap
    name: argocd-cm
  patch: |-
    apiVersion: v1
    kind: ConfigMap
    metadata:
      name: argocd-cm
    data:
      dex.config: ""
# 把Dex Deployment副本数设为0,或者直接删除
- target:
    kind: Deployment
    name: argocd-dex-server
  patch: |-
    apiVersion: apps/v1
    kind: Deployment
    metadata:
      name: argocd-dex-server
    spec:
      replicas: 0

这样操作后,Dex相关的资源根本不会被创建,从根源解决问题,比单纯忽略或删除靠谱得多。

内容的提问来源于stack exchange,提问作者Sandeep Kumar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 23:46:00