You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在自托管ArgoCD的Helm应用参数中配置dex.config?

解决ArgoCD Helm应用中添加dex.config的类型错误问题

问题根源

ArgoCD Helm Chart里的configs.cm.dex.config对应ConfigMap中的dex.config字段,该字段要求是字符串格式的YAML/JSON。你当前用parameters传递多行YAML时,Helm会把它解析成map类型,导致类型不匹配报错。

两种可行解决方案

方案1:改用values字段(推荐,易维护)

直接在helm.values中定义配置,Helm会自动将嵌套的多行YAML序列化为字符串存入ConfigMap:

apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: argocd
  namespace: argocd
spec:
  project: argocd
  source:
    chart: argo-cd
    repoURL: https://argoproj.github.io/argo-helm
    targetRevision: 5.19.1
    helm:
      values: |
        configs:
          cm:
            timeout.reconciliation: 120s
            dex.config: |
              logger:
                level: debug
                format: json
              connectors:
              - type: saml
                id: saml
                name: AzureAD
                config:
                  entityIssuer: https://argocd.example.com/api/dex/callback
                  ssoURL: https://login.microsoftonline.com/xxx/saml2
                  caData: |
                    ...
                  redirectURI: https://argocd.example.com/api/dex/callback
                  usernameAttr: email
                  emailAttr: email
                  groupsAttr: Group
  destination:
    server: https://kubernetes.default.svc
    namespace: argocd

方案2:在parameters中传递序列化后的JSON字符串

如果坚持使用parameters,需要把dex配置转成单行JSON字符串(注意引号转义):

apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: argocd
  namespace: argocd
spec:
  project: argocd
  source:
    chart: argo-cd
    repoURL: https://argoproj.github.io/argo-helm
    targetRevision: 5.19.1
    helm:
      parameters:
       - name: configs.cm."timeout\.reconciliation"
         value: "120s"
       - name: configs.cm."dex\.config"
         value: '{"logger":{"level":"debug","format":"json"},"connectors":[{"type":"saml","id":"saml","name":"AzureAD","config":{"entityIssuer":"https://argocd.example.com/api/dex/callback","ssoURL":"https://login.microsoftonline.com/xxx/saml2","caData":"...","redirectURI":"https://argocd.example.com/api/dex/callback","usernameAttr":"email","emailAttr":"email","groupsAttr":"Group"}}]}'
  destination:
    server: https://kubernetes.default.svc
    namespace: argocd

补充说明

  • 方案1更适合复杂配置,可读性和维护性更强,无需手动处理格式转义。
  • 方案2仅适合简单场景,手动转JSON容易出现语法错误,不推荐用于复杂的dex配置。

内容的提问来源于stack exchange,提问作者Michael Chudinov

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 01:15:31