You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EKS集群Argo CD的Nginx Ingress无法重定向至HTTPS问题排查

解决Argo CD自定义域名HTTPS访问不安全问题

你的Ingress配置存在几个关键问题,导致浏览器显示非安全HTTPS连接,以及移除backend-protocol后的重定向循环,以下是具体修复方案:

1. 修正注解拼写错误

你的配置里有个笔误:nignx.ingress.kubernetes.io/force-ssl-redirect中的nignx应该改为nginx,这个错误会导致强制HTTPS重定向注解不生效,可能引发混合内容或证书信任问题。

2. 选择合适的TLS终止方案

根据你的需求,推荐两种配置方案:

方案一:Ingress终止TLS(推荐,配置更简单)

让Ingress NGINX处理TLS终止,和Argo CD Server用HTTP通信,避免证书在后端服务的复杂配置:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: argocd
  namespace: argocd
  annotations:
    cert-manager.io/cluster-issuer: letsencrypt-prod
    kubernetes.io/tls-acme: "true"
    nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
    nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
spec:
  ingressClassName: nginx
  rules:
  - host: argocd.example.com
    http:
      paths:
      - path: /
        pathType: ImplementationSpecific
        backend:
          service:
            name: argocd-server
            port:
              number: 80
  tls:
  - hosts:
    - argocd.example.com
    secretName: argocd-tls

补充配置

需要让Argo CD Server知道对外的HTTPS地址,避免内部重定向错误:

  • 编辑argocd-cm ConfigMap:
    data:
      url: https://argocd.example.com
    
  • (可选)允许Argo CD Server接收HTTP请求,在argocd-server Deployment中添加环境变量:
    env:
    - name: ARGOCD_SERVER_INSECURE
      value: "true"
    

方案二:SSL Passthrough(后端处理TLS)

如果必须保留SSL Passthrough(直接转发TLS流量到Argo CD Server),需要确保后端使用Let's Encrypt的信任证书:

修正后的Ingress配置

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: argocd
  namespace: argocd
  annotations:
    cert-manager.io/cluster-issuer: letsencrypt-prod
    kubernetes.io/tls-acme: "true"
    nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
    nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
    nginx.ingress.kubernetes.io/ssl-passthrough: "true"
spec:
  ingressClassName: nginx
  rules:
  - host: argocd.example.com
    http:
      paths:
      - path: /
        pathType: ImplementationSpecific
        backend:
          service:
            name: argocd-server
            port:
              number: 443
  tls:
  - hosts:
    - argocd.example.com
    secretName: argocd-tls

关键补充步骤

  1. 确保Ingress NGINX启用SSL Passthrough:在Ingress控制器的Deployment中添加启动参数--enable-ssl-passthrough(该功能默认关闭)。
  2. 让Argo CD Server使用Let's Encrypt证书:
    • 编辑argocd-server Deployment,挂载cert-manager生成的证书secret:
      volumes:
      - name: tls-cert
        secret:
          secretName: argocd-tls
          items:
          - key: tls.crt
            path: tls.crt
          - key: tls.key
            path: tls.key
      volumeMounts:
      - mountPath: /app/config/tls
        name: tls-cert
      
    • 编辑argocd-cm ConfigMap,指定证书路径:
      data:
        server.tls.config: |
          certFile: /app/config/tls/tls.crt
          keyFile: /app/config/tls/tls.key
      

3. 解决重定向循环问题

移除backend-protocol: HTTPS后出现循环的原因是:Argo CD Server强制HTTPS重定向,但Ingress用HTTP连接后端,后端返回HTTPS重定向指令,Ingress转发给浏览器后,浏览器再次请求HTTPS,Ingress又用HTTP连接后端,形成循环。通过上述两种方案配置后,这个问题会自动解决。

内容的提问来源于stack exchange,提问作者waseem mir

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 20:20:31