求助:如何通过Istio Ingress Gateway无TLS认证访问ArgoCD?
问题描述
尝试通过Istio Ingress Gateway访问ArgoCD服务器失败,系统自动重定向至HTTPS后页面显示服务器不可达,已尝试多种方案未解决,以下是当前配置,请求协助排查。
启用Istio Sidecar注入
kubectl label namespace argocd istio-injection=enabled
配置ArgoCD Server以“非安全模式”启动
apiVersion: v1 kind: ConfigMap metadata: name: argocd-cmd-params-cm namespace: argocd labels: app.kubernetes.io/name: argocd-cmd-params-cm app.kubernetes.io/part-of: argocd data: server.insecure: "true"
补丁更新ArgoCD Server部署
kubectl patch deployment \ argocd-server \ --namespace argocd \ --type='json' \ -p='[{"op": "replace", "path": "/spec/template/spec/containers/0/args", "value": [ "server", "--auth-mode=server" ]}]'
VirtualService配置
apiVersion: networking.istio.io/v1alpha3 kind: VirtualService metadata: name: argocd-virtual-service namespace: argocd spec: hosts: - argocd.lumik.com gateways: - argocd-gateway http: - route: - destination: host: argocd-server.argocd.svc.cluster.local port: number: 80
Istio Gateway配置
apiVersion: networking.istio.io/v1alpha3 kind: Gateway metadata: name: argocd-gateway namespace: argocd spec: selector: istio: ingressgateway servers: - hosts: - argocd.lumik.com port: name: https number: 443 protocol: HTTPS tls: mode: SIMPLE credentialName: argocd-secret - hosts: - argocd.lumik.com port: name: http number: 80 protocol: HTTP tls: httpsRedirect: true
Istio Destination Rule配置
apiVersion: networking.istio.io/v1alpha3 kind: DestinationRule metadata: name: argocd-server-dtrl namespace: istio-system spec: host: argocd-server.argocd.svc.cluster.local trafficPolicy: tls: mode: DISABLE
内容的提问来源于stack exchange,提问作者Nitin G
相关产品推荐
相关产品推荐

