You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ArgoCD ApplicationSet无法部署嵌套目录下的Kubernetes清单

问题解决方案

1. 优先解决"Permission Denied"权限错误

这是导致清单无法部署、进而引发健康检查错误的核心原因:

  • 配置ArgoCD控制器的Namespace权限:
    确保argocd-application-controller(默认位于argocd命名空间)拥有my-namespace下的资源操作权限,创建对应Role和RoleBinding:
    apiVersion: rbac.authorization.k8s.io/v1
    kind: Role
    metadata:
      name: argocd-deployer
      namespace: my-namespace
    rules:
    - apiGroups: ["", "apps", "rbac.authorization.k8s.io"]
      resources: ["deployments", "services", "serviceaccounts", "pods"]
      verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
    ---
    apiVersion: rbac.authorization.k8s.io/v1
    kind: RoleBinding
    metadata:
      name: argocd-deployer-binding
      namespace: my-namespace
    subjects:
    - kind: ServiceAccount
      name: argocd-application-controller
      namespace: argocd
    roleRef:
      kind: Role
      name: argocd-deployer
      apiGroup: rbac.authorization.k8s.io
    
  • 修正ArgoCD项目权限:
    确保my-project允许部署到my-namespace,并开放所需资源类型:
    apiVersion: argoproj.io/v1alpha1
    kind: AppProject
    metadata:
      name: my-project
      namespace: argocd
    spec:
      destinations:
      - namespace: my-namespace
        server: https://kubernetes.default.svc
      sourceRepos:
      - https://gitlab.com/gitlab/repo.git
      clusterResourceWhitelist:
      - group: '*'
        kind: '*'
      namespaceResourceWhitelist:
      - group: '*'
        kind: '*'
    

2. 优化ApplicationSet配置(保持每个App对应一个Application)

你的原配置逻辑可行,output/*会匹配所有app子目录,ArgoCD默认会递归扫描嵌套子目录的清单。调整以下细节:

apiVersion: argoproj.io/v1alpha1
kind: ApplicationSet
metadata:
  name: output-appset
  namespace: argocd  # Application资源应默认部署在argocd命名空间
spec:
  generators:
  - git:
      repoURL: https://gitlab.com/gitlab/repo.git
      revision: HEAD
      directories:
      - path: output/*
  template:
    metadata:
      name: '{{path.basenameNormalized}}'
      namespace: argocd
    spec:
      project: my-project
      source:
        repoURL: https://gitlab.com/gitlab/repo.git
        targetRevision: HEAD
        path: '{{path}}'
        directory:
          recurse: true  # 显式开启递归扫描(默认已开启,可省略)
      destination:
        server: https://kubernetes.default.svc
        namespace: my-namespace
      syncPolicy:
        automated:
          prune: true
          selfHeal: true
        syncOptions:
        - CreateNamespace=true  # 若my-namespace不存在则自动创建

3. 消除"Lua returned an invalid health status"错误

该错误通常随权限问题解决而自动消失,若仍存在:

  • 升级ArgoCD至v2.8+稳定版本,旧版本可能存在健康检查脚本bug
  • 检查argocd-cm ConfigMap中的自定义健康检查配置,若有冲突暂时移除

4. 备选方案:单个Application部署所有清单

若无需每个App单独管理,可直接创建一个Application覆盖整个output目录:

apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: all-output-apps
  namespace: argocd
spec:
  project: my-project
  source:
    repoURL: https://gitlab.com/gitlab/repo.git
    targetRevision: HEAD
    path: output
    directory:
      recurse: true
  destination:
    server: https://kubernetes.default.svc
    namespace: my-namespace
  syncPolicy:
    automated:
      prune: true
      selfHeal: true

内容的提问来源于stack exchange,提问作者parax

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 16:45:18