Skip to content

This is the Stable version of the documentation. The latest version is experimental and under active development. You can use the version selector in the top-right menu to switch versions for this specific page, or click here to go to the latest version's homepage.

ArgoCD Non-Production Environment Installation

ArgoCD (Non-Production) will be installed on 🟦 Non-Production Workload Kubernetes Cluster

  • 📥Ingress Service provided as Kubernetes Ingress Class (IngressClass)
  • 🛡️TLS Certificate for ArgoCD (Non-Production) provided as Kubernetes Secret
    • ArgoCD (Non-Production) will be exposed as HTTPS with Kubernetes Ingress.

To Setup Single Sign-On with Opstella (MUST be performed at the time of installation), you need

  • 📦Opstella Keycloak
    • Your dedicated Keycloak Realm. foobar-opstella ; Please change accordingly
  • 🔑OpenID Connect Credentials: Client ID, Client Secret.

Ensure you have defined and loaded your Global Shell Variables as described in Shell Variables.

  1. Connect to 🟦 Non-Production Workload Kubernetes Cluster ; i.e w/ Kubeconfig File

    Ensure you have defined and loaded your Global Shell Variables as described in Shell Variables.

    Terminal window
    source $HOME/opstella-installation/shell-values/kubernetes/nonprod_cluster.vars.sh
    Terminal window
    export KUBECONFIG="$HOME/opstella-installation/kubeconfigs/nonprod_cluster.yaml"
  2. Export these variables in your terminal before proceeding with the installation.

    Ensure ARGOCD_DOMAIN, K8S_INTERNAL_DOMAIN, K8S_INGRESSCLASS_NAME, K8S_STORAGECLASS_NAME, K8S_INGRESS_TLS_CERTIFICATE_SECRET_NAME are defined as per the Shell Variables guide.

    # OIDC
    export ARGOCD_OIDC_CLIENT_ID="argocd-nonprod"
    export ARGOCD_OIDC_CLIENT_SECRET="CHANGEME"
  3. Create Kubernetes Secret for 🛡️ TLS Certificate for ArgoCD (Non-Production) in Namespace devsecops-system.

    Create one using from .crt and .key file.

    Terminal window
    kubectl create secret tls $K8S_INGRESS_TLS_CERTIFICATE_SECRET_NAME \
    --cert=/path/to/cert/file --key=/path/to/key/file \
    --namespace devsecops-system

    💡 Should return secret/wildcard-${BASE_DOMAIN}-tls created message.

Prepare ArgoCD (Non-Production) Configurations

Section titled “Prepare ArgoCD (Non-Production) Configurations”
  1. Specify OIDC Authentication Information

    Using Opstella Keycloak Information

    • OIDC Issuer Endpoint from Opstella Keycloak Information

      export ARGOCD_OIDC_ISSUER_ENDPOINT="https://${KEYCLOAK_DOMAIN}/realms/${KEYCLOAK_REALM}"
  2. Create Helm Values Configurations

    Terminal window
    cat <<EOF > $BASE_WORKING_DIR/helm-values/argocd-nonprod-full-values.yaml
    ## Server
    server:
    ingress:
    # -- Enable an ingress resource for the Argo CD server
    enabled: true
    # -- Defines which ingress controller will implement the resource
    ingressClassName: ${K8S_INGRESSCLASS_NAME}
    # -- List of ingress hosts
    ## Argo Ingress.
    ## Hostnames must be provided if Ingress is enabled.
    ## Secrets must be manually created in the namespace
    hostname: ${ARGOCD_DOMAIN}
    # -- List of ingress paths
    paths:
    - /
    # -- Ingress path type. One of Exact, Prefix or ImplementationSpecific
    pathType: Prefix
    extraTls:
    - secretName: ${K8S_INGRESS_TLS_CERTIFICATE_SECRET_NAME}
    hosts:
    - ${ARGOCD_DOMAIN}
    configs:
    params:
    # -- Run argocd-server without its own TLS. Keep this `true`.
    # TLS is terminated at the Ingress with ${K8S_INGRESS_TLS_CERTIFICATE_SECRET_NAME}. Setting it
    # back to `false` makes argocd-server serve TLS and redirect HTTP to HTTPS behind an Ingress
    # that already did so, which shows up as a redirect loop in the browser.
    server.insecure: true
    cm:
    url: "https://${ARGOCD_DOMAIN}"
    oidc.config: |
    name: Opstella
    issuer: "${ARGOCD_OIDC_ISSUER_ENDPOINT}"
    clientID: "${ARGOCD_OIDC_CLIENT_ID}"
    clientSecret: "${ARGOCD_OIDC_CLIENT_SECRET}"
    #Add rootCA if needed
    #rootCA: |
    # -----BEGIN CERTIFICATE-----
    # ... encoded certificate data here ...
    # -----END CERTIFICATE-----
    requestedIDTokenClaims:
    groups:
    essential: true
    requestedScopes:
    - openid
    - profile
    - email
    rbac:
    scopes: "[groups]"
    EOF
  1. Add ArgoCD Helm Repository

    Terminal window
    # Add Helm Repository
    helm repo add argo https://argoproj.github.io/argo-helm
    helm repo update
  2. Install a Helm Release with specific Helm Chart Version --version 7.4.2 (App Version: v2.12.0)

    Terminal window
    helm install argocd-nonprod argo/argo-cd --version 7.4.2 \
    --namespace devsecops-system \
    -f $HOME/opstella-installation/helm-values/argocd-nonprod-full-values.yaml

ArgoCD generates a random password for the local admin account at first install and stores it in the argocd-initial-admin-secret Secret.

Terminal window
kubectl get secret argocd-initial-admin-secret \
--namespace devsecops-system \
-o jsonpath='{.data.password}' | base64 -d; echo
  • Username is admin.
  • Store the password in your password vault before changing it — ArgoCD deletes argocd-initial-admin-secret as soon as the admin password is changed.
  1. Get Pod Status - ArgoCD

    Terminal window
    kubectl get pods -n devsecops-system

    ArgoCD should be Running

    NAME READY STATUS RESTARTS AGE
    ... (deducted)
    argocd-application-controller-0 1/1 Running 0 Xd
    argocd-applicationset-controller-XXXXXX-YYYYY 1/1 Running 0 Xd
    argocd-dex-server-b6b8bb9f5-g7n8w 1/1 Running 0 Xd
    argocd-notifications-controller-XXXXXX-YYYYY 1/1 Running 0 Xd
    argocd-redis-XXXXXX-YYYYY 1/1 Running 0 Xd
    argocd-repo-server-XXXXXX-YYYYY 1/1 Running 0 Xd
    argocd-server-XXXXXX-YYYYY 1/1 Running 0 Xd
  2. Visit https://${ARGOCD_DOMAIN}

    • It should be accessible.
    • TLS Certificate should be valid and coresponding to your TLS Certificate Installed

  3. Login with Users

  4. Verify the OIDC Configuration was rendered

    A malformed oidc.config does not stop ArgoCD from starting — the LOG IN VIA OPSTELLA button silently disappears instead. Confirm the block scalar survived envsubst:

    Terminal window
    kubectl get configmap argocd-cm \
    --namespace devsecops-system \
    -o jsonpath='{.data.oidc\.config}'; echo

    issuer, clientID and clientSecret must all be non-empty.

  5. (Optional) Verify from inside the cluster

    If the ArgoCD hostname is not reachable from your workstation yet (DNS or load balancer not in place), verify through the Ingress from inside the cluster instead.

    Terminal window
    kubectl get svc --namespace ingress-nginx \
    -o jsonpath='{.items[?(@.spec.type=="ClusterIP")].spec.clusterIP}'; echo
    # argocd-probe.yaml — passes Pod Security Admission level `restricted`
    apiVersion: v1
    kind: Pod
    metadata:
    name: argocd-probe
    spec:
    restartPolicy: Never
    securityContext:
    runAsNonRoot: true
    runAsUser: 65532
    seccompProfile:
    type: RuntimeDefault
    containers:
    - name: curl
    image: curlimages/curl:8.10.1
    securityContext:
    allowPrivilegeEscalation: false
    capabilities:
    drop: ["ALL"]
    command: ["sh", "-c"]
    args:
    - curl -sk -o /dev/null -w "argocd https=%{http_code}\n"
    --resolve $ARGOCD_DOMAIN:443:$INGRESS_CLUSTER_IP
    https://$ARGOCD_DOMAIN/
    Terminal window
    kubectl apply -f argocd-probe.yaml --namespace devsecops-system
    kubectl logs argocd-probe --namespace devsecops-system
    kubectl delete pod argocd-probe --namespace devsecops-system

    💡 Should print argocd https=200.

Finished?

Use the below navigation to proceed