Why is ArgoCD confusing GitHub.com with my own public IP?

Viewed 537

I have just set up a kubernetes cluster on bare metal using kubeadm, Flannel and MetalLB. Next step for me is to install ArgoCD.

I installed the ArgoCD yaml from the "Getting Started" page and logged in.

When adding my Git repositories ArgoCD gives me very weird error messages: enter image description here The error message seems to suggest that ArgoCD for some reason is resolving github.com to my public IP address (I am not exposing SSH, therefore connection refused).

I can not find any reason why it would do this. When using https:// instead of SSH I get the same result, but on port 443.

I have put a dummy pod in the same namespace as ArgoCD and made some DNS queries. These queries resolved correctly.

What makes ArgoCD think that github.com resolves to my public IP address?

EDIT:

I have also checked for network policies in the argocd namespace and found no policy that was restricting egress.

I have had this working on clusters in the same network previously and have not changed my router firewall since then.

2 Answers

I solved my problem!

My /etc/resolv.conf had two lines that caused trouble:

domain <my domain>
search <my domain>

These lines were put there as a step in the installation of my host machine's OS that I did not realize would affect me in this way. After removing these lines, everything is now working perfectly.

Multiple people told me to check resolv.conf, but I didn't realize what these two lines did until now.

That looks like argoproj/argo-cd issue 1510, where the initial diagnostic was that the cluster is blocking outbound connections to GitHub. And it suggested to check the egress configuration.

Yet, the issue was resolved with an ingress rule configuration:

need to define in values.yaml.
argo-cd default provide subdomain but in our case it was /argocd

ingress:
  enabled: true
  annotations:
    kubernetes.io/ingress.class: nginx
    nginx.ingress.kubernetes.io/backend-protocol: HTTP
    nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
    nginx.ingress.kubernetes.io/rewrite-target: /
  path: /argocd
  hosts:
    - www.example.com

and this I have defined under templates >> argocd-server-deployment.yaml

containers: 
  - name: argocd-server 
    image: {{ .Values.server.image.repository }}:{{ .Values.server.image.tag }} 
    imagePullPolicy: {{ .Values.server.image.pullPolicy }} 
    command: 
      - argocd-server 
      - --staticassets - /shared/app - --repo-server - argocd-repo-server:8081 - --insecure - --basehref - /argocd

The same case includes an instance very similar to yours:

https://user-images.githubusercontent.com/48730712/92177232-b9839900-ee5d-11ea-844e-9a20c8e8ee4b.png

In any case, do check your git configuration (git config -l) as seen in the ArgoCD cluster, to look for any insteadOf which would change automatically github.com into a local URL (as seen here)

Related