Argo CD
Argo CD can use an existing OpenID Connect (OIDC) provider directly, without its bundled Dex. With Casdoor as the provider, users sign in to the Argo CD UI and CLI with their Casdoor account, and Casdoor groups decide what they can do.
Create the application in Casdoor
-
In the Casdoor admin console, open the organization of your users and add an application, or open an existing one.
-
Add both callbacks to Redirect URLs:
https://argocd.example.com/auth/callback
http://localhost:8085/auth/callbackThe second one is for
argocd login --ssofrom the CLI. -
On the OIDC/OAuth tab, set Token group format to
Name (group), so groups arrive asargocd-adminsinstead ofmy-org/argocd-admins. Keep Token format at the defaultJWT: Argo CD reads groups from the ID token, and the default format carries them there. -
Save, and note the Client ID and Client secret.
Configure Argo CD
-
Store the client secret in the
argocd-secretSecret:kubectl -n argocd patch secret argocd-secret \
--patch='{"stringData": {"oidc.casdoor.clientSecret": "<your-client-secret>"}}' -
Add Casdoor to the
argocd-cmConfigMap:apiVersion: v1
kind: ConfigMap
metadata:
name: argocd-cm
namespace: argocd
data:
url: https://argocd.example.com
oidc.config: |
name: Casdoor
issuer: https://door.example.com
clientID: <your-client-id>
clientSecret: $oidc.casdoor.clientSecret
requestedScopes: ["openid", "profile", "email"]
enablePKCEAuthentication: trueurl: The public URL of Argo CD.issuer: The URL of Casdoor, without a trailing slash. It must be exactly theissuershown athttps://door.example.com/.well-known/openid-configuration.$oidc.casdoor.clientSecret: Reads the secret you stored in the previous step.
-
Grant roles to Casdoor groups in the
argocd-rbac-cmConfigMap. This example gives members ofargocd-adminsfull access and everyone else read-only access:apiVersion: v1
kind: ConfigMap
metadata:
name: argocd-rbac-cm
namespace: argocd
data:
policy.default: role:readonly
policy.csv: |
g, argocd-admins, role:admin
scopes: "[groups]"
Verify the result
-
Open Argo CD. The sign-in page shows Log in via Casdoor.
-
Click it and sign in to Casdoor as a member of
argocd-admins. Argo CD opens with full access. -
From the CLI, run:
argocd login argocd.example.com --sso
argocd account get-user-infoThe output lists the user's groups, for example
Groups: argocd-admins.
Troubleshooting
| Symptom | Cause and fix |
|---|---|
A member of argocd-admins only gets read-only access | The group arrives as my-org/argocd-admins. Set Token group format to Name (group), or use the full value in policy.csv. Users have to sign in again to pick up group changes. |
| Sign-in fails with an issuer error | issuer differs from the issuer in Casdoor's discovery document. Set origin in Casdoor's conf/app.conf to its public URL and use the same value. |
| The CLI login fails with a redirect error | Add http://localhost:8085/auth/callback to the application's Redirect URLs. |
See also
- User management in the Argo CD documentation
- Kubernetes