diff --git a/argocd-operator/controllers/argocd/deployment.go b/argocd-operator/controllers/argocd/deployment.go index d50bb6eea9b..b89e48556e8 100644 --- a/argocd-operator/controllers/argocd/deployment.go +++ b/argocd-operator/controllers/argocd/deployment.go @@ -1339,7 +1339,25 @@ func BuildTLSArgsFromClusterTLSProfile(centralTLSConfig tlsProfile.TLSConfigProf args = append(args, "--tlsminversion", v) } if ciphers := argoutil.MapCipherSuites(centralTLSConfig.Ciphers); len(ciphers) > 0 { - args = append(args, "--tlsciphers", strings.Join(ciphers, ":")) + // Go does not allow configuring TLS 1.3 cipher suites. + // Only filter them when TLS versions below 1.3 are used. + if centralTLSConfig.MinVersion != "VersionTLS13" { + tls13Ciphers := map[string]bool{ + "TLS_AES_128_GCM_SHA256": true, + "TLS_AES_256_GCM_SHA384": true, + "TLS_CHACHA20_POLY1305_SHA256": true, + } + filtered := make([]string, 0, len(ciphers)) + for _, cipher := range ciphers { + if !tls13Ciphers[cipher] { + filtered = append(filtered, cipher) + } + } + ciphers = filtered + } + if len(ciphers) > 0 { + args = append(args, "--tlsciphers", strings.Join(ciphers, ":")) + } } return args } diff --git a/test/openshift/e2e/ginkgo/sequential/1-143_validate_deployment_Env_Args_For_Tls_Configuration_test.go b/test/openshift/e2e/ginkgo/sequential/1-143_validate_deployment_Env_Args_For_Tls_Configuration_test.go index f69d2a38b29..e7e0db055c5 100644 --- a/test/openshift/e2e/ginkgo/sequential/1-143_validate_deployment_Env_Args_For_Tls_Configuration_test.go +++ b/test/openshift/e2e/ginkgo/sequential/1-143_validate_deployment_Env_Args_For_Tls_Configuration_test.go @@ -135,6 +135,10 @@ var _ = Describe("Validate Deployment Env Args For TLS Configuration", Label("op Spec: argov1beta1api.ArgoCDSpec{}, } argo.Spec.ImageUpdater.Enabled = true + argo.Spec.ImageUpdater.Env = append(argo.Spec.ImageUpdater.Env, corev1.EnvVar{ + Name: "ENABLE_WEBHOOK", + Value: "true", + }) Expect(c.Create(ctx, argo)).To(Succeed()) By("waiting for ArgoCD to be available") Eventually(func() error {