From 1719227b5f5005467d14d82793500bfd55cc13f3 Mon Sep 17 00:00:00 2001 From: akhil nittala Date: Sun, 4 Oct 2026 22:10:03 +0530 Subject: [PATCH 1/4] fix: Image Updater fails to start with TLS 1.3 cipher suites when cluster TLS profile uses TLS 1.2 minimum Signed-off-by: akhil nittala --- .../controllers/argocd/deployment.go | 33 ++++++ .../controllers/argocd/deployment_test.go | 102 ++++++++++++++++++ .../controllers/argocd/image_updater.go | 2 +- 3 files changed, 136 insertions(+), 1 deletion(-) diff --git a/argocd-operator/controllers/argocd/deployment.go b/argocd-operator/controllers/argocd/deployment.go index d50bb6eea9b..2427e283ff0 100644 --- a/argocd-operator/controllers/argocd/deployment.go +++ b/argocd-operator/controllers/argocd/deployment.go @@ -1517,3 +1517,36 @@ func removeVolumeMount(volumeMounts []corev1.VolumeMount, name string) []corev1. } return volumeMounts } + +// BuildImageUpdaterTLSArgsFromClusterTLSProfile builds the command line arguments for the ArgoCD Image Updater components based on the cluster's TLS profile configuration. +func BuildImageUpdaterTLSArgsFromClusterTLSProfile(centralTLSConfig tlsProfile.TLSConfigProfile) []string { + var args []string + if centralTLSConfig.DisableClusterTLSProfile { + return nil + } + if v := argoutil.TLSProtocolVersionString(centralTLSConfig.MinVersion); v != "" { + args = append(args, "--tlsminversion", v) + } + if ciphers := argoutil.MapCipherSuites(centralTLSConfig.Ciphers); len(ciphers) > 0 { + // Go does not allow configuring TLS 1.3 cipher suites. + // Only filter them when TLS versions below 1.3 are used. + if centralTLSConfig.MinVersion != "VersionTLS13" { + tls13Ciphers := map[string]bool{ + "TLS_AES_128_GCM_SHA256": true, + "TLS_AES_256_GCM_SHA384": true, + "TLS_CHACHA20_POLY1305_SHA256": true, + } + filtered := make([]string, 0, len(ciphers)) + for _, cipher := range ciphers { + if !tls13Ciphers[cipher] { + filtered = append(filtered, cipher) + } + } + ciphers = filtered + } + if len(ciphers) > 0 { + args = append(args, "--tlsciphers", strings.Join(ciphers, ":")) + } + } + return args +} diff --git a/argocd-operator/controllers/argocd/deployment_test.go b/argocd-operator/controllers/argocd/deployment_test.go index 0433cacf4b2..31938dd28be 100644 --- a/argocd-operator/controllers/argocd/deployment_test.go +++ b/argocd-operator/controllers/argocd/deployment_test.go @@ -3693,3 +3693,105 @@ func Test_getPromoterInitContainer(t *testing.T) { }) } } + +func TestBuildImageUpdaterTLSArgsFromClusterTLSProfile(t *testing.T) { + tests := []struct { + name string + config tlsProfile.TLSConfigProfile + want []string + }{ + { + name: "TLS profile disabled", + config: tlsProfile.TLSConfigProfile{ + DisableClusterTLSProfile: true, + MinVersion: "VersionTLS12", + }, + want: nil, + }, + { + name: "TLS 1.2", + config: tlsProfile.TLSConfigProfile{ + DisableClusterTLSProfile: false, + MinVersion: "VersionTLS12", + }, + want: []string{ + "--tlsminversion", + "1.2", + }, + }, + { + name: "TLS 1.3", + config: tlsProfile.TLSConfigProfile{ + DisableClusterTLSProfile: false, + MinVersion: "VersionTLS13", + }, + want: []string{ + "--tlsminversion", + "1.3", + }, + }, + { + name: "empty configuration", + config: tlsProfile.TLSConfigProfile{ + DisableClusterTLSProfile: false, + }, + want: nil, + }, + { + name: "unknown TLS version", + config: tlsProfile.TLSConfigProfile{ + DisableClusterTLSProfile: false, + MinVersion: "InvalidTLSVersion", + }, + want: nil, + }, + { + name: "TLS 1.3 ciphers are preserved for TLS 1.3", + config: tlsProfile.TLSConfigProfile{ + DisableClusterTLSProfile: false, + MinVersion: "VersionTLS13", + Ciphers: []string{ + "TLS_AES_128_GCM_SHA256", + "TLS_AES_256_GCM_SHA384", + "TLS_CHACHA20_POLY1305_SHA256", + }, + }, + want: []string{ + "--tlsminversion", + "1.3", + "--tlsciphers", + "TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256", + }, + }, + { + name: "only TLS 1.3 ciphers with TLS 1.2", + config: tlsProfile.TLSConfigProfile{ + DisableClusterTLSProfile: false, + MinVersion: "VersionTLS12", + Ciphers: []string{ + "TLS_AES_128_GCM_SHA256", + "TLS_AES_256_GCM_SHA384", + "TLS_CHACHA20_POLY1305_SHA256", + }, + }, + want: []string{ + "--tlsminversion", + "1.2", + }, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + got := BuildImageUpdaterTLSArgsFromClusterTLSProfile(tt.config) + + if !reflect.DeepEqual(got, tt.want) { + t.Errorf( + "BuildImageUpdaterTLSArgsFromClusterTLSProfile() = %v, want %v", + got, + tt.want, + ) + } + }) + } +} diff --git a/argocd-operator/controllers/argocd/image_updater.go b/argocd-operator/controllers/argocd/image_updater.go index 391cbf42f0f..0bb3f0f2fde 100644 --- a/argocd-operator/controllers/argocd/image_updater.go +++ b/argocd-operator/controllers/argocd/image_updater.go @@ -715,7 +715,7 @@ func (r *ReconcileArgoCD) reconcileImageUpdaterDeployment(cr *argoproj.ArgoCD, s } args := []string{"run"} - imageUpdaterTLSProfileArguments := BuildTLSArgsFromClusterTLSProfile(r.CentralTLSConfigProfile) + imageUpdaterTLSProfileArguments := BuildImageUpdaterTLSArgsFromClusterTLSProfile(r.CentralTLSConfigProfile) args = append(args, imageUpdaterTLSProfileArguments...) podSpec.Containers = []corev1.Container{{ From d00fa42514004c31016a68f3047e9856f9dc7e7d Mon Sep 17 00:00:00 2001 From: akhil nittala Date: Mon, 5 Oct 2026 20:30:58 +0530 Subject: [PATCH 2/4] fix: Image Updater fails to start with TLS 1.3 cipher suites when cluster TLS profile uses TLS 1.2 minimum Signed-off-by: akhil nittala --- .../controllers/argocd/deployment.go | 53 +++++++------------ .../controllers/argocd/image_updater.go | 2 +- 2 files changed, 20 insertions(+), 35 deletions(-) diff --git a/argocd-operator/controllers/argocd/deployment.go b/argocd-operator/controllers/argocd/deployment.go index 2427e283ff0..b89e48556e8 100644 --- a/argocd-operator/controllers/argocd/deployment.go +++ b/argocd-operator/controllers/argocd/deployment.go @@ -1339,7 +1339,25 @@ func BuildTLSArgsFromClusterTLSProfile(centralTLSConfig tlsProfile.TLSConfigProf args = append(args, "--tlsminversion", v) } if ciphers := argoutil.MapCipherSuites(centralTLSConfig.Ciphers); len(ciphers) > 0 { - args = append(args, "--tlsciphers", strings.Join(ciphers, ":")) + // Go does not allow configuring TLS 1.3 cipher suites. + // Only filter them when TLS versions below 1.3 are used. + if centralTLSConfig.MinVersion != "VersionTLS13" { + tls13Ciphers := map[string]bool{ + "TLS_AES_128_GCM_SHA256": true, + "TLS_AES_256_GCM_SHA384": true, + "TLS_CHACHA20_POLY1305_SHA256": true, + } + filtered := make([]string, 0, len(ciphers)) + for _, cipher := range ciphers { + if !tls13Ciphers[cipher] { + filtered = append(filtered, cipher) + } + } + ciphers = filtered + } + if len(ciphers) > 0 { + args = append(args, "--tlsciphers", strings.Join(ciphers, ":")) + } } return args } @@ -1517,36 +1535,3 @@ func removeVolumeMount(volumeMounts []corev1.VolumeMount, name string) []corev1. } return volumeMounts } - -// BuildImageUpdaterTLSArgsFromClusterTLSProfile builds the command line arguments for the ArgoCD Image Updater components based on the cluster's TLS profile configuration. -func BuildImageUpdaterTLSArgsFromClusterTLSProfile(centralTLSConfig tlsProfile.TLSConfigProfile) []string { - var args []string - if centralTLSConfig.DisableClusterTLSProfile { - return nil - } - if v := argoutil.TLSProtocolVersionString(centralTLSConfig.MinVersion); v != "" { - args = append(args, "--tlsminversion", v) - } - if ciphers := argoutil.MapCipherSuites(centralTLSConfig.Ciphers); len(ciphers) > 0 { - // Go does not allow configuring TLS 1.3 cipher suites. - // Only filter them when TLS versions below 1.3 are used. - if centralTLSConfig.MinVersion != "VersionTLS13" { - tls13Ciphers := map[string]bool{ - "TLS_AES_128_GCM_SHA256": true, - "TLS_AES_256_GCM_SHA384": true, - "TLS_CHACHA20_POLY1305_SHA256": true, - } - filtered := make([]string, 0, len(ciphers)) - for _, cipher := range ciphers { - if !tls13Ciphers[cipher] { - filtered = append(filtered, cipher) - } - } - ciphers = filtered - } - if len(ciphers) > 0 { - args = append(args, "--tlsciphers", strings.Join(ciphers, ":")) - } - } - return args -} diff --git a/argocd-operator/controllers/argocd/image_updater.go b/argocd-operator/controllers/argocd/image_updater.go index 0bb3f0f2fde..391cbf42f0f 100644 --- a/argocd-operator/controllers/argocd/image_updater.go +++ b/argocd-operator/controllers/argocd/image_updater.go @@ -715,7 +715,7 @@ func (r *ReconcileArgoCD) reconcileImageUpdaterDeployment(cr *argoproj.ArgoCD, s } args := []string{"run"} - imageUpdaterTLSProfileArguments := BuildImageUpdaterTLSArgsFromClusterTLSProfile(r.CentralTLSConfigProfile) + imageUpdaterTLSProfileArguments := BuildTLSArgsFromClusterTLSProfile(r.CentralTLSConfigProfile) args = append(args, imageUpdaterTLSProfileArguments...) podSpec.Containers = []corev1.Container{{ From 8b1681e4421a50a5e368c665d6e558f937841476 Mon Sep 17 00:00:00 2001 From: akhil nittala Date: Mon, 5 Oct 2026 20:31:59 +0530 Subject: [PATCH 3/4] fix: Image Updater fails to start with TLS 1.3 cipher suites when cluster TLS profile uses TLS 1.2 minimum Signed-off-by: akhil nittala --- .../controllers/argocd/deployment_test.go | 102 ------------------ 1 file changed, 102 deletions(-) diff --git a/argocd-operator/controllers/argocd/deployment_test.go b/argocd-operator/controllers/argocd/deployment_test.go index 31938dd28be..0433cacf4b2 100644 --- a/argocd-operator/controllers/argocd/deployment_test.go +++ b/argocd-operator/controllers/argocd/deployment_test.go @@ -3693,105 +3693,3 @@ func Test_getPromoterInitContainer(t *testing.T) { }) } } - -func TestBuildImageUpdaterTLSArgsFromClusterTLSProfile(t *testing.T) { - tests := []struct { - name string - config tlsProfile.TLSConfigProfile - want []string - }{ - { - name: "TLS profile disabled", - config: tlsProfile.TLSConfigProfile{ - DisableClusterTLSProfile: true, - MinVersion: "VersionTLS12", - }, - want: nil, - }, - { - name: "TLS 1.2", - config: tlsProfile.TLSConfigProfile{ - DisableClusterTLSProfile: false, - MinVersion: "VersionTLS12", - }, - want: []string{ - "--tlsminversion", - "1.2", - }, - }, - { - name: "TLS 1.3", - config: tlsProfile.TLSConfigProfile{ - DisableClusterTLSProfile: false, - MinVersion: "VersionTLS13", - }, - want: []string{ - "--tlsminversion", - "1.3", - }, - }, - { - name: "empty configuration", - config: tlsProfile.TLSConfigProfile{ - DisableClusterTLSProfile: false, - }, - want: nil, - }, - { - name: "unknown TLS version", - config: tlsProfile.TLSConfigProfile{ - DisableClusterTLSProfile: false, - MinVersion: "InvalidTLSVersion", - }, - want: nil, - }, - { - name: "TLS 1.3 ciphers are preserved for TLS 1.3", - config: tlsProfile.TLSConfigProfile{ - DisableClusterTLSProfile: false, - MinVersion: "VersionTLS13", - Ciphers: []string{ - "TLS_AES_128_GCM_SHA256", - "TLS_AES_256_GCM_SHA384", - "TLS_CHACHA20_POLY1305_SHA256", - }, - }, - want: []string{ - "--tlsminversion", - "1.3", - "--tlsciphers", - "TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256", - }, - }, - { - name: "only TLS 1.3 ciphers with TLS 1.2", - config: tlsProfile.TLSConfigProfile{ - DisableClusterTLSProfile: false, - MinVersion: "VersionTLS12", - Ciphers: []string{ - "TLS_AES_128_GCM_SHA256", - "TLS_AES_256_GCM_SHA384", - "TLS_CHACHA20_POLY1305_SHA256", - }, - }, - want: []string{ - "--tlsminversion", - "1.2", - }, - }, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - got := BuildImageUpdaterTLSArgsFromClusterTLSProfile(tt.config) - - if !reflect.DeepEqual(got, tt.want) { - t.Errorf( - "BuildImageUpdaterTLSArgsFromClusterTLSProfile() = %v, want %v", - got, - tt.want, - ) - } - }) - } -} From 45c7e105dbccb49cd93484ebe66858f0d5a7ea8b Mon Sep 17 00:00:00 2001 From: akhil nittala Date: Mon, 5 Oct 2026 20:38:33 +0530 Subject: [PATCH 4/4] fix: Image Updater fails to start with TLS 1.3 cipher suites when cluster TLS profile uses TLS 1.2 minimum Signed-off-by: akhil nittala --- ...validate_deployment_Env_Args_For_Tls_Configuration_test.go | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/test/openshift/e2e/ginkgo/sequential/1-143_validate_deployment_Env_Args_For_Tls_Configuration_test.go b/test/openshift/e2e/ginkgo/sequential/1-143_validate_deployment_Env_Args_For_Tls_Configuration_test.go index f69d2a38b29..e7e0db055c5 100644 --- a/test/openshift/e2e/ginkgo/sequential/1-143_validate_deployment_Env_Args_For_Tls_Configuration_test.go +++ b/test/openshift/e2e/ginkgo/sequential/1-143_validate_deployment_Env_Args_For_Tls_Configuration_test.go @@ -135,6 +135,10 @@ var _ = Describe("Validate Deployment Env Args For TLS Configuration", Label("op Spec: argov1beta1api.ArgoCDSpec{}, } argo.Spec.ImageUpdater.Enabled = true + argo.Spec.ImageUpdater.Env = append(argo.Spec.ImageUpdater.Env, corev1.EnvVar{ + Name: "ENABLE_WEBHOOK", + Value: "true", + }) Expect(c.Create(ctx, argo)).To(Succeed()) By("waiting for ArgoCD to be available") Eventually(func() error {