Skip to content
20 changes: 19 additions & 1 deletion argocd-operator/controllers/argocd/deployment.go
Original file line number Diff line number Diff line change
Expand Up @@ -1339,7 +1339,25 @@ func BuildTLSArgsFromClusterTLSProfile(centralTLSConfig tlsProfile.TLSConfigProf
args = append(args, "--tlsminversion", v)
}
if ciphers := argoutil.MapCipherSuites(centralTLSConfig.Ciphers); len(ciphers) > 0 {
args = append(args, "--tlsciphers", strings.Join(ciphers, ":"))
// Go does not allow configuring TLS 1.3 cipher suites.
// Only filter them when TLS versions below 1.3 are used.
if centralTLSConfig.MinVersion != "VersionTLS13" {
tls13Ciphers := map[string]bool{
"TLS_AES_128_GCM_SHA256": true,
"TLS_AES_256_GCM_SHA384": true,
"TLS_CHACHA20_POLY1305_SHA256": true,
}
filtered := make([]string, 0, len(ciphers))
for _, cipher := range ciphers {
if !tls13Ciphers[cipher] {
filtered = append(filtered, cipher)
}
}
ciphers = filtered
}
if len(ciphers) > 0 {
args = append(args, "--tlsciphers", strings.Join(ciphers, ":"))
}
}
return args
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -135,6 +135,10 @@ var _ = Describe("Validate Deployment Env Args For TLS Configuration", Label("op
Spec: argov1beta1api.ArgoCDSpec{},
}
argo.Spec.ImageUpdater.Enabled = true
argo.Spec.ImageUpdater.Env = append(argo.Spec.ImageUpdater.Env, corev1.EnvVar{
Name: "ENABLE_WEBHOOK",
Value: "true",
})
Expect(c.Create(ctx, argo)).To(Succeed())
By("waiting for ArgoCD to be available")
Eventually(func() error {
Expand Down
Loading