diff --git a/argocd-operator/controllers/argocd/image_updater.go b/argocd-operator/controllers/argocd/image_updater.go index 391cbf42f0f..89883d6da86 100644 --- a/argocd-operator/controllers/argocd/image_updater.go +++ b/argocd-operator/controllers/argocd/image_updater.go @@ -718,8 +718,11 @@ func (r *ReconcileArgoCD) reconcileImageUpdaterDeployment(cr *argoproj.ArgoCD, s imageUpdaterTLSProfileArguments := BuildTLSArgsFromClusterTLSProfile(r.CentralTLSConfigProfile) args = append(args, imageUpdaterTLSProfileArguments...) + // Command is intentionally not set so that the image's own ENTRYPOINT applies. + // The image updater image runs the manager under tini ("tini -- /manager"), which + // reaps the git child processes the manager forks. Overriding Command with "/manager" + // would make the manager PID 1 and leak zombie git processes (GITOPS-11648). podSpec.Containers = []corev1.Container{{ - Command: []string{"/manager"}, Args: args, Image: selectImageUpdaterImage(cr), ImagePullPolicy: argoutil.GetImagePullPolicy(cr.Spec.ImagePullPolicy), diff --git a/argocd-operator/controllers/argocd/image_updater_test.go b/argocd-operator/controllers/argocd/image_updater_test.go index 5bf50c66c25..02018771303 100644 --- a/argocd-operator/controllers/argocd/image_updater_test.go +++ b/argocd-operator/controllers/argocd/image_updater_test.go @@ -270,8 +270,9 @@ func TestReconcileImageUpdater_CreateDeployments(t *testing.T) { // Ensure the created Deployment has the expected properties assert.Equal(t, deployment.Spec.Template.Spec.ServiceAccountName, sa.Name) + // No Command is expected: the container must inherit the image ENTRYPOINT so that + // tini stays PID 1 and reaps git child processes (GITOPS-11648). want := []v1.Container{{ - Command: []string{"/manager"}, Args: []string{"run"}, Image: argoutil.CombineImageTag(DefaultImageUpdaterImage, DefaultImageUpdaterTag), ImagePullPolicy: v1.PullIfNotPresent,