Argo CD Dashboard Access

Accessing web-based dashboards and UIs for applications running within Kubernetes clusters, such as Argo CD, often requires securely bridging your local machine to the cluster’s network. This document outlines two common methods for achieving this: kubectl port-forward and SSH tunneling.

Method 1: Using kubectl port-forward

kubectl port-forward allows you to directly map a local port to a port on a Pod, Service, or Deployment within your Kubernetes cluster. It’s ideal for temporary access during development, debugging, or initial setup, as it does not expose the service to external networks.

kubectl port-forward svc/argocd-server -n argocd 8080:443

Command Breakdown:

  • kubectl port-forward: The command to set up port forwarding.
  • svc/argocd-server: Specifies the target resource, in this case, the argocd-server Service.
  • -n argocd: Specifies the namespace where the Service is located (the Argo CD namespace).
  • 8080:443: Maps local port 8080 to the target Service’s port 443. This means you can access the Argo CD UI by navigating to http://localhost:8080 in your browser.

Method 2: Using an SSH Tunnel

An SSH tunnel can be used to forward traffic from a local port to a port on a remote server, which then forwards it to another destination (e.g., a Kubernetes service or an internal IP). This method is particularly useful if you need to access services that are not directly exposed by kubectl port-forward (e.g., if you need to pass through a bastion host) or if you want a more persistent, secure connection to an internal network.

ssh -L 8080:localhost:8080 user@remote-server

How it Works:

This command sets up a local port forward (-L):

  • 8080: This is the port on your local machine that you will connect to.
  • localhost:8080: This specifies that traffic reaching your local port 8080 should be forwarded to localhost:8080 on the remote-server.
  • user@remote-server: The remote server (e.g., a bastion host or a node in your cluster) through which the tunnel will be established.

As a result, when you open http://localhost:8080 in your browser on your local machine, your traffic is securely tunneled to localhost:8080 on the remote-server. From there, if Argo CD (or another service) is listening on 8080 on that remote-server’s local interface, you will be able to access it.

Common Usage for Argo CD:

If your remote-server has direct network access to the argocd-server service’s ClusterIP, you might modify the command to something like:

ssh -L 8080:argocd-server.argocd.svc.cluster.local:443 user@remote-server

(Replace argocd-server.argocd.svc.cluster.local with the actual internal DNS name or IP of the service if localhost on the remote server isn’t directly forwarding to it).

When to Use Which Method:

  • kubectl port-forward:
    • Pros: Simple, direct, no SSH server required on the target K8s node, automatically handles service discovery.
    • Cons: Temporary (session-bound), only works with services directly accessible within the K8s cluster.
  • SSH Tunnel:
    • Pros: Can tunnel through multiple hops (bastion hosts), more flexible for complex network topologies, potentially more persistent.
    • Cons: Requires an SSH server on the remote host, configuration can be more complex.