apiVersion: v1
kind: Secret
metadata:
name: private-repo
namespace: openshift-operators
labels:
argocd.argoproj.io/secret-type: repository
stringData:
type: git
url: git@github.com:mbaldessari/mcg-private.git
sshPrivateKey: |
-----BEGIN OPENSSH PRIVATE KEY-----
a3...
...
...
-----END OPENSSH PRIVATE KEY-----Deploying patterns from private repositories
You can deploy patterns from git repositories that are either password-protected or secured with an SSH key.
Using an SSH key
To deploy a pattern from an SSH-secured private repository, create a secret for repository access and then reference it in your pattern’s Custom Resource.
Create a secret for repository access
Generate a secret containing the credentials for accessing your repository. This secret should be formatted according to ArgoCD’s declarative setup guidelines.
This secret can now be created with the bootstrap_secrets feature like so:
version: "2.0"
bootstrap_secrets:
- name: private-repo
targetNamespaces:
- openshift-operators
labels:
argocd.argoproj.io/secret-type: repository
fields:
- name: type
value: git
- name: sshPrivateKey
value: |
-----BEGIN OPENSSH PRIVATE KEY-----
a3...
...
...
-----END OPENSSH PRIVATE KEY-----
- name: url
value: git@github.com:mbaldessari/mcg-private.gitDeploy the pattern with the secret
Reference the secret you created by passing TOKEN_SECRET and TOKEN_NAMESPACE to the install command:
./pattern.sh make TOKEN_SECRET=private-repo TOKEN_NAMESPACE=openshift-operators installThis command assumes that the private-repo secret exists and that the origin remote of the repository points to git@github.com:mbaldessari/mcg-private.git as specified in the secret. The install sets the tokenSecret and tokenSecretNamespace fields on the pattern’s Custom Resource, which ensures that all Argo instances can access the private repository.
If you need to create the pattern CR manually instead, set those fields directly:
apiVersion: gitops.hybrid-cloud-patterns.io/v1alpha1
kind: Pattern
metadata:
name: pattern-sample
namespace: patterns-operator
spec:
clusterGroupName: hub
gitSpec:
targetRepo: git@github.com:mbaldessari/mcg-private.git
targetRevision: private-repo
tokenSecret: private-repo
tokenSecretNamespace: openshift-operatorsSSH known hosts for self-hosted Git servers
When you deploy a pattern from a self-hosted or non-public SSH remote (for example git@controller-0.utility:/var/git/repo.git), both the patterns operator and Argo CD need to verify the server’s SSH host key. Public hosts such as github.com and gitlab.com are already trusted by Argo CD, but private hosts are not.
Without known hosts the operator falls back to accepting any host key, and Argo CD will reject the connection entirely with:
ssh: handshake failed: knownhosts: key is unknownTo fix this, add an sshKnownHosts key to the same secret that holds your sshPrivateKey. The operator will:
Use the known hosts for its own strict host-key verification when cloning the pattern repository.
Set
InitialSSHKnownHostson the managed Argo CD instance so that Argo CD merges your entries intoargocd-ssh-known-hosts-cmalongside the built-in public-host fingerprints.
Obtain the host fingerprints
Run ssh-keyscan against your Git server to collect its public keys:
ssh-keyscan my-git-server.example.comThis prints one or more known_hosts lines. You can also obtain fingerprints from your server administrator.
Add sshKnownHosts to the secret
Include the sshKnownHosts field in the same secret that contains sshPrivateKey:
apiVersion: v1
kind: Secret
metadata:
name: private-repo
namespace: openshift-operators
labels:
argocd.argoproj.io/secret-type: repository
stringData:
type: git
url: git@my-git-server.example.com:org/repo.git
sshPrivateKey: |
-----BEGIN OPENSSH PRIVATE KEY-----
a3...
...
-----END OPENSSH PRIVATE KEY-----
sshKnownHosts: |
my-git-server.example.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA...
my-git-server.example.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQA...Using the bootstrap_secrets feature:
version: "2.0"
bootstrap_secrets:
- name: private-repo
targetNamespaces:
- openshift-operators
labels:
argocd.argoproj.io/secret-type: repository
fields:
- name: type
value: git
- name: url
value: git@my-git-server.example.com:org/repo.git
- name: sshPrivateKey
value: |
-----BEGIN OPENSSH PRIVATE KEY-----
a3...
...
-----END OPENSSH PRIVATE KEY-----
- name: sshKnownHosts
value: |
my-git-server.example.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA...
my-git-server.example.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQA...Then deploy as usual:
./pattern.sh make TOKEN_SECRET=private-repo TOKEN_NAMESPACE=openshift-operators installBehavior details
Argo CD’s default known hosts (github.com, gitlab.com, bitbucket.org, ssh.dev.azure.com) are always preserved. Your entries are merged with them, not replaced.
The operator re-applies the known hosts on every reconcile, so if
argocd-ssh-known-hosts-cmdrifts, it will be corrected automatically.If
sshKnownHostsis not present in the secret, the operator falls back to accepting any host key for its own clone operations. Argo CD will still enforce its default known hosts.For public Git hosting services you do not need
sshKnownHosts— onlysshPrivateKeyis required.
Using a GitLab private repository with a PAT
First, make sure your PAT has at least Read and Download permissions for your private repository.
As with the SSH example above, create a secret before running the install:
apiVersion: v1
kind: Secret
metadata:
name: private-repo
namespace: openshift-operators
labels:
argocd.argoproj.io/secret-type: repository
stringData:
type: git
url: https://gitlab.com/dminnear-rh/mcg-private.git
username: oauth2
password: glpat-xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxUsing the bootstrap_secrets feature, this can be created as follows:
version: "2.0"
bootstrap_secrets:
- name: private-repo
targetNamespaces:
- openshift-operators
labels:
argocd.argoproj.io/secret-type: repository
fields:
- name: type
value: git
- name: url
value: https://gitlab.com/dminnear-rh/mcg-private.git
- name: username
value: oauth2
- name: password
value: glpat-xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxThe username must be oauth2, not your GitLab handle. |
Then reference the secret in the install:
./pattern.sh make TOKEN_SECRET=private-repo TOKEN_NAMESPACE=openshift-operators install