# ArgoCD Installation on the Kubernetes

<div data-node-type="callout">
<div data-node-type="callout-emoji">💡</div>
<div data-node-type="callout-text">At the time of writing this blog, the latest version available on github was Kubernetes available is 1.28.3, ArgoCD -2.8.6 and <strong><em>Calico</em></strong> Open Source v3.26.3, Ubuntu 23.10, Helm - 3.13.1</div>
</div>

<div data-node-type="callout">
<div data-node-type="callout-emoji">💡</div>
<div data-node-type="callout-text">What I tested is Kubernetes - 1.26.10, ArgoCD - 2.8.4 and Calico - 3.26.3, Ubuntu - 22.4.03, Helm - 3.13.1</div>
</div>

<div data-node-type="callout">
<div data-node-type="callout-emoji">💡</div>
<div data-node-type="callout-text">Observed many issues at the time of installing the ArgoCD with Kubernetes, ArgoCD, Redis, Calico Networking issues, coredns issues, etc. So, took a lot of time to find to strike the right balance and try and test why. This Blog is for those who can just follow along (fingers crossed!!, as I have installed this way thrice to see, to check the validity of the blog)</div>
</div>

<div data-node-type="callout">
<div data-node-type="callout-emoji">💡</div>
<div data-node-type="callout-text">In this blog, we are going to install ArgoCD in Kubernetes as a pod which is generally the standard practice.</div>
</div>

### Pre-requisites

Make sure that Git, K8s, Calic, Helm are already installed

1. Test the Networking is it working fine or not in the current Kubernetes, because ArgoCD will heavily rely on it.
    
    Make sure that the KUBECONFIG environment variable is already configured on your system
    

```bash
echo $KUBECONFIG
```

1. Ports --- Keep an eye on these ports (Make sure that they are not used by other software or if required check if the firewall is blocking them, some of them are Inbound and some of them are outbound ports, Make sure, you firewalled the rules properly) --
    

* *Kubernetes - 2379, 2380, 6443, 10250, 10255, 10256, 10257, 10259, 30000-32767(Node Ports)*
    
* *Calico and ArgoCD- 5556,5557,5558,6379,6443,7000,8080,8081,8082,8084,9001, 5473, 4789(UDP), 179*
    

1. ```bash
    kubectl get pods -o wide --all-namespaces
    ```
    

* When you run the above command, you should see all the pods from all the namespaces along the nodes where they are deployed. This command should work as expected on all the nodes connected in the Kubernetes
    

1. In the master - create a yaml file named dnsutils
    

```yaml
apiVersion: v1
kind: Pod
metadata:
  name: dnsutils
  namespace: default
spec:
  containers:
  - name: dnsutils
    image: k8s.gcr.io/e2e-test-images/jessie-dnsutils:1.3
    command:
      - sleep
      - "3600"
    imagePullPolicy: IfNotPresent
  restartPolicy: Always
```

Save it and run *kubectl apply -f dnsutils.yaml*

Run the following command

```bash
kubectl exec -i -t dnsutils -- nslookup kubernetes.default
```

if you see the error as

*\*\*\* Can't find kubernetes.svc.cluster.local: No answer*

then restart the pods of Kube-Proxy (once it's done), CoreDNS pods (once it's done) then Calico Pods. (You can observe that, some pods, shifted from the master to the worker nodes which were the pods that were getting blocked in the communication)

How to restart - kubectl delete -n &lt;namespace of the pod&gt; pods &lt;pod name&gt;

they will be automatically restarted because they come under replica sets or deployments or Statefulsets

Run the following command

```bash
kubectl exec -i -t dnsutils -- nslookup kubernetes.default
```

this time, you should be seeing *Name: kubernetes.default.svc.cluster.local*

if you do, then you are in luck to go the next steps, If not and still have some issues here in this step, The Problem can persist in Networking and configuration, please look at the Calico or CoreDNS areas and also check the permissions, read the logs!!

to check the issues in the coredns pods

```bash
kubectl logs --namespace=kube-system -l k8s-app=kube-dns
```

If you are still finding issues - then

Don't know why, by some users did have luck, in seeing the output when deleting the following network policies

```bash
kubectl delete networkpolicy argocd-redis-network-policy
kubectl delete networkpolicy argocd-server-network-policy
```

once that is done, restart all the pods then try the above command kubectl exec command provided above.

Lastly, try this!!, Written by K8s Guys !! , Excellent Debugging Process - [Link](https://kubernetes.io/docs/tasks/administer-cluster/dns-debugging-resolution/)

Once you can see the *kubernetes.default.svc.cluster.local as the output for kubectl exec -it dnsutils --nslookup kubernetes.default command, then only perform the next steps. Remember !! this command should work as expected even when run on the other nodes.*

### ArgoCD Installation

```bash
kubectl create namespace argocd
```

```bash
kubectl apply -n argocd -f https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml
```

I set it to NodePort process (you can set it to [port forward](https://argo-cd.readthedocs.io/en/stable/getting_started/) process if you want or if you have a load balancer already, you can set it to it)

```bash
kubectl patch svc argocd-server -n argocd -p '{"spec": {"type": "NodePort"}}'
```

### Installing ARGO CD CLI

```bash
curl -LO https://github.com/argoproj/argo-cd/releases/latest/download/argocd-linux-amd64
```

```bash
chmod +x argocd-linux-amd64
sudo mv argocd-linux-amd64 /usr/local/bin/argocd
chown <currentusername>:<groupname> /usr/local/bin/argocd
```

Now let's run the command to check the default password, provided by the ArgoCD

```bash
argocd admin initial-password -n argocd 
```

Node down the passphrase provided by it.

As we set it to NodePort, let's see which port it is set to

```bash
kubectl describe svc argocd-server -n argocd
```

In the output of the above command, we can see the HTTP and HTTPS NodePorts.

Now Type

```bash
argocd login <your server public ip>:<node port> --insecure
```

observe that it will ask you for a username and password, once you provide them, it will show as login updated successfully.

Now change the password as shown below

```bash
argocd account update-password
```

Once, you change the password from the above step, it checks the context of k8s.

```bash
kubectl config get-contexts -o name
```

```bash
kubectl config set-context --current --namespace=argocd
```

That's it !! head to your browser!! provide the &lt;server public ip&gt;:&lt;nodeport&gt; , once asked , provide username and password!! you are good to go!!
