Argo CD + Casdoor

Single sign-on for Argo CD

Argo CD can use an existing OpenID Connect provider directly, without its bundled Dex. With Casdoor, people sign in to the Argo CD UI and CLI with their Casdoor account, and Casdoor groups decide what they can do.

You need a running Casdoor, self-hosted or on Casdoor Cloud. In the examples, replace https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.

Set up Argo CD with Casdoor

  1. 1

    Register Argo CD in Casdoor

    In the Casdoor console, open Applications, add an application for Argo CD, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add these redirect URLs to Redirect URLs:

    • https://argocd.example.com/auth/callback
    • http://localhost:8085/auth/callback

    The second URL is for argocd login --sso from the CLI. To use groups, create them in the application's organization (for example argocd-admins) and add users. Then set Token group format to Name on the same tab, so tokens carry argocd-admins rather than <organization>/argocd-admins.

  2. 2

    Store the client secret

    Put the client secret in the argocd-secret Secret, where oidc.config can reference it.

    kubectl -n argocd patch secret argocd-secret \
      --patch='{"stringData": {"oidc.casdoor.clientSecret": "<client secret>"}}'
  3. 3

    Configure OIDC in argocd-cm

    Add Casdoor to the argocd-cm ConfigMap. Casdoor puts the user's groups in the ID token, which is where Argo CD reads them.

    apiVersion: v1
    kind: ConfigMap
    metadata:
      name: argocd-cm
      namespace: argocd
    data:
      url: https://argocd.example.com
      oidc.config: |
        name: Casdoor
        issuer: https://auth.example.com
        clientID: <client ID>
        clientSecret: $oidc.casdoor.clientSecret
        requestedScopes: ["openid", "profile", "email"]
        enablePKCEAuthentication: true
  4. 4

    Grant permissions by group

    Map Casdoor groups to Argo CD roles in argocd-rbac-cm. Here members of argocd-admins get full access and everyone else can only look.

    apiVersion: v1
    kind: ConfigMap
    metadata:
      name: argocd-rbac-cm
      namespace: argocd
    data:
      policy.default: role:readonly
      policy.csv: |
        g, argocd-admins, role:admin
      scopes: "[groups]"
  5. 5

    Sign in

    The Argo CD login page now has a Log in via Casdoor button, and argocd login argocd.example.com --sso opens Casdoor in the browser.

Good to know

  • Argo CD reads oidc.config changes without a restart, but users have to sign in again to pick up new group memberships.

Argo CD settings are from its documentation as of October 2026 (Argo CD user management). Argo CD is a trademark of its owner.

FAQ

Frequently asked questions

Do I still need Dex?
No. With oidc.config, Argo CD talks to Casdoor directly, and you can leave Dex unconfigured.
Can the argocd CLI sign in through Casdoor?
Yes. argocd login <server> --sso opens the browser and receives the result on http://localhost:8085/auth/callback, which is why that URL is in the Casdoor application.