How to Configure ArgoCD SSO with AWS IAM Identity Center Using Dex SAML

A technical guide details how to integrate ArgoCD single sign-on with AWS IAM Identity Center using ArgoCD's built-in Dex as a SAML service provider. The setup works with both IAM Identity Center's native directory and external identity providers such as Google, requiring no client secrets since trust is established via certificate. Key configuration steps include creating a custom SAML 2.0 application in Identity Center, mapping user attributes, and updating ArgoCD's config map with the SSO URL and certificate data. The guide highlights several non-obvious pitfalls, including the need to set the Subject NameID format to 'persistent' and ensuring the SAML audience matches the entityIssuer to avoid cryptic errors. Once SSO is verified, the built-in local admin account can be disabled to enforce identity-provider-only access.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in