12_get_argocd_password.yml - Usage Guide
Purpose
This playbook reads the admin password that Argo CD creates automatically on first install (argocd-initial-admin-secret), base64-decodes it, and reports it. It is read-only (it does not modify the secret; it only reads it).
Requirements
- Runs on the first control-plane node with
kubectlaccess (the first host in themaster/singlenodegroup). - Argo CD must be installed in the
argocdnamespace andargocd-initial-admin-secretmust not have been deleted yet. If the password was changed and this secret was deleted (Argo CD’s recommended practice), the playbook detects that and prints a clear warning — it cannot recover the current password.
How to run
ansible-playbook -i inventories/musteri_a/hosts.ini playbooks/12_get_argocd_password.yml
Sample output
TASK [ArgoCD admin password report (when: password must be retrievable)] *******
ok: [203.0.113.10] => {
"msg": "ArgoCD admin password: xK4mQ9vR2wZ7tPa1 (username: admin, service type: NodePort). This is the one-time password created at initial install; Argo CD's official recommendation is to change it after first login and delete this secret with 'kubectl -n argocd delete secret argocd-initial-admin-secret'."
}
Notes
- If the service type is
NodePort, the Argo CD UI is reached at<node-ip>:<nodeport>; runkubectl -n argocd get svc argocd-serverfor the exact port. - If the service type is
ClusterIP, there is no direct external access; usekubectl port-forwardor an Ingress. - This playbook writes the password in plaintext to Ansible output (visible in the terminal/logs); in a sensitive environment, watch where the output is stored/logged.