Default Policy Behavior for OIDC Users
When an OIDC provider successfully authenticates a user but provides no group memberships, Argo CD evaluates the user against the policy.default setting in the argocd-rbac-cm ConfigMap. Because the user does not match any specific role mappings defined in the policy.csv section, they are treated as a generic authenticated user and assigned the permissions defined by the default policy.
The Most Restrictive Default Value
To ensure that authenticated users have zero permissions until a role is explicitly granted, the most restrictive value for policy.default is:
policy.default: ""
Setting this value to an empty string (or omitting any permission‑granting role) ensures that no baseline permissions are inherited. In this state, a user who is authenticated via OIDC but belongs to no mapped groups will be unable to view applications, clusters, or settings within the Argo CD console.
Implementation and Verification
To apply the most restrictive policy, update the argocd-rbac-cm ConfigMap in the namespace where Argo CD is installed (typically argocd).
- Update the ConfigMap:
kubectl edit cm argocd-rbac-cm -n argocd
Ensure the data section contains policy.default: "".
- Verify Access:
Log in with an OIDC account that has no assigned roles. The UI should load, but the user should encounter "Permission Denied" errors when attempting to access any resources.
- Test Explicit Grant:
Add a specific mapping in
policy.csv for that user or a group they belong to (e.g., g, my-group, role:readonly) to verify that explicit roles still override the empty default.
Assumptions and Constraints
This behavior assumes you are using the standard Argo CD RBAC engine. If you have integrated an external authorization service (such as Open Policy Agent), the policy.default setting in the ConfigMap may be bypassed or superseded by the external logic. We assume the use of Argo CD v2.x; earlier versions may handle empty strings differently, though the "deny-all" principle remains the security baseline.
Diagnostic Detail Needed: Are you utilizing a custom --auth-policy or an external authorization provider? If so, the argocd-rbac-cm settings may be ignored.