PRACTICE TRACK / 10 QUESTIONS

ArgoCD
Think it through.

GitOps, ApplicationSets, sync strategies, and multi-cluster.

Choose a question, explain your approach, then reveal the supplied answer. Difficulty labels come from the existing question library.

10 questions

Answers stay closed until you choose to reveal them.

QUESTION 01ArgoCDEasy

What is ArgoCD and how does it implement GitOps?

#
Reveal answer guidance

ArgoCD is a declarative GitOps CD tool for Kubernetes. It continuously monitors a Git repository and syncs the desired state defined in manifests (YAML, Helm, Kustomize) to the cluster. Git is the single source of truth — any drift between Git and the live cluster is detected and can be auto-corrected via Self-Heal. The core loop: watch Git → detect drift → sync to cluster → report status.

QUESTION 02ArgoCDEasy

What is the difference between Automated and Manual sync policies?

#
Reveal answer guidance

Automated sync: ArgoCD automatically syncs the cluster whenever Git changes are detected. Manual sync: an operator must click Sync or run argocd app sync. Automated sync can optionally enable Prune (delete resources removed from Git) and Self-Heal (revert manual cluster changes back to Git state). For production, use Automated with Prune and Self-Heal disabled initially, then enable gradually.

QUESTION 03ArgoCDMedium

What are Sync Waves and Sync Hooks in ArgoCD?

#
Reveal answer guidance

Sync Waves control resource ordering within a sync — resources with lower wave numbers (e.g., wave -5) apply first, higher waves (e.g., wave 10) apply last. Sync Hooks run Jobs at specific sync phases (PreSync, Sync, PostSync, Skip, SyncFail). Hooks are for db migrations, smoke tests, or pre-sync validation. Annotation: argocd.argoproj.io/sync-wave: "5" and argocd.argoproj.io/hook: PreSync. Hooks replace the deprecated Helm hook pattern.

QUESTION 04ArgoCDMedium

How does ArgoCD handle multi-cluster deployments?

#
Reveal answer guidance

ArgoCD can manage any number of external clusters. Register clusters via argocd cluster add <context> or declaratively in argocd-cm. Applications target specific clusters via spec.destination.server or spec.destination.name. For deploying the same app to many clusters, use an ApplicationSet with cluster generators: generators: - clusters: {selector: {matchLabels: {env: prod}}}. ApplicationSets create one Application per cluster automatically.

QUESTION 05ArgoCDMedium

What is an ApplicationSet and what generators does it support?

#
Reveal answer guidance

ApplicationSet is a template that generates multiple ArgoCD Applications from a single definition. Generators: List (hardcoded values), Cluster (all registered clusters matching labels), Git (directories or files in a repo), SCM Provider (GitHub/GitLab/Bitbucket org repos), Pull Request (auto-creates apps for PRs), Matrix (combine two generators), Merge (merge generator outputs). ApplicationSets are the standard way to manage multi-cluster and multi-service deployments at scale.

QUESTION 06ArgoCDHard

How does ArgoCD RBAC work and how do you configure it for multi-team access?

#
Reveal answer guidance

RBAC is configured in argocd-rbac-cm ConfigMap. Policy format follows Casbin: p, role, resource, action, object. Example: p, team-leads, applications, sync, myproject/*, allow. Resources: applications, projects, clusters, repositories, logs, exec. Actions: get, create, update, delete, sync, override, action/* (for custom resource actions). Roles map to OIDC groups via argocd-cm: data: scopes: [groups, email]. For full isolation, create separate Projects per team — an ArgoCD Project restricts which clusters, namespaces, and Git sources an Application can use.

QUESTION 07ArgoCDHard

How do you manage secrets in ArgoCD without storing them in Git?

#
Reveal answer guidance

Options: (1) SealedSecrets — encrypt secrets in Git, ArgoCD syncs them, the SealedSecrets controller decrypts. (2) External Secrets Operator (ESO) — store secret references in Git, ESO fetches from AWS/GCP/Vault. (3) Vault Agent Injector — inject via annotations at runtime. (4) argocd-vault-plugin — render secrets at sync time (plugin runs in ArgoCD repo server). (5) SOPS — encrypt secret values in Git, decrypt at sync via a SOPS plugin. Best practice: avoid storing even encrypted secrets in the GitOps repo if possible — use ESO or Vault for true secret-free GitOps.

QUESTION 08ArgoCDHard

How does ArgoCD's health assessment system work, and how do you write custom health checks?

#
Reveal answer guidance

ArgoCD has built-in health checks for standard resources (Deployment, StatefulSet, Service, Ingress). For custom resources (CRDs), you write a Lua script in argocd-cm: resource.customizations: argoproj.io_Rollout: health.lua: | hs = {} if obj.status.currentStepIndex == obj.status.stepCount - 1 then hs.status = "Healthy" else hs.status = "Progressing" end return hs. Health statuses: Healthy, Progressing, Degraded, Suspended, Missing, Unknown. The health check is evaluated after every sync and determines the Application's overall health status in the UI.

QUESTION 09ArgoCDHard

How do you implement canary deployments with Argo Rollouts in an ArgoCD GitOps workflow?

#
Reveal answer guidance

Argo Rollouts extends Kubernetes with BlueGreen and Canary rollout strategies. Declare a Rollout CRD (replaces Deployment) with strategy: canary: steps: [{setWeight: 20}, {pause: {duration: 60}}, {setWeight: 100}]. ArgoCD syncs the Rollout resource. The Rollout controller manages the actual traffic shift (via Service mesh or ingress). Analysis runs: analysis: templates: - templateName: success-rate. If the analysis fails, the Rollout auto-aborts. ArgoCD shows Rollout health as Progressing until fully promoted. This enables GitOps-driven progressive delivery without external CI triggers.

QUESTION 10ArgoCDMedium

What is the argocd-image-updater and how does it automate image updates?

#
Reveal answer guidance

argocd-image-updater watches container registries for new tags and automatically updates the Git repository (creating PRs or committing directly) to update image tags in manifests. Configured via annotations on the Application: argocd-image-updater.argoproj.io/image-list: myapp=nginx:1.25. Update strategies: semver (follows semantic versions), latest (track latest), digest (track digest), name (track by tag name pattern). This closes the loop: CI pushes image → image-updater detects new tag → updates Git → ArgoCD syncs → cluster updated.

CONTINUE PRACTICING

Try another perspective.