Skip to main content

GitOps with ArgoCD Configuration

Set up a GitOps workflow with ArgoCD for Kubernetes — application definitions, sync policies, RBAC, secrets management, and multi-cluster deployment.

Fill in the placeholders

Edit the values, then copy your finished prompt.

Your Prompt
prompt.txt
Set up a GitOps workflow using ArgoCD for microservices platform running on EKS (production) and kind (development). The system manages 15 applications across 3 (dev, staging, production) clusters. Configure: 1) ArgoCD Application manifests for api-gateway, user-service, order-service, notification-service, frontend using Helm charts in a monorepo with Kustomize overlays per environment as source — define source repo, target revision (main for production, HEAD for staging, feature branches for dev), path to manifests, and destination cluster/namespace. 2) Sync policy: automated sync with CreateNamespace=true, PrunePropagationPolicy=foreground, ServerSideApply=true — self-heal (revert manual changes), prune (delete removed resources), with sync waves and hooks for databases first (wave 1), backend services (wave 2), API gateway (wave 3), frontend (wave 4) ordered deployments. 3) ApplicationSet for each microservice across all environments using Git directory generator combined with cluster generator (matrix) generator to automatically create ArgoCD Applications from directories in the deployment repo matching services/*/ — one Application per environment/service combination. 4) RBAC configuration: define roles for developer (sync own apps), sre (sync all, manage clusters), admin (full access) with project-scoped permissions — developers can sync their apps, ops can sync any app, admins manage projects. 5) Secret management using Sealed Secrets with Bitnami controller — keep secrets out of Git while maintaining GitOps principles for database credentials, API keys, TLS certificates. 6) Health checks and resource tracking: custom health checks for CronJob (healthy if last run succeeded), Certificate (healthy if not expiring within 30d) and resource tracking for ConfigMaps generated by Kustomize, ServiceMonitors for Prometheus with proper annotations. 7) Notification integration: send deployment status to Slack #deployments channel and GitHub commit status using argocd-notifications with templates for success, failure, and degraded states.

What this prompt does

This prompt sets up a GitOps workflow with ArgoCD for a [application_type] on [kubernetes_platform], managing [app_count] applications across [cluster_count] clusters. It defines Application manifests for [app_list] sourced from [source_type], with target revisions per [branch_strategy] and a sync policy using [sync_options] — automated sync with self-heal to revert manual edits, prune to delete removed resources, and sync waves and hooks for the [deployment_order] ordering.

It scales this with an ApplicationSet for [dynamic_apps] using a [generator_type] generator over [generator_source] to auto-create one Application per environment-and-service combination. It configures RBAC for [argocd_roles] with project-scoped permissions, secret management via [secret_strategy] to keep [secret_types] out of Git, custom health checks for [custom_health_resources], resource tracking for [tracked_resources] via annotations, and notifications to [notification_channels] for success, failure, and degraded states using argocd-notifications templates. The setups that scale rely on generated Applications, ordered sync waves, and secrets that never touch Git in plaintext.

When to use it

  • You're adopting GitOps and want Git as the source of truth for deployments
  • You need many apps across clusters generated automatically rather than hand-written
  • You want ordered rollouts (databases before services before frontend) via sync waves
  • You need role-scoped permissions so developers sync only their own apps
  • You want secrets in Git without storing them in plaintext
  • You want deployment status posted to Slack or commit statuses
  • You're managing multiple clusters and want one consistent application definition pattern

Example output

The AI returns ArgoCD Application YAML for [app_list], an ApplicationSet using the [generator_type] generator over [generator_source], an RBAC policy for [argocd_roles], a [secret_strategy] setup for [secret_types], custom health-check definitions for [custom_health_resources], resource-tracking annotations, and an argocd-notifications config for [notification_channels]. Expect YAML grouped per numbered concern so you can adopt the ApplicationSet, RBAC, or secret pieces independently.

Pro tips

  • Use sync waves to enforce [deployment_order] so databases come up before the services that depend on them
  • Enable self-heal and prune in [sync_options] deliberately — self-heal reverts manual cluster edits, which you usually want but should understand
  • Drive [dynamic_apps] from a [generator_type] generator so adding a service is a directory change, not a new hand-written Application
  • Scope [argocd_roles] per project so developers can sync their apps but not others'
  • Keep [secret_types] out of Git with [secret_strategy] (like Sealed Secrets) so the repo stays the source of truth without leaking credentials
  • Wire [notification_channels] to fire on degraded and failed states, not just success, so a stuck sync surfaces quickly
  • Track [tracked_resources] with proper annotations so ArgoCD doesn't keep pruning resources another controller generates
  • Add custom health checks for [custom_health_resources] so ArgoCD reports a CronJob or Certificate as unhealthy when it genuinely is

Frequently Asked Questions

How does it deploy applications in the right order?
It uses ArgoCD sync waves and hooks to enforce `[deployment_order]`, for example databases in wave one, backend services in wave two, and the frontend last. This ensures dependencies are running before the components that rely on them get applied.
Do I have to write an Application manifest for every service and environment?
No. The prompt uses an ApplicationSet with a `[generator_type]` generator over `[generator_source]` to automatically create one Application per environment-and-service combination. Adding a new service becomes a directory change rather than a hand-written manifest.
How are secrets kept out of Git while still using GitOps?
It uses `[secret_strategy]`, such as Sealed Secrets, so `[secret_types]` like database credentials and TLS certificates are stored encrypted in Git and decrypted only in-cluster. This preserves Git as the source of truth without exposing plaintext secrets.
Can different teams have different permissions in ArgoCD?
Yes. RBAC is configured for `[argocd_roles]` with project-scoped permissions, so developers can sync only their own apps, SREs can sync any app and manage clusters, and admins manage projects. This limits who can affect which workloads.
Engr Mejba Ahmed

Need this built for real?

Engr Mejba Ahmed

AI Developer · Software Engineer

I'm Mejba — I design and ship production AI systems, automations, and full-stack apps. If you want this turned into a working solution for your team, let's talk.

More in Terraform & Infrastructure as Code Prompts

Engr Mejba Ahmed

Engr Mejba Ahmed

AI assistant · trained on my work

👋

Hey there!

Quick Actions

WhatsApp Direct line to me

Chat on WhatsApp

+880 1723 741224 · Replies within the hour on working days

Popular Questions

Engr Mejba Ahmed is connected
Engr Mejba Ahmed is typing...
Engr Mejba Ahmed avatar

✉ Want me to follow up? Drop your email

Engr Mejba Ahmed avatar

📞 Connect Directly

Choose how you'd like to reach me

WhatsApp

+880 1723 741224

Email

mejba.13@gmail.com

✓ Details sent! I'll get back to you shortly.

Powered by OpenAI

335+

Blog Posts

25

AI Courses

63

Projects

Services & Expertise

Pricing & Process

Learning & Resources

Connect & Support