What this prompt does
This prompt sets up a GitOps workflow with ArgoCD for a [application_type] on [kubernetes_platform], managing [app_count] applications across [cluster_count] clusters. It defines Application manifests for [app_list] sourced from [source_type], with target revisions per [branch_strategy] and a sync policy using [sync_options] — automated sync with self-heal to revert manual edits, prune to delete removed resources, and sync waves and hooks for the [deployment_order] ordering.
It scales this with an ApplicationSet for [dynamic_apps] using a [generator_type] generator over [generator_source] to auto-create one Application per environment-and-service combination. It configures RBAC for [argocd_roles] with project-scoped permissions, secret management via [secret_strategy] to keep [secret_types] out of Git, custom health checks for [custom_health_resources], resource tracking for [tracked_resources] via annotations, and notifications to [notification_channels] for success, failure, and degraded states using argocd-notifications templates. The setups that scale rely on generated Applications, ordered sync waves, and secrets that never touch Git in plaintext.
When to use it
- You're adopting GitOps and want Git as the source of truth for deployments
- You need many apps across clusters generated automatically rather than hand-written
- You want ordered rollouts (databases before services before frontend) via sync waves
- You need role-scoped permissions so developers sync only their own apps
- You want secrets in Git without storing them in plaintext
- You want deployment status posted to Slack or commit statuses
- You're managing multiple clusters and want one consistent application definition pattern
Example output
The AI returns ArgoCD Application YAML for [app_list], an ApplicationSet using the [generator_type] generator over [generator_source], an RBAC policy for [argocd_roles], a [secret_strategy] setup for [secret_types], custom health-check definitions for [custom_health_resources], resource-tracking annotations, and an argocd-notifications config for [notification_channels]. Expect YAML grouped per numbered concern so you can adopt the ApplicationSet, RBAC, or secret pieces independently.
Pro tips
- Use sync waves to enforce
[deployment_order]so databases come up before the services that depend on them - Enable self-heal and prune in
[sync_options]deliberately — self-heal reverts manual cluster edits, which you usually want but should understand - Drive
[dynamic_apps]from a[generator_type]generator so adding a service is a directory change, not a new hand-written Application - Scope
[argocd_roles]per project so developers can sync their apps but not others' - Keep
[secret_types]out of Git with[secret_strategy](like Sealed Secrets) so the repo stays the source of truth without leaking credentials - Wire
[notification_channels]to fire on degraded and failed states, not just success, so a stuck sync surfaces quickly - Track
[tracked_resources]with proper annotations so ArgoCD doesn't keep pruning resources another controller generates - Add custom health checks for
[custom_health_resources]so ArgoCD reports a CronJob or Certificate as unhealthy when it genuinely is