All skills
wshobson avatar

/gitops-workflow

@5684887
by Seth Hobsonwshobson/agents40k stars
4,281

Implement GitOps workflows with ArgoCD and Flux for automated, declarative Kubernetes deployments with continuous reconciliation. Use when implementing GitOps practices, automating Kubernetes deployments, or setting up declarative infrastructure management.

Use this Skill: https://skilld.dev/gh/wshobson/agents/gitops-workflow

This session only. Nothing lands on disk.

referencesargocd-setup.md

≈737 tokens on demand. Your agent reads this file only when SKILL.md points to it.

ArgoCD Setup and Configuration

Installation Methods

1. Standard Installation

kubectl create namespace argocd
kubectl apply -n argocd -f https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml

2. High Availability Installation

kubectl apply -n argocd -f https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/ha/install.yaml

3. Helm Installation

helm repo add argo https://argoproj.github.io/argo-helm
helm install argocd argo/argo-cd -n argocd --create-namespace

Initial Configuration

Access ArgoCD UI

# Port forward
kubectl port-forward svc/argocd-server -n argocd 8080:443

# Get initial admin password
argocd admin initial-password -n argocd

Configure Ingress

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: argocd-server-ingress
  namespace: argocd
  annotations:
    cert-manager.io/cluster-issuer: letsencrypt-prod
    nginx.ingress.kubernetes.io/ssl-passthrough: "true"
    nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
spec:
  ingressClassName: nginx
  rules:
    - host: argocd.example.com
      http:
        paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: argocd-server
                port:
                  number: 443
  tls:
    - hosts:
        - argocd.example.com
      secretName: argocd-secret

CLI Configuration

Login

argocd login argocd.example.com --username admin

Add Repository

argocd repo add https://github.com/org/repo --username user --password token

Create Application

argocd app create my-app \
  --repo https://github.com/org/repo \
  --path apps/my-app \
  --dest-server https://kubernetes.default.svc \
  --dest-namespace production

SSO Configuration

GitHub OAuth

apiVersion: v1
kind: ConfigMap
metadata:
  name: argocd-cm
  namespace: argocd
data:
  url: https://argocd.example.com
  dex.config: |
    connectors:
      - type: github
        id: github
        name: GitHub
        config:
          clientID: $GITHUB_CLIENT_ID
          clientSecret: $GITHUB_CLIENT_SECRET
          orgs:
          - name: my-org

RBAC Configuration

apiVersion: v1
kind: ConfigMap
metadata:
  name: argocd-rbac-cm
  namespace: argocd
data:
  policy.default: role:readonly
  policy.csv: |
    p, role:developers, applications, *, */dev, allow
    p, role:operators, applications, *, */*, allow
    g, my-org:devs, role:developers
    g, my-org:ops, role:operators

Best Practices

  1. Enable SSO for production
  2. Implement RBAC policies
  3. Use separate projects for teams
  4. Enable audit logging
  5. Configure notifications
  6. Use ApplicationSets for multi-cluster
  7. Implement resource hooks
  8. Configure health checks
  9. Use sync windows for maintenance
  10. Monitor with Prometheus metrics

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides standard installation and configuration guides for ArgoCD and Flux CD. It includes remote downloads and privileged commands that are part of the official, documented setup processes for these well-known industry tools.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    2/3 files flagged

  • ZeroLeaks5mo

    2 findings · Score: 80/100

Signed by skilld at 5684887. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 8 months ago
  • kubernetes
  • gitops
  • argocd
  • flux
  • cd
  • declarative
  • deployment
  • kustomization
  • multi-cluster

README badge

README badge for wshobson/agents/gitops-workflow

Implements GitOps workflows for Kubernetes using ArgoCD or Flux CD, with declarative application deployments that continuously reconcile desired state from Git. Covers repository structure, auto-sync policies, progressive delivery strategies like canary deployments, and secret management with External Secrets Operator or Sealed Secrets.

Generated from the current SKILL.md.

Does this skill cover both ArgoCD and Flux, or do I have to pick one?
The skill covers both ArgoCD and Flux CD. You choose which tool fits your GitOps workflow; the skill shows setup and configuration for each.
Can I use this skill for multi-cluster deployments?
Yes. The skill includes guidance for multi-cluster deployments and uses the App of Apps pattern to manage applications across clusters.
How does secret management work in this GitOps workflow?
The skill covers External Secrets Operator and Sealed Secrets to keep secrets out of Git while maintaining declarative infrastructure.
Does this skill support progressive delivery strategies like canary or blue-green deployments?
Yes. The skill includes examples of canary deployments using ArgoCD Rollouts and blue-green deployment configurations.
What happens if there's a sync failure or drift between Git and the cluster?
The skill covers troubleshooting commands (argocd app get, argocd app diff) and auto-sync policies with retry logic to handle failures and reconcile drift.

Generated from the current SKILL.md. These answers refresh after source changes.