Argo CD Zero-to-Hero
A five-tier GitOps mastery path — from your first Application to a production platform spanning AKS, EKS and GKE — every lesson hands-on and multi-cloud.
Start the courseA complete, practical path through GitOps with Argo CD, built multi-cloud from the start. Tier 1 begins with the GitOps principles and Argo CD's architecture, installing it on AKS/EKS/GKE, your first Application, sync vs health, and the Kustomize and Helm engines. Tier 2 is real delivery: App-of-Apps, ApplicationSets and every generator, sync policies, waves and hooks, the diff engine, AppProjects, RBAC, SSO and secrets done properly. Tier 3 is the heart of the course — Argo CD end to end on Azure AKS, AWS EKS and Google GKE with each cloud's identity, secret store, registry and ingress, then a single hub managing all three, plus OpenShift/on-prem, Terraform bootstrapping and private clusters. Tier 4 adds Argo Rollouts progressive delivery, traffic management, metrics-driven rollback, observability, scaling, HA/DR and hardening. Tier 5 is production reality: the troubleshooting playbooks, Argo CD vs Flux, environment promotion, compliance, migration — and a multi-cloud capstone.
What you’ll be able to do
- Explain and apply the GitOps model — declarative, versioned, pulled and continuously reconciled — and know exactly where CI stops and Argo CD starts
- Install, secure and operate Argo CD on Azure AKS, AWS EKS and Google GKE, including each cloud's identity, secret store, registry and ingress
- Deliver at scale with App-of-Apps, ApplicationSets, sync waves/hooks, AppProjects, RBAC and enterprise SSO
- Handle secrets correctly in GitOps with Sealed Secrets, External Secrets Operator, SOPS or Vault backed by Key Vault / Secrets Manager / Secret Manager
- Run one Argo CD hub against a multi-cloud AKS + EKS + GKE fleet, including private clusters and Terraform-to-GitOps bootstrapping
- Ship safely with Argo Rollouts canary/blue-green, traffic management and metrics-driven automatic rollback
- Diagnose any Argo CD failure — OutOfSync, Degraded, ComparisonError, sync and hook failures — and run the platform with HA, DR, observability and compliance
Prerequisites
- Working Kubernetes basics: pods, deployments, services, namespaces and kubectl (the Kubernetes Zero-to-Hero course covers this)
- Comfort with Git and YAML; a cluster for the labs — kind/minikube is enough for most lessons, and a free-tier AKS/EKS/GKE cluster for the cloud-specific tiers
Who it’s for
Kubernetes users who deploy with kubectl/Helm and want real GitOps, platform and DevOps engineers running clusters on more than one cloud, SREs owning delivery and rollback, and anyone preparing for the CGOA certification or a platform-engineering role.
Curriculum
Tier 1 · Foundation
GitOps from first principles, then Argo CD itself: the architecture and reconcile loop, installing it (on AKS, EKS and GKE), your first Application, sync status vs health, connecting private repos and registries, the UI/CLI, and the two manifest engines you will actually use — Kustomize and Helm.
- 1 GitOps From First Principles: Declarative, Versioned, Pulled & Continuously Reconciled
- 2 Argo CD Architecture: API Server, Repo Server, Application Controller, Redis & Dex
- 3 Installing Argo CD: Manifests vs Helm, non-HA vs HA, First Login & the CLI — on AKS, EKS and GKE
- 4 Your First Application: The Application CRD, source, destination & Your First Sync
- 5 Sync Status & Health Assessment: Synced/OutOfSync, Healthy/Degraded/Progressing
- 6 Connecting Repositories: HTTPS, SSH, Private Repos, Credential Templates & Helm/OCI Registries
- 7 The UI, the CLI & Declarative vs Imperative: Managing Argo CD the GitOps Way
- 8 Kustomize with Argo CD: Bases, Overlays, Patches & Per-Environment Config
- 9 Helm with Argo CD: Charts, values.yaml, valueFiles, Parameters & the Rendering Model
Tier 2 · Intermediate
Real deployments at scale: App-of-Apps, ApplicationSets and every generator, sync policies (automated/self-heal/prune), sync waves and hooks, the diff engine and drift, AppProjects for multi-tenancy, RBAC, SSO against Entra ID/AWS/Google, secrets done properly (Sealed Secrets, ESO, SOPS, Vault + the cloud secret stores), and multi-cluster registration.
- 10 The App-of-Apps Pattern: Bootstrapping a Whole Cluster From One Application
- 11 ApplicationSets In Depth: List, Cluster, Git, Matrix, Merge, SCM & Pull-Request Generators
- 12 Sync Policies: Automated Sync, Self-Heal, Prune & Sync Options
- 13 Sync Waves & Resource Hooks: Ordering, PreSync/Sync/PostSync/SyncFail & Jobs
- 14 Diffing & Drift: ignoreDifferences, Server-Side Diff, Mutating Webhooks & Perpetual OutOfSync
- 15 AppProjects: Multi-Tenancy Boundaries, Allowed Repos, Clusters, Namespaces & Resource Whitelists
- 16 Argo CD RBAC: Built-in Roles, policy.csv, Local Accounts, Project Roles & Tokens
- 17 SSO for Argo CD: OIDC & Dex — Microsoft Entra ID, AWS (Cognito/IAM IdC) & Google Workspace
- 18 Secrets in GitOps: Sealed Secrets, External Secrets Operator, SOPS & Vault — with Key Vault, Secrets Manager & Secret Manager
- 19 Multi-Cluster Argo CD: Registering Clusters, Cluster Secrets & Targeting Deployments
Tier 3 · Multi-Cloud
The heart of this course: Argo CD end-to-end on each managed Kubernetes — AKS (Entra ID, Key Vault, ACR, Workload Identity, App Gateway), EKS (IRSA/Pod Identity, Secrets Manager, ECR, ALB) and GKE (Workload Identity, Secret Manager, Artifact Registry, GCLB) — then one hub managing an AKS+EKS+GKE fleet, OpenShift/Rancher/on-prem, Terraform→Argo CD bootstrapping, private-cluster connectivity, and cross-registry image automation.
- 20 Argo CD on Azure AKS: Entra ID SSO, Key Vault Secrets, ACR, Workload Identity & Application Gateway Ingress
- 21 Argo CD on AWS EKS: IRSA & Pod Identity, Secrets Manager, ECR & the AWS Load Balancer Controller
- 22 Argo CD on Google GKE: Workload Identity, Secret Manager, Artifact Registry & GCLB Ingress
- 23 One Hub, Many Clouds: A Single Argo CD Managing an AKS + EKS + GKE Fleet
- 24 Argo CD Beyond the Big Three: OpenShift (GitOps Operator), Rancher & On-Prem/Edge Clusters
- 25 Cluster Bootstrapping: Terraform Creates the Cluster, Argo CD Takes Over — on AKS, EKS & GKE
- 26 Private Clusters & Network Connectivity: Reaching Private API Servers Across AKS, EKS & GKE
- 27 Argo CD Image Updater: Automated Image Promotion from ACR, ECR & Artifact Registry
Tier 4 · Advanced
Progressive delivery and running Argo CD like a platform: Argo Rollouts canary and blue-green, traffic management across NGINX/Istio/ALB/Gateway API, metrics-driven promotion and automatic rollback, notifications, observability and SLOs, sharding and monorepo performance, HA and disaster recovery, config-management plugins, and hardening.
- 28 Argo Rollouts: Canary & Blue-Green Progressive Delivery
- 29 Rollouts Traffic Management: NGINX, Istio, ALB & the Gateway API
- 30 Metrics-Driven Promotion: AnalysisTemplates, Prometheus Queries & Automatic Rollback
- 31 Argo CD Notifications: Triggers, Templates, Slack, Teams & Webhooks
- 32 Observing Argo CD: Metrics, Prometheus, Grafana Dashboards & SLOs
- 33 Scaling Argo CD: Controller Sharding, Repo-Server Tuning & Monorepo Performance
- 34 Argo CD HA & Disaster Recovery: Backup, Restore & Rebuilding the Control Plane
- 35 Config Management Plugins (CMP): Extending Argo CD for jsonnet, cdk8s & Custom Tooling
- 36 Hardening Argo CD: Least Privilege, Network Policy, Image Verification & Admission Control
Tier 5 · Specialist
Production reality and the job: the full troubleshooting playbooks (OutOfSync/Degraded/Unknown, sync failures, pruning disasters), Argo CD vs Flux, environment promotion without drift, monorepo vs polyrepo, compliance/audit with OPA/Kyverno, migrating off Jenkins/helm-install — capped with a multi-cloud platform capstone and interview/CGOA prep.
- 37 Troubleshooting Argo CD Part 1 — OutOfSync, Degraded, Unknown & ComparisonError
- 38 Troubleshooting Argo CD Part 2 — Sync Failures, Hooks, Pruning Disasters & Stuck Operations
- 39 Argo CD vs Flux: An Honest Comparison (and When to Choose Which)
- 40 Environment Promotion: Dev → Staging → Prod the GitOps Way (PR-Based, No Drift)
- 41 Monorepo vs Polyrepo GitOps: Structuring Your Repos for 100 Apps and 40 Teams
- 42 Compliance & Audit in GitOps: Who Deployed What, Drift Evidence & Policy with OPA/Kyverno
- 43 Migrating to GitOps: From Jenkins/`helm install` Pipelines to Argo CD Without a Big Bang
- 44 Capstone: A Production Multi-Cloud GitOps Platform Across AKS, EKS & GKE
- 45 Argo CD & GitOps Interview Prep: Questions, Scenarios & the CGOA Certification