Argo CD · Cheat sheet

Argo CD cheat sheet

Argo CD cheat sheet: sync, rollback, sync options, diffing, stuck-sync troubleshooting, projects, RBAC, credentials, and ApplicationSets.

56 commands·8 sections·Updated ·By SecOpsLog

Rows marked Destructive State operation Caution Exposes secrets can remove data, change authoritative state, affect a running system, or print secrets. Read the note before running them against anything that matters.

Login & context

Beginner
kubectl -n argocd get secret argocd-initial-admin-secret -o jsonpath="{.data.password}" | base64 -dExposes secrets
Get the initial admin password.Exposes secrets: Prints the admin password; delete this Secret once the password is changed.
argocd login argocd.example.com
Authenticate the CLI to a server.
argocd login --sso argocd.example.com
Log in via configured SSO.
argocd account get-user-info
Who am I / which groups.
argocd context
List contexts; pass a context name to switch servers.
argocd version
Client and server versions.

Applications

Beginner
argocd app create web --repo <url> --path k8s --dest-namespace web --dest-server https://kubernetes.default.svc
Create an Application from a Git path.
argocd app list
All apps with sync + health status.Example output
NAME        CLUSTER                         NAMESPACE  PROJECT  STATUS  HEALTH   SYNCPOLICY  CONDITIONS
argocd/web  https://kubernetes.default.svc  web        default  Synced  Healthy  Manual      <none>
argocd app get web
Detailed status and resource tree.
argocd app sync web
Reconcile the app to Git now.Example output
Operation:   Sync
Phase:       Succeeded
Message:     successfully synced
argocd app set web -p image.tag=1.2.3
Override a Helm parameter (Kustomize apps use --kustomize-image).
argocd app delete webDestructive
Delete the app (and, by default, its resources).Destructive: Cascade is on by default: every live resource the app manages is deleted.
argocd app delete web --cascade=false
Remove the Application but leave its resources running.

Sync & rollback

Intermediate
argocd app sync web --pruneCaution
Sync and delete resources removed from Git.Caution: Deletes live resources that are no longer defined in Git.
argocd app sync web --resource apps:Deployment:web
Sync only one resource.
argocd app diff web
Show live-vs-desired differences.
argocd app history web
List deployed revisions with IDs.Example output
SOURCE  https://github.com/org/repo
ID      DATE                           REVISION
12      2025-06-12 10:04:00 +0000 UTC  HEAD (a1b2c3d)
argocd app rollback web 12Caution
Roll back to a previous history ID (auto-sync must be disabled first).Caution: Syncs an older revision to the live cluster.
argocd app wait web --health --timeout 300
Block in CI until the app is healthy.

Sync options & diffing

Intermediate
argocd app set web --sync-option CreateNamespace=true
Add an app-level sync option; remove one with a ! prefix. CreateNamespace works only at app level.
argocd.argoproj.io/sync-options: Prune=false
On a resource: never prune it, for a PVC or CRD that must outlive the app.
argocd.argoproj.io/sync-options: ServerSideApply=true
On a resource: server-side apply, for objects too big for the 262144-byte last-applied annotation.
ignoreDifferences: [{ group: apps, kind: Deployment, jsonPointers: [/spec/replicas] }]
Stop an HPA-managed replica count showing OutOfSync; add the RespectIgnoreDifferences=true sync option so a sync does not reset it either.
argocd.argoproj.io/compare-options: IgnoreExtraneous
Leave a generated resource out of the app's sync status; its health still counts.
argocd app sync web --dry-run
Preview the apply without changing the cluster.

Troubleshooting a sync

Intermediate
argocd app get web --show-operation
The current or last operation, with per-resource results and messages.
argocd app get web --hard-refresh
Re-render from Git, bypassing the repo-server manifest cache.
argocd app terminate-op webCaution
Stop a sync that is stuck, for example on a hook that never completes.Caution: Resources already applied in earlier waves stay applied.
argocd app logs web --kind Deployment --name web --tail 100
Pod logs for one of the app's resources, through the Argo CD API.
argocd app resources web --orphaned
Resources in the app's namespace that no Application tracks (the project must enable orphaned-resource monitoring).
argocd proj set team-a --orphaned-resources --orphaned-resources-warn
Turn on orphaned-resource monitoring and flag apps that have them.

Automation & repos

Intermediate
argocd app set web --sync-policy automated --auto-prune --self-healCaution
Turn on continuous auto-sync + drift repair.Caution: Auto-prune deletes resources removed from Git with no manual step.
argocd app manifests web
Print the rendered manifests Argo will apply.
argocd repo add https://github.com/org/repo --username x --password yExposes secrets
Register a private Git repo.Exposes secrets: Password lands in shell history; omit --password to be prompted.
argocd repo add git@github.com:org/config.git --ssh-private-key-path ~/.ssh/id_ed25519
Register a private repo over SSH, with no password in shell history.
argocd repocreds add https://github.com/org/ --github-app-id 1 --github-app-installation-id 2 --github-app-private-key-path app.pem
Credential template: every repo under this URL prefix authenticates with the GitHub App.
argocd repo list
Connected repositories and status.
argocd cluster add my-kube-contextCaution
Let Argo deploy to another cluster.Caution: Creates argocd-manager SA bound to an admin-level ClusterRole on that cluster.
argocd cluster list
Managed target clusters.
argocd admin export -n argocd > backup.yamlExposes secrets
Back up Applications, projects and settings; argocd admin import restores them.Exposes secrets: The file holds Argo CD's Secrets, including repository and cluster credentials; pass -n, because a wrong namespace exports without an error.

Projects & RBAC

Advanced
argocd proj create team-a --dest https://kubernetes.default.svc,team-a --src "https://github.com/org/*"
Fence a team to certain repos/namespaces.
argocd proj role create team-a deployer
Define a project role.
argocd account can-i sync applications "*"
Check your own permission.Example output
yes
argocd admin settings rbac can role:deployer sync application 'team-a/*' --policy-file policy.csv
Test an RBAC policy offline before it reaches argocd-rbac-cm.
argocd account generate-token --account ci --expires-in 720hExposes secrets
API token for a local automation account (the account needs the apiKey capability in argocd-cm).Exposes secrets: Prints a bearer token; put it straight into the CI secret store.
argocd proj windows add team-a --kind deny --schedule "0 22 * * *" --duration 8h --applications "*" --manual-sync
Freeze automated syncs nightly; deny beats allow, and --manual-sync still lets a person sync.

GitOps patterns

Advanced
app-of-apps
An Application whose Git path contains more Application manifests — bootstraps everything.
ApplicationSet + generators
Template many apps from git/list/cluster/matrix generators.
argocd appset get team-apps
Inspect one ApplicationSet; argocd appset list shows them all.
argocd.argoproj.io/sync-wave: "1"
Order resources: lower waves apply first.
argocd.argoproj.io/hook: PreSync
Run a Job around a sync (PreSync/Sync/PostSync/SyncFail); PreDelete/PostDelete run only when the whole app is deleted.
argocd.argoproj.io/hook-delete-policy: HookSucceeded
Clean up hook Jobs automatically.
finalizers: [resources-finalizer.argocd.argoproj.io]
On an Application: deleting it cascade-deletes its resources. App-of-apps children need it, or a pruned child leaves its workloads running.
syncPolicy: { preserveResourcesOnDeletion: true }
On an ApplicationSet: deleting it no longer deletes the resources of the Applications it generated (by default it does).
notifications.argoproj.io/subscribe.on-sync-failed.slack: deploys
Notify a Slack channel when this app fails to sync (trigger and service configured in argocd-notifications-cm).
resource.customizations.health.example.com_Widget
argocd-cm key (group_kind) for a custom Lua health check, for a CRD with no built-in check; Argo CD already ships checks for common CRDs such as cert-manager Certificates.

Primary references

Found a technical issue on this page? Report it with the tool version you used and the behavior you saw. How resources are maintained.

Go deeper
Hands-on courses for Argo CD