Q: Your enterprise operates 120 Kubernetes clusters across dev, staging, and production in 4 cloud regions. Managing individual Argo CD Application YAML manifests for 80 microservices required 9,600 separate files, causing configuration drift and PR review gridlock. How do you re-architect the GitOps platform using Argo CD ApplicationSet Matrix Generators to deploy all services across all clusters with a single template?
Engineering a declarative multi-cluster, multi-environment GitOps deployment engine using Argo CD ApplicationSet Matrix Generators, combining Git directory structure with cluster label discovery.
Want to master this scenario in a live sandbox? KodeKloud's Enterprise GitOps with ArgoCD & Kubernetes Rollouts covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Define ApplicationSet with Combined Git & Cluster Matrix Generators
Combine multi-dimensional parameters to dynamically generate Applications:
- Matrix Generator: Declared an
ApplicationSetcombining a Git directory generator (scanningservices/*) and a Cluster generator matching labelsenv: prod, region: us-east-1. - Dynamic Matrix Permutation: The generator computes the Cartesian product of (Services x Clusters), dynamically creating Argo CD Applications with zero manual templating.
Parameterize Helm Values & Target Cluster Destination
Inject environment-specific and cluster-specific configurations into Helm releases:
- Dynamic Destination: Configured
destination: { server: '{{server}}', namespace: '{{path.basename}}' }. - Value File Hierarchy: Configured Helm value files to cascade:
values.yaml -> values-{{metadata.labels.env}}.yaml -> values-{{metadata.labels.region}}.yaml.
Implement Progressive Canary Sync Waves Across Environments
Prevent simultaneous blast-radius outages across global clusters:
- Sync Policy Waves: Annotated ApplicationSet with sync waves: Dev (Wave 0), Staging (Wave 1), Production Canary (Wave 2), Production Global (Wave 3).
- Automated Rollback Hook: Configured
syncPolicy: { automated: { prune: true, selfHeal: true } }with failure retry backoffs (5s, 10s, 20s).
Enforce Resource Orphan Deletion & Pruning Guardrails
Prevent accidental deletion of databases and stateful workloads during Git directory refactors:
- Preserve Resources Annotation: Added
argocd.argoproj.io/sync-options: Delete=falseon PVCs, StatefulSets, and CRDs. - ApplicationSet Dry-Run: Integrated
argocd-appset-testCLI into CI pipelines to validate generated Application YAML deltas before merging PRs.
- Consolidate thousands of manual Application YAMLs using ApplicationSet Matrix Generators.
- Combine Git directory generators with cluster label generators to compute deployment permutations.
- Parameterize cascading Helm values by environment and region (values-prod.yaml).
- Enforce automated sync waves and resource pruning annotations to protect persistent databases.