⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All CI/CD & GitOps Interview Questions Scenario 159 of 176 in CI/CD & GitOps
Senior DevOps / SRE CI/CD Argo CD & Security Governance Security Hardening

Q: In a shared Argo CD instance managing 50 engineering teams, developers have broad permissions: the 'marketing' team can accidentally deploy manifests to the 'payments' namespace, delete other teams' applications in the web UI, or connect unauthorized personal GitHub repositories. How do you design and enforce strict multi-tenant isolation using Argo CD AppProjects and RBAC policy.csv?

Engineering a multi-tenant security architecture in Argo CD using AppProjects, repository whitelisting, destination cluster constraints, and granular policy.csv RBAC role mappings.

#CI/CD #Argo CD #RBAC #AppProject #Security #Multi-Tenancy #GitOps
🎙️ Candidate Opening & Architectural Context
"Running Argo CD with the 'default' project grants teams unconstrained access to deploy arbitrary resources across all connected clusters. We architected a hardened multi-tenant boundary utilizing Argo CD AppProjects, repository whitelisting, and Okta group RBAC role mappings."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's Enterprise GitOps with ArgoCD & Kubernetes Rollouts covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Define Isolated Argo CD AppProject CRDs per Engineering Team

Establish strict technical perimeters for tenant applications:

  • AppProject Manifest: Created AppProject CRD project-payments.
  • Source Whitelist: Restricted source repositories strictly to corporate repos: sourceRepos: ['https://github.com/my-org/payments-*'].
  • Destination Constraints: Restricted deployment destinations: destinations: [{ namespace: 'payments', server: 'https://kubernetes.default.svc' }].
Pro Tip: AppProjects create an impenetrable logical boundary: teams cannot deploy to any cluster, namespace, or repository not explicitly whitelisted in their project.
2️⃣

Enforce Cluster-Scoped and Namespace-Scoped Resource Whitelists

Prevent tenants from creating dangerous cluster-level resources:

  • Cluster Resource Blacklist: Configured clusterResourceBlacklist: [{ group: '*', kind: '*' }], completely forbidding creation of ClusterRoles, CRDs, or StorageClasses.
  • Namespace Resource Whitelist: Permitted only safe workload resources: namespaceResourceWhitelist: [{ group: 'apps', kind: 'Deployment' }, { group: '', kind: 'Service' }, { group: '', kind: 'ConfigMap' }].
Pro Tip: Restricting resource kinds prevents compromised tenant repositories from installing cluster-wide webhooks or privilege-escalating RBAC bindings.
Advertisement
3️⃣

Configure Granular RBAC Permissions in argocd-rbac-cm (policy.csv)

Map corporate SSO IdP groups (Okta / Entra ID) to scoped Argo CD roles:

  • Role Definition: Created role: p, role:payments-dev, applications, *, project-payments/*, allow.
  • Group Mapping: Bound Okta identity group: g, 'okta-group-payments-engineers', role:payments-dev.
  • Deny Global Admin: Developers can view, sync, and restart applications ONLY within their assigned project, with zero access to admin settings or other teams' apps.
Pro Tip: Mapping SSO groups to AppProject-scoped roles ensures that new employees automatically inherit the correct permissions upon joining their team.
4️⃣

Verify Isolation & Audit Access Logs in SIEM

Confirm unauthorized cross-tenant operations are rejected and logged:

  • Penetration Test: An engineer in the Marketing team attempted to create an Application targeting the payments namespace; Argo CD rejected the operation with application destination is not permitted in project.
  • Audit Logging: All RBAC denials and sync operations stream to SIEM with user identity, IP address, and timestamp for SOC 2 compliance.
Pro Tip: AppProject enforcement occurs directly within the Argo CD API server, guaranteeing consistent protection across CLI, UI, and GitOps syncs.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Multi-tenant Argo CD security isolates teams using AppProjects (whitelisting source repositories, destination namespaces, and resource kinds) and maps SSO groups to project-scoped roles via policy.csv."
⚡ 60-Second Elevator Pitch Talking Points
  • Create dedicated AppProject CRDs per engineering team to restrict repositories and namespaces.
  • Blacklist cluster-scoped resources to prevent unauthorized ClusterRole or CRD creation.
  • Map corporate Okta/Entra ID groups to project-scoped roles in argocd-rbac-cm (policy.csv).
  • Enforce strict least-privilege boundaries preventing cross-tenant deployments across clusters.
Advertisement
Want more CI/CD & GitOps scenarios?
Explore our complete collection of scenario-based CI/CD & GitOps interview runbooks.
Browse All CI/CD & GitOps Questions →