Q: In a shared Argo CD instance managing 50 engineering teams, developers have broad permissions: the 'marketing' team can accidentally deploy manifests to the 'payments' namespace, delete other teams' applications in the web UI, or connect unauthorized personal GitHub repositories. How do you design and enforce strict multi-tenant isolation using Argo CD AppProjects and RBAC policy.csv?
Engineering a multi-tenant security architecture in Argo CD using AppProjects, repository whitelisting, destination cluster constraints, and granular policy.csv RBAC role mappings.
Want to master this scenario in a live sandbox? KodeKloud's Enterprise GitOps with ArgoCD & Kubernetes Rollouts covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Define Isolated Argo CD AppProject CRDs per Engineering Team
Establish strict technical perimeters for tenant applications:
- AppProject Manifest: Created
AppProjectCRDproject-payments. - Source Whitelist: Restricted source repositories strictly to corporate repos:
sourceRepos: ['https://github.com/my-org/payments-*']. - Destination Constraints: Restricted deployment destinations:
destinations: [{ namespace: 'payments', server: 'https://kubernetes.default.svc' }].
Enforce Cluster-Scoped and Namespace-Scoped Resource Whitelists
Prevent tenants from creating dangerous cluster-level resources:
- Cluster Resource Blacklist: Configured
clusterResourceBlacklist: [{ group: '*', kind: '*' }], completely forbidding creation of ClusterRoles, CRDs, or StorageClasses. - Namespace Resource Whitelist: Permitted only safe workload resources:
namespaceResourceWhitelist: [{ group: 'apps', kind: 'Deployment' }, { group: '', kind: 'Service' }, { group: '', kind: 'ConfigMap' }].
Configure Granular RBAC Permissions in argocd-rbac-cm (policy.csv)
Map corporate SSO IdP groups (Okta / Entra ID) to scoped Argo CD roles:
- Role Definition: Created role:
p, role:payments-dev, applications, *, project-payments/*, allow. - Group Mapping: Bound Okta identity group:
g, 'okta-group-payments-engineers', role:payments-dev. - Deny Global Admin: Developers can view, sync, and restart applications ONLY within their assigned project, with zero access to admin settings or other teams' apps.
Verify Isolation & Audit Access Logs in SIEM
Confirm unauthorized cross-tenant operations are rejected and logged:
- Penetration Test: An engineer in the Marketing team attempted to create an Application targeting the
paymentsnamespace; Argo CD rejected the operation withapplication destination is not permitted in project. - Audit Logging: All RBAC denials and sync operations stream to SIEM with user identity, IP address, and timestamp for SOC 2 compliance.
- Create dedicated AppProject CRDs per engineering team to restrict repositories and namespaces.
- Blacklist cluster-scoped resources to prevent unauthorized ClusterRole or CRD creation.
- Map corporate Okta/Entra ID groups to project-scoped roles in argocd-rbac-cm (policy.csv).
- Enforce strict least-privilege boundaries preventing cross-tenant deployments across clusters.