KubeRusted
Spinning up your cluster…

CAPA exam prep — Certified Argo Project Associate

Free CAPA (Certified Argo Project Associate) practice: the 4 official domains, exam-style questions, a timed practice exam and more.

Play the CAPA map → · Official CAPA exam page

Argo Workflows (36%)

Fundamentals, artifacts, templates, the Workflow spec, DAGs, data processing

Argo CD (34%)

Fundamentals, syncing, Applications, Helm and Kustomize, reconciliation patterns

Argo Rollouts (18%)

Fundamentals, progressive strategies, AnalysisTemplate and AnalysisRun

Argo Events (12%)

Fundamentals, components and architecture

Practice questions

Which field names the template a Workflow starts with?

Answer: spec.entrypoint. Templates are defined under spec.templates and called by name.

What does a container template run?

Answer: A single container, like a Pod spec container. Each step of a Workflow runs in its own Pod.

What does a script template add over a container template?

Answer: An inline source script that is written to a file and executed. The script’s stdout becomes the result output parameter.

Which template type creates or patches a Kubernetes resource and can wait for a condition?

Answer: resource. action: create/apply/patch/delete with successCondition/failureCondition.

What does a suspend template do?

Answer: Pauses the Workflow until resumed (manually or after a duration). Useful for approvals: argo resume <workflow>.

In a steps template, how do you run two steps in parallel?

Answer: Put them in the same inner list (same step group). Outer list items run sequentially; items in one inner list run in parallel.

In a DAG, how do you make task C wait for tasks A and B?

Answer: dependencies: [A, B] on task C. Or depends: "A && B" with richer conditions such as A.Succeeded.

Which DAG feature lets a task run only if another task failed?

Answer: depends with a result, e.g. depends: "A.Failed". depends supports .Succeeded, .Failed, .Errored, .Skipped and .Daemoned.

How do you pass a small value from step A to step B?

Answer: An output parameter of A referenced as {{steps.A.outputs.parameters.name}}. In a DAG use {{tasks.A.outputs.parameters.name}}.

Where does an output parameter usually get its value from?

Answer: valueFrom.path — a file the container writes. It can also come from a JSON path, supplied value or expression.

Where are artifacts stored between steps?

Answer: An artifact repository such as S3, GCS, Azure Blob or MinIO. The default repository is configured in the workflow-controller ConfigMap.

How do you run a step only when a condition holds?

Answer: A when expression, e.g. when: "{{steps.flip.outputs.result}} == heads". when is evaluated before the step runs.

Which field retries a failing step automatically?

Answer: retryStrategy (e.g. limit: 3, retryPolicy: OnFailure). Backoff can be configured with duration and factor.

What is an exit handler (onExit)?

Answer: A template that always runs at the end of the Workflow, e.g. for notifications or cleanup. It runs whether the Workflow succeeded or failed; check {{workflow.status}}.

Which resource runs a Workflow on a schedule?

Answer: CronWorkflow. It supports concurrencyPolicy like Kubernetes CronJobs.

Which CLI command submits a Workflow from a WorkflowTemplate?

Answer: argo submit --from workflowtemplate/<name>. Pass parameters with -p name=value.

How do you reference a template inside a WorkflowTemplate from another Workflow?

Answer: templateRef with name and template. Add clusterScope: true for a ClusterWorkflowTemplate.

What does spec.workflowTemplateRef do on a Workflow?

Answer: Runs a whole WorkflowTemplate as the Workflow’s spec. The Workflow only supplies arguments.

Which command shows a Workflow’s steps and their status as a tree?

Answer: argo get <workflow>. argo logs <workflow> prints the step logs.

How do you limit how many Pods a Workflow runs at once?

Answer: spec.parallelism. Templates can also set their own parallelism.

What does withParam iterate over?

Answer: A JSON list, typically produced by a previous step’s output. withItems takes a static list; withSequence generates numbers.

Which ServiceAccount does a Workflow’s Pod use?

Answer: spec.serviceAccountName (or the namespace default). Give it only what the steps need; the executor needs permissions to report results.

What does a memoized step (memoize) do?

Answer: Reuses a cached result for the same key instead of running again. The cache is backed by a ConfigMap.

How can a Workflow avoid leaving many completed Pods behind?

Answer: spec.podGC (e.g. strategy: OnPodSuccess). ttlStrategy deletes the Workflow object itself after a while.

Which Argo Workflows component reconciles Workflow resources?

Answer: The workflow-controller. The Argo Server provides the UI and API; argoexec runs inside Pods.

Which container does Argo add to step Pods to handle outputs and artifacts?

Answer: The wait container (argoexec). An init container also loads input artifacts.

What is a typical data-processing pattern in Argo Workflows?

Answer: Fan-out over items with parallel steps, then fan-in to aggregate. Map-reduce style jobs are a classic Workflows use case.

How do you pass a Secret to a step safely?

Answer: Mount it as a volume or env var in the step’s container spec. Parameters and outputs are visible in the Workflow status and UI.

Which field sets a time limit for a whole Workflow?

Answer: spec.activeDeadlineSeconds. Templates can also set activeDeadlineSeconds.

What does an Argo CD Application’s source.targetRevision specify?

Answer: The Git branch, tag or commit (or chart version) to deploy. HEAD tracks the default branch.

Which field tells Argo CD where to deploy?

Answer: spec.destination (server or name, plus namespace). https://kubernetes.default.svc is the cluster Argo CD runs in.

What is an AppProject used for?

Answer: Restricting which repos, clusters, namespaces and resource kinds Applications may use. The default project allows everything.

Which command syncs an Application from the CLI?

Answer: argocd app sync <app>. refresh re-reads Git; sync applies changes.

What does a "hard refresh" do?

Answer: Invalidates the manifest cache and regenerates manifests from Git. Useful when a Helm chart dependency changed without a Git change.

Which sync option creates the destination namespace if missing?

Answer: CreateNamespace=true. Set it under syncPolicy.syncOptions.

Which sync option deletes removed resources only after all others are applied?

Answer: PruneLast=true. Other options include Replace, ServerSideApply and ApplyOutOfSyncOnly.

How do you prevent Argo CD from deleting one specific resource during prune?

Answer: Annotate it argocd.argoproj.io/sync-options: Prune=false. The resource then stays even when removed from Git.

How does Argo CD ignore a field that a controller changes (e.g. replicas managed by HPA)?

Answer: ignoreDifferences on the Application (e.g. jsonPointers: /spec/replicas). Without it, the app shows OutOfSync and selfHeal would fight the HPA.

Which health status means resources are fine but still rolling out?

Answer: Progressing. Healthy, Progressing, Degraded, Suspended, Missing and Unknown are the built-in states.

How do sync hooks know when to run?

Answer: The annotation argocd.argoproj.io/hook (PreSync, Sync, PostSync, SyncFail, PostDelete). hook-delete-policy controls cleanup, e.g. HookSucceeded.

Resources in wave 1 and wave 2: when does wave 2 start?

Answer: After wave 1 is applied and healthy. Within a wave, resources are ordered by kind and name.

Which source type renders a Helm chart directly in an Application?

Answer: source.chart with repoURL of a Helm repository (or source.path with a chart in Git). Helm values go under source.helm.values or valueFiles.

Does Argo CD run helm install for Helm sources?

Answer: No — it renders templates (helm template) and applies the manifests. That is why helm list shows no release for Argo CD apps.

How does an Application use several sources at once (e.g. chart from a Helm repo, values from Git)?

Answer: spec.sources (multiple sources) with a ref to the values repo. Values files can be referenced as $ref/path.

Which ApplicationSet generator creates one Application per directory in a repo?

Answer: Git generator (directories). The files variant reads parameters from JSON/YAML files.

Which ApplicationSet generator combines two generators’ parameters?

Answer: Matrix. e.g. every cluster × every app directory.

What is the "app of apps" pattern?

Answer: A parent Application whose manifests are other Application resources. ApplicationSets are the more dynamic alternative.

How do you register an external cluster with Argo CD?

Answer: argocd cluster add <context>. It creates a ServiceAccount in the target cluster and stores credentials as a Secret.

Where does Argo CD store repository credentials?

Answer: Kubernetes Secrets in the argocd namespace labelled as repository secrets. Label argocd.argoproj.io/secret-type: repository (or repo-creds).

Which Argo CD component generates manifests from Git?

Answer: argocd-repo-server. The application-controller compares and syncs; the server exposes UI/API.

Which Argo CD component compares live state with desired state and syncs?

Answer: argocd-application-controller. It runs the reconciliation loop.

How often does Argo CD poll Git by default?

Answer: About every 3 minutes (configurable), unless a webhook triggers a refresh. Webhooks from the Git provider make it near-instant.

What does automated sync with allowEmpty: false protect against?

Answer: Pruning every resource when the source suddenly renders nothing. An accidentally emptied path would otherwise delete the app.

How do you roll back an Argo CD-managed app?

Answer: Revert the commit in Git (or argocd app rollback when auto-sync is off). With auto-sync on, a manual rollback is immediately re-synced to Git.

Which RBAC configuration controls who may sync which applications in Argo CD?

Answer: The argocd-rbac-cm ConfigMap (policy.csv). Policies grant actions like sync on applications per project.

What does selfHeal do when someone edits a managed resource by hand?

Answer: Argo CD reverts it to the Git state automatically. Without selfHeal, the app just shows OutOfSync.

How do you migrate an existing Deployment to a Rollout without duplicating the Pod template?

Answer: spec.workloadRef pointing at the Deployment. Scale the Deployment down once the Rollout is healthy.

Which kubectl plugin command promotes a paused Rollout?

Answer: kubectl argo rollouts promote <name>. promote --full skips the remaining steps.

Which command aborts a Rollout and returns traffic to stable?

Answer: kubectl argo rollouts abort <name>. retry restarts an aborted rollout.

What is the difference between stableService and canaryService in a canary Rollout?

Answer: Each selects the stable or canary ReplicaSet so a traffic router can split by weight. Rollouts injects a hash selector into each Service.

Without a traffic router, how does a canary setWeight: 20 behave?

Answer: Approximated by scaling the canary ReplicaSet to about 20% of replicas. Fine-grained weights need Istio, Gateway API, ALB or similar.

What is an AnalysisRun?

Answer: One execution of an AnalysisTemplate during a rollout. Its result (Successful, Failed, Inconclusive) drives promotion or abort.

What does an Inconclusive analysis result do?

Answer: Pauses the Rollout for a human decision. Set inconclusiveLimit to bound it.

Which blue-green field runs analysis before traffic switches to the new version?

Answer: prePromotionAnalysis. postPromotionAnalysis runs after the switch.

How does a background analysis differ from an analysis step?

Answer: It runs continuously during the canary steps instead of at one step. Defined under strategy.canary.analysis.

Which analysis provider runs a Kubernetes Job and judges by its result?

Answer: job. Job success counts as a successful measurement.

What does scaleDownDelaySeconds do in blue-green?

Answer: Keeps the old ReplicaSet running for a while after the switch, for fast rollback. The previous ReplicaSet stays up (30 seconds by default) so switching back is instant.

What is the Argo Rollouts dashboard?

Answer: A UI started with kubectl argo rollouts dashboard. It shows Rollouts, steps and analysis runs.

Which Rollout strategy keeps both versions fully scaled and switches all traffic at once?

Answer: blueGreen. Canary shifts traffic in steps.

Which Argo Events resource listens to external systems such as GitHub webhooks?

Answer: EventSource. Each EventSource type knows how to talk to one kind of system.

What must exist in a namespace for EventSources and Sensors to communicate?

Answer: An EventBus (usually named default). NATS JetStream is the common EventBus implementation.

Which Sensor field filters events, e.g. only pushes to main?

Answer: Dependency filters (data, exprs, context). Filters inspect event data such as body.ref.

What does a Sensor trigger template with argoWorkflow do?

Answer: Submits an Argo Workflow when dependencies are satisfied. Parameters can copy event data into the Workflow.

How do you pass the Git commit SHA from a webhook into the triggered Workflow?

Answer: Trigger parameters mapping event data (e.g. body.after) into the Workflow spec. parameters: src: dependencyName + dataKey, dest: spec path.

How can a Sensor wait for two different events before triggering?

Answer: Two dependencies combined in the trigger conditions (e.g. "dep1 && dep2"). Conditions use boolean logic over dependency names.

Which EventSource type fires on a schedule?

Answer: calendar. It supports cron schedules and intervals.

Which ServiceAccount permissions does a Sensor need to create Workflows?

Answer: RBAC to create workflows in the target namespace. Set template.serviceAccountName on the Sensor.

In which format do EventSources publish events to the EventBus?

Answer: CloudEvents. CloudEvents is a CNCF specification for event data.

Tasks B and C both depend only on A, and D depends on B and C. Which template type runs B and C in parallel with minimal config?

Answer: dag. A DAG runs every task whose dependencies are met, so B and C start together once A succeeds.

Step 1 produces a 2 GB file that step 2 needs. How should it be passed?

Answer: As an output artifact stored in the artifact repository. Parameters are for small strings; artifacts are files stored in S3/GCS/MinIO between steps.

Several teams need the same build steps. Where should they live?

Answer: In a WorkflowTemplate (or ClusterWorkflowTemplate) referenced with templateRef. WorkflowTemplates are reusable, versioned cluster resources.

Someone edits a Deployment with kubectl, and Argo CD should undo it automatically. Which setting?

Answer: syncPolicy.automated.selfHeal: true. selfHeal re-syncs when live state drifts from Git; prune only deletes resources removed from Git.

An Application shows Synced but Degraded. What does that tell you?

Answer: Git was applied, but the resources are unhealthy (e.g. Pods crashing). Sync status compares with Git; health status reflects the live resources. They are independent.

A database migration must run before the new Deployment is applied. How?

Answer: A Job annotated as a PreSync hook (or in a lower sync wave). Hooks and waves order the sync; PreSync runs before the main manifests are applied.

Deploy the same app to 20 clusters, one Application each, without writing 20 manifests. What do you use?

Answer: An ApplicationSet with a cluster generator. ApplicationSet generators template Applications per cluster, directory or list item.

A canary step list contains `pause: {}` with no duration. What happens there?

Answer: The rollout waits indefinitely until it is promoted. An indefinite pause needs `kubectl argo rollouts promote`.

Automatically roll back a canary when the error rate from Prometheus exceeds 5%. What do you configure?

Answer: An AnalysisTemplate with a Prometheus metric and failureCondition, used in the canary steps. A failing AnalysisRun aborts the Rollout and shifts traffic back to stable.

In a blue-green Rollout, which Service receives production traffic before promotion?

Answer: activeService. previewService points at the new version for testing; promotion switches activeService to it.

Start an Argo Workflow every time a GitHub push webhook arrives. Which pieces?

Answer: A GitHub (or webhook) EventSource, the EventBus, and a Sensor with an Argo Workflow trigger. EventSource ingests, EventBus transports, Sensor evaluates dependencies and fires the trigger.

Which Argo Events component decides whether an action should run?

Answer: Sensor. Sensors hold the dependencies and filters, and run triggers when they are satisfied.