Argo CD Pipeline TasksSync, wait on, diff and report Argo CD applications from Azure Pipelines — over the Argo CD REST API, with nothing to download. Why not just script the CLI?Most pipelines hand-roll These tasks call the Argo CD REST gateway over ordinary HTTPS instead.
The CLI is still there when you need it: Quick startAdd an Argo CD service connection, then:
The tasks
|
| Command | What it does |
|---|---|
get |
Read sync and health status, optionally refreshing first. |
sync |
Sync one or more applications, then wait for them to converge. |
wait |
Wait for applications to reach a condition without syncing. |
diff |
Compare desired and live state, and publish a rendered diff to the run summary. |
refresh |
Refresh from Git (optionally hard), then report status. |
history |
List deployment history for an application. |
rollback |
Roll back to a previous history entry. |
action |
Run a resource action, such as restarting a Deployment. |
manifests |
Fetch rendered manifests for a revision, to a file and a build artifact. |
logs |
Pull pod logs for a managed resource. |
terminate |
Cancel an in-flight sync operation. |
create / set / unset / delete |
Manage Applications declaratively from a manifest file. |
Target applications by name, by namespace/name for app-in-any-namespace installs, or by
label selector for an app-of-apps.
Output variables
- task: ArgoCDApp@1
displayName: Check payments
name: argocd
inputs:
connection: 'argocd-prod'
command: 'get'
applications: 'payments-api'
project: 'payments'
- script: echo "Health is $(argocd.healthStatus) at $(argocd.revision)"
syncStatus, healthStatus, revision, operationPhase, operationMessage and appUrl for a
single application; appsJson for every run; hasDiff and diffResourceCount for diff. Every
task declares its own — see the task input reference.
Task results
- Failed — a health status in
failOnHealth(defaultDegraded,Missing), a failed sync operation, or a timeout withfailOnTimeouton. - SucceededWithIssues — out of sync, or a diff found, when configured not to fail.
- Succeeded — the requested conditions were met.
Security
Authenticate with an Argo CD project role token, scoped to a single AppProject:
argocd proj role create-token payments ado-ci --expires-in 90d
The token is masked before the task makes any request, and is only ever sent in an
Authorization header — never on a command line, never as a plain pipeline variable. A local
account API token works too when a step needs to cross projects. The
security guide has the RBAC policy
to grant, and token rotation
covers renewing them from a pipeline.
Destructive commands are guarded: delete requires explicit names and confirm: true, and
refuses to act on a label selector.
Compatibility
Argo CD 3.3, 3.4 and 3.5, the versions upstream supports. Windows, Linux and macOS agents;
hosted, self-hosted and Managed DevOps Pools. Runs on the Node24 handler, falling back to
Node20_1; minimum agent version 4.248.0.
Links
Argo and Argo CD are trademarks of The Linux Foundation. This project is not affiliated with, endorsed by, or sponsored by The Linux Foundation or the Argo project.