21 - GitOps (ArgoCD/Flux)
Why this matters
Manual kubectl apply from a laptop doesn't scale, isn't auditable, and drifts from
what's actually in git. GitOps makes git the single source of truth and a controller
continuously reconciles the cluster to match it — this is how most serious orgs run prod.
Read this first — Definitions & Explanations
GitOps
Git is the source of truth for desired cluster state. Agents (Argo CD / Flux) continuously sync the cluster to match Git.
Continuous reconciliation
If someone hotfixes live YAML, GitOps detects drift and can alert or auto-correct back to Git.
PR-based changes
Cluster changes go through pull requests: review, CI checks, audit history.
App-of-apps / root app
A pattern where one root application defines many child apps — useful for managing large fleets of services.
Benefits
Repeatability, auditability, easier disaster recovery (“re-sync from Git”), fewer snowflake clusters.
Official docs (read for detail)
- Declarative Management of Kubernetes Objects Using Configuration Files
- Argo CD Documentation
- Flux Documentation
Key Concepts
- Git as the source of truth; cluster state converges to what's in a repo
- ArgoCD: Application CRD, sync policies (manual vs automated), sync waves, health checks
- Flux: GitRepository + Kustomization/HelmRelease CRDs, similar goal, different model
- Drift detection — what happens when someone manually
kubectl edits something GitOps manages - Progressive delivery tie-in (canary/blue-green — mention only, deep dive is optional: Argo Rollouts/Flagger)
- Multi-environment patterns: overlays per environment (dev/staging/prod) via Kustomize + GitOps
YouTube search terms
- "ArgoCD tutorial for beginners"
- "GitOps explained Kubernetes ArgoCD vs Flux"
- "Kustomize overlays multiple environments tutorial"
Hands-on lab (on prod-sim)
# Install ArgoCD
kubectl create namespace argocd
kubectl apply -n argocd -f https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml
kubectl -n argocd port-forward svc/argocd-server 8080:443 &
kubectl -n argocd get secret argocd-initial-admin-secret -o jsonpath='{.data.password}' | base64 -d
# login at https://localhost:8080 user=admin
# Point it at a real public repo with k8s manifests (or fork one of your own)
argocd app create guestbook \
--repo https://github.com/argoproj/argocd-example-apps.git \
--path guestbook \
--dest-server https://kubernetes.default.svc \
--dest-namespace default
argocd app sync guestbook
kubectl get deployments -l app=guestbook
# The real lesson: prove drift detection + self-heal
kubectl scale deployment guestbook-ui --replicas=5 # manual change, bypassing git
argocd app get guestbook # should show OutOfSync
# with auto-sync enabled, ArgoCD reverts it back to what git says within seconds
argocd app set guestbook --sync-policy automated --self-heal
kubectl scale deployment guestbook-ui --replicas=5
sleep 15
kubectl get deployment guestbook-ui # back to git's replica count
Notes
(fill in your own words after watching + labbing)