⚡ ~/naveed k8s
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Phase 4 — Advanced / Mastery Module 21 of 24 Free & Open Access

GitOps (ArgoCD/Flux)

Complete production curriculum breakdown. Learn core architectural mechanics, study definitions in plain language, practice hands-on labs with the local minikube prod-sim cluster, and test active recall.

21 - GitOps (ArgoCD/Flux)

Why this matters

Manual kubectl apply from a laptop doesn't scale, isn't auditable, and drifts from what's actually in git. GitOps makes git the single source of truth and a controller continuously reconciles the cluster to match it — this is how most serious orgs run prod.

Read this first — Definitions & Explanations

GitOps

Git is the source of truth for desired cluster state. Agents (Argo CD / Flux) continuously sync the cluster to match Git.

Continuous reconciliation

If someone hotfixes live YAML, GitOps detects drift and can alert or auto-correct back to Git.

PR-based changes

Cluster changes go through pull requests: review, CI checks, audit history.

App-of-apps / root app

A pattern where one root application defines many child apps — useful for managing large fleets of services.

Benefits

Repeatability, auditability, easier disaster recovery (“re-sync from Git”), fewer snowflake clusters.

Official docs (read for detail)

Key Concepts

YouTube search terms

Hands-on lab (on prod-sim)

# Install ArgoCD
kubectl create namespace argocd
kubectl apply -n argocd -f https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml
kubectl -n argocd port-forward svc/argocd-server 8080:443 &
kubectl -n argocd get secret argocd-initial-admin-secret -o jsonpath='{.data.password}' | base64 -d
# login at https://localhost:8080 user=admin

# Point it at a real public repo with k8s manifests (or fork one of your own)
argocd app create guestbook \
  --repo https://github.com/argoproj/argocd-example-apps.git \
  --path guestbook \
  --dest-server https://kubernetes.default.svc \
  --dest-namespace default

argocd app sync guestbook
kubectl get deployments -l app=guestbook

# The real lesson: prove drift detection + self-heal
kubectl scale deployment guestbook-ui --replicas=5   # manual change, bypassing git
argocd app get guestbook   # should show OutOfSync
# with auto-sync enabled, ArgoCD reverts it back to what git says within seconds
argocd app set guestbook --sync-policy automated --self-heal
kubectl scale deployment guestbook-ui --replicas=5
sleep 15
kubectl get deployment guestbook-ui   # back to git's replica count

Notes

(fill in your own words after watching + labbing)

📋 Self-Assessment Mastery Checklist (4 Competencies)
🧠 Practice Exam Questions (Module 21 MCQs)
⚡ Take Quiz & Save Progress in Tracker

Review these sample exam questions out loud, test your retrieval, and then unlock official scoring in the interactive tracker.

Question 1: GitOps means:
  • A. Git is the source of truth; cluster reconciles to it
  • B. Only CI builds images
  • C. SSH is the only deploy method
  • D. Helm cannot be used
✓ Correct Answer: A (Git is the source of truth; cluster reconciles to it)
Option A ('Git is the source of truth; cluster reconciles to it') is the standard production architectural best practice.
Question 2: Argo CD / Flux primarily:
  • A. Continuously sync cluster state from Git
  • B. Replace kubelet
  • C. Store metrics long-term
  • D. Provision cloud VMs only
✓ Correct Answer: A (Continuously sync cluster state from Git)
Option A ('Continuously sync cluster state from Git') is the standard production architectural best practice.
Question 3: A drift detection benefit of GitOps is:
  • A. Seeing when live state differs from Git
  • B. Faster etcd
  • C. Automatic CIS scans
  • D. Free certificates
✓ Correct Answer: A (Seeing when live state differs from Git)
Option A ('Seeing when live state differs from Git') is the standard production architectural best practice.
Question 4: PR-based changes improve:
  • A. Reviewability and auditability of cluster changes
  • B. Pod DNS speed
  • C. CNI throughput
  • D. PVC latency
✓ Correct Answer: A (Reviewability and auditability of cluster changes)
Option A ('Reviewability and auditability of cluster changes') is the standard production architectural best practice.
Question 5: App of Apps / root app patterns help:
  • A. Manage many applications hierarchically
  • B. Replace Namespaces
  • C. Disable RBAC
  • D. Bypass admission controls
✓ Correct Answer: A (Manage many applications hierarchically)
Option A ('Manage many applications hierarchically') is the standard production architectural best practice.
← Previous Module (20) CRDs & Custom Controllers/Operators Next Module (22) → Autoscaling (HPA, VPA, Cluster Autoscaler, KEDA)