ЁЯПл The SchoolтА║ЁЯдЦ ArgoCDтА║ЁЯУЦ рдзрдбрд╛ 05 тАФ GitOps рдХрд▓реНрдкрдирд╛: рд╡рд╛рд╕реНрддрд╡ рдкреБрд╕реНрддрдХрд╛рд╢реА рдЬреБрд│рд▓реЗрдЪ рдкрд╛рд╣рд┐рдЬреЗ
ЁЯЦ╝я╕П See the drawing + lab ЁЯПа Course home ЁЯМ┐ Branch on GitHub тЬПя╕П View source
ЁЯЦ╝я╕П рдЖрдХреГрддреА рдЖрдгрд┐ labThe drawing + lab рдкреВрд░реНрдг рдкрд╛рдирд╛рд╡рд░ рдЙрдШрдбрд╛ тЖЧOpen full page тЖЧ

ЁЯУЦ рдзрдбрд╛ 05 тАФ GitOps рдХрд▓реНрдкрдирд╛: рд╡рд╛рд╕реНрддрд╡ рдкреБрд╕реНрддрдХрд╛рд╢реА рдЬреБрд│рд▓реЗрдЪ рдкрд╛рд╣рд┐рдЬреЗ

ЁЯУН рддреБрдореНрд╣реА рдЗрдереЗ рдЖрд╣рд╛рдд: 12 рдкреИрдХреА рдзрдбрд╛ 05 тАФ рднрд╛рдЧ 2 рд╕реБрд░реВ! ┬╖ рдорд╛рдЧреЗ: lesson-04-limits-of-push ┬╖ рдкреБрдвреЗ: lesson-06-install-argocd


ЁЯУж рдпрд╛ рдмреНрд░рдБрдЪрдордзреНрдпреЗ рдХрд╛рдп рдЖрд╣реЗ

рдзрдбреЗ 01тАУ04, рдЖрдгрд┐ рддреНрдпрд╛рд╕реЛрдмрдд рдЪрд╛рд░рд╣реА рдЦрдбреНрдбреЗ рдПрдХрд╛рдЪ рд╡реЗрд│реА рдмреБрдЬрд╡рдгрд╛рд░реА рдореЛрдареА рдХрд▓реНрдкрдирд╛: GitOps тАФ git рд╣реЗ рдПрдХрдореЗрд╡ source of truth, рдЖрдгрд┐ cluster рдЪреНрдпрд╛ рдЖрдд рд░рд╛рд╣рдгрд╛рд░рд╛ agent рддреЗ рдЕрдВрдорд▓рд╛рдд рдЖрдгрддреЛ.

ЁЯзТ 5 рд╡рд░реНрд╖рд╛рдВрдЪреНрдпрд╛ рдореБрд▓рд╛рд▓рд╛ рд╕рдордЬрд╛рд╡рд▓реНрдпрд╛рд╕рд╛рд░рдЦреЗ

рд╢рд╛рд│рд╛ рдПрдХрдЪ рдореБрдЦреНрдп рдкреНрд▓реЕрди-рд╡рд╣реА ЁЯУЦ рд▓рд┐рд╣рд┐рддреЗ рдЖрдгрд┐ рддреА рдЧреНрд░рдВрдерд╛рд▓рдпрд╛рдд рдареЗрд╡рддреЗ (git). рдкреНрд░рддреНрдпреЗрдХ рдЦреЛрд▓реА рдиреЗрдордХреА рдХрд╢реА рджрд┐рд╕рд╛рдпрд▓рд╛ рд╣рд╡реА рддреЗ рд╡рд╣реА рд╕рд╛рдВрдЧрддреЗ: рдЦреБрд░реНрдЪреНрдпрд╛, рдкреЛрд╕реНрдЯрд░реНрд╕, рдЭрд╛рдбрд╛рдВрдирд╛ рдкрд╛рдгреА рдШрд╛рд▓рдгрд╛рд░реЗ, projector рдЪреНрдпрд╛ рдЬрд╛рдЧрд╛.

рдЖрдгрд┐ рдЗрдереЗ рдпреБрдХреНрддреА рдЖрд╣реЗ тАФ рд╢рд╛рд│рд╛ рдПрдХ рдХреЗрдЕрд░рдЯреЗрдХрд░ ЁЯдЦ рдХрд╛рдорд╛рд╡рд░ рдареЗрд╡рддреЗ рдЬреЛ рдЗрдорд╛рд░рддреАрддрдЪ рд░рд╛рд╣рддреЛ рдЖрдгрд┐ рдЬреНрдпрд╛рдЪреЗ рдПрдХрдЪ рдХрд╛рдо рдЖрд╣реЗ, рдХрд╛рдпрдо рдкреБрдиреНрд╣рд╛ рдкреБрдиреНрд╣рд╛:

рд╡рд╣реА рд╡рд╛рдЪрд╛. рд╡реНрд╣рд░рд╛рдВрдбреНрдпрд╛рддреВрди рдлрд┐рд░рд╛. рдЦреЛрд▓реНрдпрд╛ рд╡рд╣реАрд╢реА рдЬреБрд│рд╡рд╛. рдкреБрдиреНрд╣рд╛ рдХрд░рд╛.

рдЖрддрд╛ рд╕рдЧрд│реНрдпрд╛рдЪреЗрдЪ рд╕реНрд╡рд░реВрдк рдмрджрд▓рддреЗ:

рдзрдбрд╛ 04 рдордзрд▓реЗ рдЪрд╛рд░ рдЦрдбреНрдбреЗ. рдЪрд╛рд░ рдЙрдкрд╛рдп. рдПрдХ рдХрд▓реНрдкрдирд╛.

ЁЯЧ║я╕П рдЖрдХреГрддреА

flowchart LR
    book["ЁЯУЦ git repo<br/>DESIRED state - the book<br/>reviewed PRs, full history"]
    agent(("ЁЯФД agent<br/>compare and converge"))
    cluster["ЁЯПл cluster<br/>ACTUAL state - the rooms"]
    book -->|"1 reads the book"| agent
    cluster -->|"2 looks at the rooms"| agent
    agent -->|"3 fixes any difference"| cluster
    agent -.->|"4 repeat every ~3 min, forever"| agent

тЭУ рдХрд╛рдп

GitOps = рдЪрд╛рд░ рдирд┐рдпрдо (OpenGitOps project рдиреЗ рдард░рд╡рд▓реНрдпрд╛рдкреНрд░рдорд╛рдгреЗ):

  1. Declarative тАФ рд╕рдВрдкреВрд░реНрдг system files рдЪреНрдпрд╛ рд░реВрдкрд╛рдд рд╡рд░реНрдгрди рдХреЗрд▓реЗрд▓реА рдЕрд╕рддреЗ (рд╣реЗ рддреБрдордЪреНрдпрд╛рдХрдбреЗ рдзрдбрд╛ 01 рдкрд╛рд╕реВрдирдЪ рдЖрд╣реЗ тАФ рддреБрдордЪрд╛ k8s/ folder).
  2. Versioned & immutable тАФ рддреНрдпрд╛ files git рдордзреНрдпреЗ рд░рд╛рд╣рддрд╛рдд: history, blame, review, revert.
  3. Pulled automatically тАФ cluster рдЪреНрдпрд╛ рдЖрддрд▓рд╛ agent рдЗрдЪреНрдЫрд┐рдд рд╕реНрдерд┐рддреА рд╕реНрд╡рддрдГрдЪ рдЖрдгрддреЛ. рдмрд╛рд╣реЗрд░рдЪреА рдХреЛрдгрддреАрд╣реА system key рдШреЗрдКрди push рдХрд░рдд рдирд╛рд╣реА.
  4. Continuously reconciled тАФ agent рдХрд╛рдпрдо рддреБрд▓рдирд╛ рдХрд░рддреЛ рдЖрдгрд┐ рдЬреБрд│рд╡рддреЛ, рдлрдХреНрдд deploy рдЪреНрдпрд╛ рдХреНрд╖рдгреА рдирд╛рд╣реА.

рдирд┐рдпрдо 1тАУ2 рддреБрдордЪреНрдпрд╛рдХрдбреЗ рдЖрдзреАрдкрд╛рд╕реВрдирдЪ рд╣реЛрддреЗ. рдирд┐рдпрдо 3тАУ4 рдпрд╛ рдирд╡реНрдпрд╛ рдорд╣рд╛рд╢рдХреНрддреА рдЖрд╣реЗрдд тАФ рдЖрдгрд┐ рддреНрдпрд╛ рдУрд│рдЦреАрдЪреНрдпрд╛ рд╡рд╛рдЯрдд рдЕрд╕рддреАрд▓ рддрд░: Deployment "replicas: 2" рд▓рд╛ рдЕрдЧрджреА рдЕрд╕реЗрдЪ рд╡рд╛рдЧрд╡рддреЗ (k8s рдХреЛрд░реНрд╕, рдзрдбрд╛ 03). GitOps рд╣рд╛рдЪ reconcile loop рддреБрдордЪреНрдпрд╛ рд╕рдВрдкреВрд░реНрдг cluster рд▓рд╛ рд▓рд╛рдЧреВ рдХрд░рддреЗ, git рд▓рд╛ рдЗрдЪреНрдЫрд┐рдд рд╕реНрдерд┐рддреА рдорд╛рдиреВрди.

ЁЯдФ рдХрд╛

рдХрд╛рд░рдг рддреЗ push model рдЪреЗ рдЪрд╛рд░рд╣реА рдЦрдбреНрдбреЗ рд╕рдорд╕реНрдпрд╛рдЪ рдЙрд░реВ рджреЗрдд рдирд╛рд╣реА: drift тЖТ рд╕рддрдд рдЙрд▓рдЯрд╡рд▓рд╛ рдЬрд╛рддреЛ ┬╖ рдмрд╛рд╣реЗрд░реВрди рдпреЗрдгрд╛рд░реЗ deployment credentials тЖТ agent рдЖрддреВрди pull рдХрд░рддреЛ ┬╖ рджрд╣рд╛ clusters тЖТ рджрд╣рд╛ agents, рдкреНрд░рддреНрдпреЗрдХ рдПрдХрд╛рдЪ repo рдордзреВрди pull рдХрд░рддреЛ ┬╖ "рдХрд╛рдп рдЪрд╛рд▓реВ рдЖрд╣реЗ?" тЖТ рд╡рд╣реА, рдЖрдгрд┐ agent рдЪреА рд╕реНрд╡рддрдГрдЪреА sync history. Deploys рдЖрддрд╛ рдХреЛрдгреАрддрд░реА рдХрд░рд╛рдпрдЪреНрдпрд╛ рдШрдЯрдирд╛ рд░рд╛рд╣рдд рдирд╛рд╣реАрдд, рддрд░ рдХреЛрдгреАрддрд░реА commit рдХреЗрд▓реЗрд▓реА рддрдереНрдпреЗ рдмрдирддрд╛рдд.

ЁЯФз рдХрд╕реЗ (рдпрд╛ repo рдордзреНрдпреЗ)

рдЕрдЬреВрди рдХрд╛рд╣реАрдЪ install рдХрд░рд╛рдпрдЪреЗ рдирд╛рд╣реА тАФ рд╣рд╛ рдзрдбрд╛ рдореНрд╣рдгрдЬреЗ рдордирд╛рддрд▓реЗ model. рдкрдг рд▓рдХреНрд╖рд╛рдд рдШреНрдпрд╛ рдХреА repo рдЖрдзреАрдЪ GitOps рдЪреНрдпрд╛ рдЖрдХрд╛рд░рд╛рдд рдЖрд╣реЗ: k8s/ рд╣реЗ app рдЪреЗ рд╕рдВрдкреВрд░реНрдг declarative рд╡рд░реНрдгрди рдЖрд╣реЗ (рдирд┐рдпрдо 1), git рдордзреНрдпреЗ versioned (рдирд┐рдпрдо 2). рдзрдбреЗ 06тАУ07 agent рдЬреЛрдбрддрд╛рдд (рдирд┐рдпрдо 3тАУ4): ArgoCD + рдПрдХ Application file.

ЁЯзк рдХрд░реВрди рдкрд╛рд╣рд╛ (рдХрд╛рдЧрджрд╛рд╡рд░рдЪрд╛ рд╕рд░рд╛рд╡, 2 рдорд┐рдирд┐рдЯреЗ)

# GitOps quiz тАФ answer each with "edit the book" or "touch the room":
#   Q1: you want 3 replicas instead of 2            тЖТ ?
#   Q2: prod is on fire, revert last night's change тЖТ ?
#   Q3: auditor asks who changed the memory limit   тЖТ ?
# answers: book (git commit), book (git revert), book (git log -p k8s/)
git log --oneline -- k8s/    # тЖР the book's history: your future desired-state history

тЬЕ рддрдкрд╛рд╕рд╛ тАФ рддреБрдореНрд╣рд╛рд▓рд╛ рдХрд╛рдп рджрд┐рд╕рд╛рдпрд▓рд╛ рд╣рд╡реЗ

рдХрд╛рдЧрджрд╛рд╡рд░рдЪрд╛ рд╕рд░рд╛рд╡: рддрд┐рдиреНрд╣реА рдЙрддреНрддрд░реЗ "рд╡рд╣реА" рдЖрд╣реЗрдд. git log --oneline -- k8s/ manifests рдирд╛ рд╕реНрдкрд░реНрд╢ рдХреЗрд▓реЗрд▓реЗ commits рдЫрд╛рдкрддреЗ тАФ рддреА рдпрд╛рджреА рдореНрд╣рдгрдЬреЗ рддреБрдордЪреНрдпрд╛ рднрд╡рд┐рд╖реНрдпрд╛рддрд▓реНрдпрд╛ рдЗрдЪреНрдЫрд┐рдд-рд╕реНрдерд┐рддреА history рдЪрд╛ рдЖрдХрд╛рд░.

ЁЯз╣ рд╕рд╛рдлрд╕рдлрд╛рдИ

рдХрд╛рд╣реАрдЪ рд╕рд╛рдл рдХрд░рд╛рдпрдЪреЗ рдирд╛рд╣реА тАФ рдпрд╛ рдзрдбреНрдпрд╛рдд cluster рдордзреНрдпреЗ рдХреЛрдгрддрд╛рд╣реА рдмрджрд▓ рдирд╛рд╣реА.

тЪая╕П рдиреЗрд╣рдореАрдЪреНрдпрд╛ рдЪреБрдХрд╛

ЁЯПн рдкреНрд░рддреНрдпрдХреНрд╖ рд╡рд╛рдкрд░рд╛рдд рд╣реЗ рдХрд╛ рдорд╣рддреНрддреНрд╡рд╛рдЪреЗ рдЖрд╣реЗ: GitOps on-call рдЪрд╛ рдкреНрд░рд╢реНрди "рдХреЛрдгреА рдХрд╛рдп deploy рдХреЗрд▓реЗ?" рд╡рд░реВрди "git рдХрд╛рдп рд╕рд╛рдВрдЧрддреЗ, рдЖрдгрд┐ app Synced рдЖрд╣реЗ рдХрд╛?" рдЕрд╕рд╛ рдмрджрд▓рддреЗ тАФ рдкрдг рдлрдХреНрдд рдкреНрд░рддреНрдпреЗрдХ рдмрджрд▓ рд╡рд╣реАрдордзреВрдирдЪ рдЧреЗрд▓рд╛ рддрд░рдЪ. Prod рдордзреНрдпреЗ рдПрдХ kubectl edit рдХреЗрд▓рд╛ рдХреА рддреБрдореНрд╣реА рдкреБрдиреНрд╣рд╛ рдзрдбрд╛ 02 рдордзреНрдпреЗ рдкреЛрд╣реЛрдЪрддрд╛, рдЬреЛрдкрд░реНрдпрдВрдд selfHeal рд╡реЗрдЧрд│реЗ рдард░рд╡рдд рдирд╛рд╣реА.

тПня╕П рдкреБрдвреЗ

рдХреЗрдЕрд░рдЯреЗрдХрд░рд▓рд╛ рдХрд╛рдорд╛рд╡рд░ рдареЗрд╡рдгреНрдпрд╛рдЪреА рд╡реЗрд│. ArgoCD рдПрдХрд╛ command рдиреЗ рддреБрдордЪреНрдпрд╛ cluster рдордзреНрдпреЗ install рд╣реЛрддреЛ.

git checkout lesson-06-install-argocd

ЁЯУЦ Lesson 05 тАФ The GitOps idea: reality must match the book

ЁЯУН You are here: Lesson 05 of 12 тАФ Part 2 begins! ┬╖ Previous: lesson-04-limits-of-push ┬╖ Next: lesson-06-install-argocd


ЁЯУж What's in this branch

Lessons 01тАУ04, plus the big idea that fixes all four gaps at once: GitOps тАФ git as the single source of truth, enforced by an agent that lives inside the cluster.

ЁЯзТ Explain like I'm 5

The school writes ONE master plan book ЁЯУЦ and keeps it in the library (git). The book says exactly how every room should look: chairs, posters, plant-waterers, projector positions.

And here's the trick тАФ the school hires a caretaker ЁЯдЦ who lives in the building and has one job, repeated forever:

Read the book. Walk the halls. Make the rooms match the book. Repeat.

Now everything changes shape:

Four gaps from lesson 04. Four fixes. One idea.

ЁЯЧ║я╕П Diagram

flowchart LR
    book["ЁЯУЦ git repo<br/>DESIRED state - the book<br/>reviewed PRs, full history"]
    agent(("ЁЯФД agent<br/>compare and converge"))
    cluster["ЁЯПл cluster<br/>ACTUAL state - the rooms"]
    book -->|"1 reads the book"| agent
    cluster -->|"2 looks at the rooms"| agent
    agent -->|"3 fixes any difference"| cluster
    agent -.->|"4 repeat every ~3 min, forever"| agent

тЭУ What

GitOps = four rules (as codified by the OpenGitOps project):

  1. Declarative тАФ the whole system is described as files (you've had this since lesson 01 тАФ your k8s/ folder).
  2. Versioned & immutable тАФ those files live in git: history, blame, review, revert.
  3. Pulled automatically тАФ an agent inside the cluster fetches the desired state itself. No outside system pushes with a key.
  4. Continuously reconciled тАФ the agent compares & converges forever, not just at deploy moments.

Rules 1тАУ2 you already had. Rules 3тАУ4 are the new superpowers тАФ and if they sound familiar: it's exactly how a Deployment treats "replicas: 2" (k8s course, lesson 03). GitOps applies the same reconcile loop to your entire cluster, with git as the desired state.

ЁЯдФ Why

Because it converts the four push-model gaps into non-problems: drift тЖТ reverted continuously ┬╖ deployment credentials from outside тЖТ the agent pulls from inside ┬╖ ten clusters тЖТ ten agents, each pulling the same repo ┬╖ "what's running?" тЖТ the book, plus the agent's own sync history. Deploys stop being events somebody performs and become facts somebody committed.

ЁЯФз How (in this repo)

Nothing to install yet тАФ this lesson is the mental model. But notice the repo is already GitOps-shaped: k8s/ is a complete declarative description of the app (rule 1), versioned in git (rule 2). Lessons 06тАУ07 add the agent (rules 3тАУ4): ArgoCD + one Application file.

ЁЯзк Try it (a paper exercise, 2 minutes)

# GitOps quiz тАФ answer each with "edit the book" or "touch the room":
#   Q1: you want 3 replicas instead of 2            тЖТ ?
#   Q2: prod is on fire, revert last night's change тЖТ ?
#   Q3: auditor asks who changed the memory limit   тЖТ ?
# answers: book (git commit), book (git revert), book (git log -p k8s/)
git log --oneline -- k8s/    # тЖР the book's history: your future desired-state history

тЬЕ Verify тАФ what you should see

Paper exercise: all three answers are "the book". git log --oneline -- k8s/ prints the commits that touched the manifests тАФ that list is the shape of your future desired-state history.

ЁЯз╣ Clean up

Nothing to clean тАФ no cluster changes in this lesson.

тЪая╕П Common mistakes

ЁЯПн Why this matters in production: GitOps changes the on-call question from "who deployed what?" to "what does git say, and is the app Synced?" тАФ but only if every change goes through the book. One kubectl edit in prod and you are back in lesson 02, until selfHeal says otherwise.

тПня╕П Next

Time to hire the caretaker. ArgoCD installs into your cluster with one command.

git checkout lesson-06-install-argocd
тЖР Previouslimits of pushNext тЖТinstall argocd

This page is the lesson's README from the lesson-05-gitops-idea branch, shown here so the whole School stays on one site. Code files open on GitHub at the same branch.