GitOps with Argo CD
The cluster as a copy of a Git repository: sync, drift and rollback.
An interactive Kubernetes lesson: 21 steps, about 30 minutes, on a live simulation in your browser.
You run the shop's website. Three copies of web serve customers through a NodePort Service on port 30080. Every deploy is someone on the team running helm install or helm upgrade from their laptop, with a values file that lives on the same laptop.
It works. Customer requests flow and every one returns 200. Watch that traffic line as the lesson goes on: it stays green through most of what follows, which is exactly why the problems ahead go unnoticed for so long.
What you will learn
Deploys by hand
- The shop runs on hand applies: A hand deploy sends files to the cluster. Nothing records which files, from whose laptop, or in which order.
- Two laptops, two truths: If the values are not in git, the release cannot be rebuilt from scratch. The laptop is a single point of failure.
- A hotfix at midnight: Live edits fix the cluster and leave the repo behind. From that moment the two disagree.
Drift
- Argo CD moves in: GitOps means the repo is the desired state and the cluster is measured against it. Drift is any difference between the two.
- Break it: five where git says three
- Nobody presses sync
- Read the diff before the sync
The Application object
- One object points at git: An Application says: this repo, this revision, this cluster. Everything Argo CD does follows from those three lines.
- What a branch revision follows: targetRevision picks the commit. A branch follows movement; a tag or SHA pins one commit.
- Press sync: A sync writes git onto the cluster. Live edits are overwritten, never merged.
Drift correction
- Three switches: auto, prune, heal: Automated sync closes the loop. Prune deletes what git removed. SelfHeal reverts what hands changed.
- Break it: down to one by hand
- SelfHeal notices: SelfHeal makes live edits temporary. The cluster converges back to git on its own.
- Prune deletes the stray: Prune deletes what git stopped asking for. It never touches what git never owned.
- Drill: sync one app by hand
Rollback with Git and Helm
- Break it: the tag that was never pushed
- Revert the commit, not the cluster: Roll back the repo, not the cluster. The sync carries the fix wherever the app runs.
- Git says why, Helm says what: Git is the intent: who meant what, and why. The release history is the fact: what the cluster actually ran.
- Drill: read the release history
Recap & playground
- Cheat sheet
- Playground