GitOps Explained in Simple Words (ArgoCD + Real Demo)
What Is GitOps? One Sentence
GitOps is a practice where Git is the single source of truth for what should be running in your infrastructure โ and an automated system continuously ensures that what's running matches what's in Git.
The Traditional vs GitOps Deployment Flow
Traditional (Push-based): CI pipeline builds image โ pipeline SSHs into server or uses kubectl โ applies changes. If someone manually edits a resource in the cluster, nobody knows. Drift happens silently.
GitOps (Pull-based): CI pipeline builds image โ updates image tag in Git (your "desired state repo") โ ArgoCD running in the cluster detects the change โ pulls and applies it. If someone manually changes the cluster, ArgoCD detects "drift" and reverts it or alerts you.
Setting Up ArgoCD
# Install ArgoCD in your K8s cluster
kubectl create namespace argocd
kubectl apply -n argocd -f \
https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml
# Get the admin password
kubectl -n argocd get secret argocd-initial-admin-secret \
-o jsonpath="{.data.password}" | base64 -d
# Port-forward to access UI
kubectl port-forward svc/argocd-server -n argocd 8080:443
Creating an ArgoCD Application
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: my-app
namespace: argocd
spec:
project: default
source:
repoURL: https://github.com/yourorg/your-app-manifests.git
targetRevision: main
path: manifests/production
destination:
server: https://kubernetes.default.svc
namespace: production
syncPolicy:
automated:
prune: true # Delete resources removed from Git
selfHeal: true # Revert manual changes to cluster
syncOptions:
- CreateNamespace=true
The GitOps Workflow in Practice
- Developer merges a PR to main
- CI pipeline runs: build โ test โ Docker push (new image tag:
sha-abc123) - CI pipeline opens a PR in your manifests repo to update the image tag
- Tech lead reviews and merges the manifest PR
- ArgoCD detects the change in the manifests repo within 3 minutes
- ArgoCD applies the new deployment to the cluster automatically
- ArgoCD shows "Synced" in its UI. If something fails, it shows the error immediately.