What Is GitOps? One Sentence

Cloud Engineering Architecture

GitOps is a practice where Git is the single source of truth for what should be running in your infrastructure โ€” and an automated system continuously ensures that what's running matches what's in Git.

The Traditional vs GitOps Deployment Flow

Traditional (Push-based): CI pipeline builds image โ†’ pipeline SSHs into server or uses kubectl โ†’ applies changes. If someone manually edits a resource in the cluster, nobody knows. Drift happens silently.

GitOps (Pull-based): CI pipeline builds image โ†’ updates image tag in Git (your "desired state repo") โ†’ ArgoCD running in the cluster detects the change โ†’ pulls and applies it. If someone manually changes the cluster, ArgoCD detects "drift" and reverts it or alerts you.

Setting Up ArgoCD

# Install ArgoCD in your K8s cluster
kubectl create namespace argocd
kubectl apply -n argocd -f \
  https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml

# Get the admin password
kubectl -n argocd get secret argocd-initial-admin-secret \
  -o jsonpath="{.data.password}" | base64 -d

# Port-forward to access UI
kubectl port-forward svc/argocd-server -n argocd 8080:443

Creating an ArgoCD Application

apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: my-app
  namespace: argocd
spec:
  project: default
  source:
    repoURL: https://github.com/yourorg/your-app-manifests.git
    targetRevision: main
    path: manifests/production
  destination:
    server: https://kubernetes.default.svc
    namespace: production
  syncPolicy:
    automated:
      prune: true      # Delete resources removed from Git
      selfHeal: true   # Revert manual changes to cluster
    syncOptions:
      - CreateNamespace=true

The GitOps Workflow in Practice

  1. Developer merges a PR to main
  2. CI pipeline runs: build โ†’ test โ†’ Docker push (new image tag: sha-abc123)
  3. CI pipeline opens a PR in your manifests repo to update the image tag
  4. Tech lead reviews and merges the manifest PR
  5. ArgoCD detects the change in the manifests repo within 3 minutes
  6. ArgoCD applies the new deployment to the cluster automatically
  7. ArgoCD shows "Synced" in its UI. If something fails, it shows the error immediately.
๐Ÿ’ก Quick Answer: GitOps uses Git as the single source of truth for infrastructure state. Tools like ArgoCD continuously compare what's in Git with what's running in Kubernetes and automatically apply any differences. Benefits: full audit trail, automatic drift detection, easy rollback (just revert the Git commit), and declarative infrastructure management.