GitOps treats your Git repository as the single source of truth for infrastructure and application state. ArgoCD watches your repo and automatically reconciles your Kubernetes cluster to match. No more manual kubectl applies.
The GitOps Workflow
The core idea is simple: every change goes through a pull request. ArgoCD detects the merged change and applies it to the cluster. If someone makes a manual change via kubectl, ArgoCD reverts it. This gives you a complete audit trail and rollback capability for free.
Installing ArgoCD
kubectl create namespace argocd
kubectl apply -n argocd -f https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml
# Get the initial admin password
argocd admin initial-password -n argocd
# Port forward the UI
kubectl port-forward svc/argocd-server -n argocd 8080:443
Your First Application
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: my-app
namespace: argocd
spec:
project: default
source:
repoURL: https://github.com/org/k8s-manifests
targetRevision: main
path: apps/my-app/overlays/production
destination:
server: https://kubernetes.default.svc
namespace: my-app
syncPolicy:
automated:
prune: true
selfHeal: true
The selfHeal: true setting is what makes GitOps powerful: any drift from the declared state gets automatically corrected.
Repository Structure for Multi-Environment
k8s-manifests/
apps/
my-app/
base/
deployment.yaml
service.yaml
kustomization.yaml
overlays/
staging/
kustomization.yaml
production/
kustomization.yaml
replica-patch.yaml
Best Practices
- Use Kustomize or Helm for environment-specific overrides
- Enable automated sync with pruning for production confidence
- Set up notifications via Slack or PagerDuty for sync failures
- Use ApplicationSets for managing many similar applications
- Store secrets separately using Sealed Secrets or External Secrets Operator