Part 5 · 1 chapters · ~8 min

GitOps and Promotion Between Environments

GitOps principles, Argo CD and Flux, repository layouts per environment, CI that commits instead of deploying, promotion as reviewed commits, drift detection and self-healing, and rollback by revert.

6

Pull-based delivery

code
# repository layout
config/
  base/ledger/            deployment.yaml, service.yaml, rollout.yaml
  envs/dev/ledger/        kustomization.yaml  → image: ledger:1.43
  envs/staging/ledger/    kustomization.yaml  → image: ledger:1.42
  envs/prod/ledger/       kustomization.yaml  → image: ledger:1.41   (promotion PR open: 1.42)

# Argo CD Application
spec:
  source: { repoURL: https://git.example.com/config, path: envs/prod/ledger }
  destination: { server: https://kubernetes.default.svc, namespace: ledger }
  syncPolicy: { automated: { prune: true, selfHeal: true } }
GITOPS AND PROMOTION
the desired state lives in Git; an agent in each cluster makes reality match
bump tagCIbuild image ledger:1.42config repoenvs/dev, staging, proddev clusterArgo CDstaging clusterArgo CDprod clusterArgo CD
swipe the figure sideways, or tap expand for full screen
1/5
CI builds, not deploys
CI tests and builds an immutable image, then opens a commit (or PR) bumping the image tag in the config repository. CI never holds production credentials.
CI writes a commit, not to clustersno prod credentials in CI