GitOps
Declared desired state in version control, with a reconciler closing the gap continuously.
5 to work through
-
intermediate
A platform adopts a declarative, git-driven deployment model. What does it improve, and what does it not solve?
2 min answer -
intermediate
A platform manages infrastructure declaratively and production has diverged from the declarations. Is that a failure of discipline?
2 min answer -
intermediate
You are adopting GitOps. Someone asks how secrets work, since the repository is the source of truth. What are the options and which do you choose?
2 min answer -
advanced
During an incident an engineer edits a live Kubernetes resource and the change is reverted a minute later by the GitOps controller. The incident continues. What is your position?
2 min answer -
advanced
On 14 March 2023 a Kubernetes upgrade at Reddit caused an outage of about 314 minutes. The upgrade removed a node label that an internal network component had been selecting on, and that component's configuration had been hand-edited through a CLI and committed nowhere. Where do you start investigating, and what is the diagnosis?
3 min answer
2 terms in this topic
GitOps
Declaring desired infrastructure state in version control and letting an in-cluster agent continuously reconcile reality to it.
patternReconciliation Loop
A controller that continuously compares declared state with actual state and acts to close the gap, replacing deployment as an event with convergence…
Neighbouring topics
Delivery & Release Engineering
General material on getting a change from commit to production safely and often.
Pipeline Architecture
Stages, fan-out, caching, and the difference between a pipeline and a long script.
Build Reproducibility
Pinned inputs and hermetic builds, so one commit cannot produce two different artifacts.
Artifact Management
Immutable versioned outputs, promotion between repositories, and retention policy.
Environment Strategy
How many environments earn their cost, what each proves, and what none of them prove.
Branching Models
GitFlow, trunk and release branches as delivery constraints rather than Git preferences.
Continuous Integration Discipline
Integrating to the mainline daily, and the test speed and review culture that requires.
Deployment Strategies
Rolling, blue-green, canary and shadow, and the traffic and state each one assumes.
Progressive Delivery
Separating deploy from release, and exposing a change to users in controlled increments.
Rollback & Forward Fix
When reversing is genuinely possible, and designing so that it usually is.
Database Migration Under CD
Expand-contract, backwards-compatible schema change, and migrations that cannot roll back.
IaC Modules & Drift
Reusable infrastructure modules, state ownership, and detecting what changed out of band.
Policy as Code
Encoding standards as automated admission and plan-time checks instead of review comments.
Pipeline Secrets
Short-lived credentials, workload identity, and why the CI system is a prime target.
Supply-Chain Provenance
SBOMs, signed artifacts, attestation, and knowing what actually went into a build.
Deployment Gates
Automated verification between stages, and the difference between a gate and a delay.
Flow Metrics
Work in progress, flow time and flow efficiency — where a change waits rather than moves.
Change Management vs CD
Reconciling CAB-era controls with continuous delivery without pretending either away.
Multi-Region Rollout
Ordering regions, bake time, and stopping a bad change before it becomes global.