TT Lab
Get started
Learn Learning paths Courses

CGOA — GitOps Certified Associate

Who turned automation back on?

Continue in TT Lab

Goal

You distinguish the loop in which an ApplicationSet reconciles Applications from the loop in which an Application reconciles Git to actual objects.

Why it matters

Even if you turn automation off on the child, the parent can turn it back on, and even if you turn automated apply off, a manual request can still be applied. You do not change the production LabHub or external repositories. You use only the cgoa-appset-ownership Namespace on your personal VM, one parent, one child, one independent Application, and two small ConfigMaps. Do not delete the Namespace, the ApplicationSet, or the Applications. Do not change global controller, RBAC, network, or security settings either. It is a 55-minute lab. If needed, extend the time before it expires and keep your observations. When the session ends, the VM and files are reclaimed.

Prepared environment and helper

The parent is cgoa-appset-ownership, the child is cgoa-appset-ownership-alpha, and the independent control is cgoa-appset-ownership-sentinel. Git is /srv/cgoa-appset-ownership, and the remote inside the VM is /srv/bare/cgoa-appset-ownership.git. The child reads apps/alpha, and the control reads the sentinel directory. You do not use external Git or a production API. The parent ApplicationSet itself is a bootstrap in which the helper directly applies /root/cgoa-appset-ownership-source.json. It is not an environment that implements a third loop in which a higher-level Application also manages the parent with Git. Student files are in /root/cgoa-appset. The key=value in the tasks is explanatory, and for the JSON files follow the format examples. python3 /opt/fixtures/cgoa_appset_lab.py observe reads the current parent, child, Git, and ConfigMaps. complete N reviews the answer you wrote and records a bounded action and the actual observation. Step 2 is the child toggle, 3 is stopping the parent, 4 is the Git change, 5 is the manual apply, 6 is the parent's narrow exception, and 7 is ending the exception and the new Git. Check the changed files and the commit lineage with git show. Git changes happen only in steps 4 and 7. solve N is the same as the solution view and fills in only the current answer that is missing. It does not modify an existing wrong answer or a partial answer. prepare N prepares only the earlier steps and does not create the current answer. grade N only reads and does not re-run changes.

Steps

  1. Read parent.uid and child.uid from baseline.json. In parent_uid and child_uid of ownership.json, write the corresponding strings and run complete 1. In observation-1.json, check that child.owners points to the same parent UID and that the sentinel is an independent Application. The ConfigMap's tracking annotation shows which Application manages it.
  2. In child.json, write target_uid=the baseline child UID string and the booleans enabled=false and expected_reverted=true, and run complete 2. Compare the false in effect.patch_receipt with the true in result.snapshot.child. Check that the UID is the same but the resourceVersion is different. Distinguish the case where the request itself was rejected from the case where the parent reverted it.
  3. In parent.json, write the string change_source=parent-template and the boolean enabled=false, and run complete 3. The helper modifies and applies the parent's source declaration file. Read the three samples in which the enabled of both the parent and the child is false and the data one is maintained. The independent sentinel's policy and data must not change.
  4. In git.json, write the strings release=two and expected_live=one and the boolean will_apply_automatically=false, and run complete 4. Only apps/alpha/config.json in Git changes. Check the three samples in which the new SHA appears in child.status.sync.revision but it is OutOfSync and the actual value is one. This is different from a failure to read the new commit.
  5. Read result.snapshot.revision in observation-4.json. In manual.json, write revision=that SHA, child_uid=the baseline child UID string, and the boolean manual_allowed=true, and run complete 5. It requests a manual operation for the commit you reviewed. Cross-check effect.request_receipt with the actual data two and the enabled that is still false. The request metadata alone does not prove user authentication.
  6. In exception.json, write the strings app_name=cgoa-appset-ownership-alpha and json_pointer=/spec/syncPolicy/automated/enabled and the booleans parent_enabled=true and child_enabled=false, and run complete 6. The parent template is true, but because of a one-field exception specified by name, the child remains false. Read the parent's ignoreApplicationDifferences and the three observations.
  7. In resume.json, write the boolean remove_exception=true and the string release=three, and run complete 7. After the exception is removed, check that enabled of both parent and child is true, and create a new Git commit. Check the actual data three and the operation success for the current commit. Do not judge the return to automation from an earlier manual success or the existing Synced alone.
  8. In decision.json, write the booleans automatic_resumed=true, manual_blocked=false, all_paths_frozen=false, and samples_guarantee=false, and run complete 8. Check that the parent, child, and ConfigMap UIDs and the independent sentinel were preserved. Report separately stopping automation, a freeze on all changes, short samples, and a long-term guarantee.

Notes and limits

Do not edit the completion input or the observations yourself. The files from earlier steps are also the basis for later grading. If a pending journal remains, an interrupted request is not automatically re-run. Keep the material and start over in a new lab. If the request completed but only the observation failed, it retries only the observation on the same commit and does not repeat the same apply. Steps 3, 4, and 6 are three samples taken at intervals. This is not a freeze on changes through every path or a guarantee of indefinite maintenance. initiatedBy is request metadata. Judge whether it was manual by looking together at the request receipt, the policy, and the actual change on the same commit. The hashes detect accidental overwriting of records, but they are not a security guarantee that blocks every forgery by root on the same VM. Grading has a budget of 60 seconds, and preparing earlier steps has a budget of 90 seconds. Complete handles the waiting. ApplicationSet resource modification control · kubectl sync request.

Checking the owners of the two reconcile loops

Read parent.uid and child.uid from baseline.json. In parent_uid and child_uid of ownership.json, write the corresponding strings and run complete 1. In observation-1.json, check that child.owners points to the same parent UID and that the sentinel is an independent Application. The ConfigMap's tracking annotation shows which Application manages it.

Check the UID of ownerReferences, not just the name.

Observing automation turned off on the child turning back on

In child.json, write target_uid=the baseline child UID string and the booleans enabled=false and expected_reverted=true, and run complete 2. Compare the false in effect.patch_receipt with the true in result.snapshot.child. Check that the UID is the same but the resourceVersion is different. Distinguish the case where the request itself was rejected from the case where the parent reverted it.

Look side by side at the value in the patch response and the value read later.

Stopping automation in the parent template

In parent.json, write the string change_source=parent-template and the boolean enabled=false, and run complete 3. The helper modifies and applies the parent's source declaration file. Read the three samples in which the enabled of both the parent and the child is false and the data one is maintained. The independent sentinel's policy and data must not change.

Check the template that generates the child, not the child.

Confirming the difference between Git comparison and automated apply

In git.json, write the strings release=two and expected_live=one and the boolean will_apply_automatically=false, and run complete 4. Only apps/alpha/config.json in Git changes. Check the three samples in which the new SHA appears in child.status.sync.revision but it is OutOfSync and the actual value is one. This is different from a failure to read the new commit.

The current comparison revision and the actual ConfigMap data are different pieces of evidence.

Syncing manually with automation off

Read result.snapshot.revision in observation-4.json. In manual.json, write revision=that SHA, child_uid=the baseline child UID string, and the boolean manual_allowed=true, and run complete 5. It requests a manual operation for the commit you reviewed. Cross-check effect.request_receipt with the actual data two and the enabled that is still false. The request metadata alone does not prove user authentication.

operation is a top-level request field of the Application.

Making one field of a specific child a temporary exception

In exception.json, write the strings app_name=cgoa-appset-ownership-alpha and json_pointer=/spec/syncPolicy/automated/enabled and the booleans parent_enabled=true and child_enabled=false, and run complete 6. The parent template is true, but because of a one-field exception specified by name, the child remains false. Read the parent's ignoreApplicationDifferences and the three observations.

Limit it by both name and jsonPointer together.

Removing the exception and verifying automation with a new change

In resume.json, write the boolean remove_exception=true and the string release=three, and run complete 7. After the exception is removed, check that enabled of both parent and child is true, and create a new Git commit. Check the actual data three and the operation success for the current commit. Do not judge the return to automation from an earlier manual success or the existing Synced alone.

You need an actual reflection of the new Git target.

Reporting the scope and limits of maintenance mode

In decision.json, write the booleans automatic_resumed=true, manual_blocked=false, all_paths_frozen=false, and samples_guarantee=false, and run complete 8. Check that the parent, child, and ConfigMap UIDs and the independent sentinel were preserved. Report separately stopping automation, a freeze on all changes, short samples, and a long-term guarantee.

Turning automated apply off does not mean manual permission is gone too.