CGOA — GitOps Certified Associate
Fix Git and the Cluster Follows
This lab runs on a real Argo CD
k3s + Argo CD + a Git server are actually running inside the VM. When you commit to Git, Argo CD reads it and really deploys, and when someone fixes something by hand, it really reverts it.
The fake cluster on which the other labs of the CGOA course run has no Argo CD. So neither drift nor self-healing could happen — everything there is to learn in GitOps was missing.
It takes 4–5 minutes to come up the first time.
What is prepared
작업 사본 /srv/gitops 여기서 고치고 커밋·푸시합니다
원격 git://gitd.gitsrv.svc.cluster.local:9418/app.git
Argo CD argocd 네임스페이스
The Git server is a Pod inside the cluster. Since it mounts /srv/bare as a hostPath, when you push from the VM, Argo CD sees it right away.
Goal
You trigger yourself and confirm four behaviors of GitOps: deployment, change tracking, drift detection, and self-healing.
Why it matters
The core claim of GitOps is one thing. Git is the single source of truth, and the cluster is its copy.
For that claim to hold, two things are needed.
- When you change Git, the cluster must follow (synchronization)
- When you change the cluster, it must go back (self-healing)
The second is especially important. Without self-healing, whatever you fixed directly with kubectl stays, and Git and the cluster quietly drift apart. Then Git is no longer the truth, and at the next deployment that difference blows up all at once.
Steps
- In
/srv/gitops, createapp/deploy.yaml(namespaceshop, Deploymentweb, 2 replicas) and push it, then put in/root/cgo/repo.txtthe proof that the Git server serves it. - Create the
shopApplication (automated,prune,selfHeal) and put in/root/cgo/app.txtthe proof that it is actually deployed. - Change the replicas to 3 in Git and push, and put in
/root/cgo/gitchange.txtthe proof that the cluster follows. Do not fix it directly withkubectl. - Turn off
selfHeal, change the replicas withkubectl, and put in/root/cgo/drift.txtthe proof that it becomesOutOfSync. - Turn
selfHealback on and put in/root/cgo/selfheal.txtthe proof that it reverts. - Put a ConfigMap
extrainto Git and deploy it, then delete it from Git and put in/root/cgo/prune.txtthe proof thatprunedeletes it from the cluster too. - Check the deployment history and put it in
/root/cgo/history.txt, and write what a rollback is in GitOps. - In
/root/cgo/report.md, write three lines,selfheal=yes,prune=yes, andreplicas=, along with an explanation.
Notes
- Pushing is
git -C /srv/gitops push origin main. The remote is already set up. - The interval at which Argo re-reads Git is 3 minutes by default. To avoid waiting, use
argocd app get shop --refreshorkubectl -n argocd patch app shop --type merge -p '{"metadata":{"annotations":{"argocd.argoproj.io/refresh":"hard"}}}'. - You view the status with
kubectl -n argocd get app shop -o jsonpath='{.status.sync.status}'. - Turning
selfHealoff and on iskubectl -n argocd patch app shop --type merge -p '{"spec":{"syncPolicy":{"automated":{"selfHeal":false}}}}'. - Common mistake 1: creating drift in step 4 with
selfHealleft on. It reverts within seconds, so you cannot seeOutOfSync. - Common mistake 2: leaving
pruneon and accidentally deleting a file from Git. It is deleted from the cluster too — that is why the default is off.
For Git to be the source of truth
In /srv/gitops, create app/deploy.yaml (namespace shop, Deployment web, 2 replicas) and push it, then put in /root/cgo/repo.txt the proof that the Git server serves it.
Edit in /srv/gitops, commit, and then push. The remote is the Git server inside the cluster.
Argo reads Git and deploys
Create the shop Application (automated, prune, selfHeal) and put in /root/cgo/app.txt the proof that it is actually deployed.
If you give the Application a syncPolicy.automated, nobody has to press sync.
Change Git and it follows
Change the replicas to 3 in Git and push, and put in /root/cgo/gitchange.txt the proof that the cluster follows. Do not fix it directly with kubectl.
Do not use kubectl. Change Git, push, and then wait for Argo to follow.
Fix it by hand and they diverge
Turn off selfHeal, change the replicas with kubectl, and put in /root/cgo/drift.txt the proof that it becomes OutOfSync.
Turn off selfHeal and create the drift. If it is left on, it reverts within seconds and you cannot see it.
Turn it back on and it reverts
Turn selfHeal back on and put in /root/cgo/selfheal.txt the proof that it reverts.
When you turn on selfHeal, Argo reverts to the value in Git. It takes only a few seconds.
Delete from Git and it is deleted from the cluster
Put a ConfigMap extra into Git and deploy it, then delete it from Git and put in /root/cgo/prune.txt the proof that prune deletes it from the cluster too.
After you put the ConfigMap into Git and deploy it, delete the file from Git and push.
A rollback means rolling back Git
Check the deployment history and put it in /root/cgo/history.txt, and write what a rollback is in GitOps.
The deployment history is in .status.history. But there is a separate way to roll back in GitOps.
What you learned
In /root/cgo/report.md, write three lines, selfheal=yes, prune=yes, and replicas=, along with an explanation.
Along with the three lines selfheal=, prune=, and replicas=, write why Git is the source of truth.