> ## Documentation Index
> Fetch the complete documentation index at: https://notes.kodekloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Continuous Delivery and GitOps Fundamentals

> Overview of continuous delivery and GitOps practices for automating immutable artifact promotion, declarative Git-driven deployments, progressive rollouts, migration safety, policy gates, and platform observability.

Welcome. This lesson extends continuous integration (CI) into the practices of continuous delivery (CD) and GitOps so you can reliably promote software from build to production with automation, traceability, and safety.

We covered building, testing, publishing, and distributing artifacts in CI. After artifacts land in a registry, you need an automated, auditable way to:

* Promote the same immutable artifact through environments (development → QA → staging → production).
* Run environment‑specific validation (smoke tests, capacity/scalability tests, health checks).
* Update deployment manifests and GitOps configuration so clusters reconcile to the desired state.

This combination of CD and GitOps is how teams safely deliver software at scale.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/og-mfTVvAAl8u5l1/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/cd-pipeline-ci-to-live-deployment.jpg?fit=max&auto=format&n=og-mfTVvAAl8u5l1&q=85&s=cc4b7f232237f0778b3e01b9acdc62a4" alt="A slide titled &#x22;CD Pipeline – From CI Success to Live Deployment&#x22; showing the five key stages: Artifact Promotion, Manifest Updates, GitOps Reconciliation, Automated Validation, and Progressive Deployment, each with a short description." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/cd-pipeline-ci-to-live-deployment.jpg" />
</Frame>

Goals of an automated path to production:

* Minimize manual intervention (especially for Kubernetes operations).
* Bake safety and operational checks into the pipeline.
* Enable automated rollback and progressive rollout strategies when failures occur.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/og-mfTVvAAl8u5l1/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/continuous-delivery-automated-path-production.jpg?fit=max&auto=format&n=og-mfTVvAAl8u5l1&q=85&s=0cbb989f09ecfeb11393d6cbee60b12f" alt="A presentation slide titled &#x22;Continuous Delivery – Automated Path to Production&#x22; showing four colored items: Immutable Artifacts, Automated Promotion, Environment Parity, and Safe Rollbacks, each with a short explanatory note. The items describe testing the same artifact, dev→test→staging promotion, consistent deployment scripts, and reversible deployments." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/continuous-delivery-automated-path-production.jpg" />
</Frame>

Database and other stateful-system considerations

* Treat database migration scripts and versioned schemas as first-class artifacts.
* Use automated, versioned migrations that are coordinated with application deployments.
* Prefer backward-compatible migration patterns (expand → migrate → contract) and combine them with feature flags to avoid downtime.

<Callout icon="warning" color="#FF6B6B">
  Database migrations are high risk. Automate and version migrations alongside the application, and validate them with safety patterns (expand-then-migrate-then-contract, feature flags, ordered releases) to avoid outages.
</Callout>

GitOps — four core principles

1. Declarative configuration — manifests in Git are the single source of truth.
2. Automated reconciliation — cluster-side controllers continuously sync live state to the desired state in Git.
3. Pull-based deployments — controllers pull and apply changes securely from Git into clusters.
4. Complete audit trail — commits and pull requests provide traceability for every change.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/og-mfTVvAAl8u5l1/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/gitops-pillars-declarative-automated-pull-audit.jpg?fit=max&auto=format&n=og-mfTVvAAl8u5l1&q=85&s=a09bbffd2a741ebf4c2ce7c08422d20d" alt="A presentation slide titled &#x22;GitOps – Declarative Operations Through Version Control&#x22; showing four pillars (Declarative, Automated Reconciliation, Pull‑Based Deployments, Complete Audit Trail) with colorful icons and brief explanatory text under each." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/gitops-pillars-declarative-automated-pull-audit.jpg" />
</Frame>

How GitOps works in practice

* Store declarative manifests in Git.
* Run a GitOps controller (Argo CD, Flux, Rancher Fleet) inside each cluster.
* The controller pulls repositories and reconciles live cluster state to match Git.
* CI pipelines produce immutable artifacts and can update manifests in Git to reference those artifacts, which triggers reconciliation.

Example workflow:

* Alan (infra engineer) needs to scale a database → he commits Terraform changes to Git.
* An automation tool or controller runs `terraform apply` (via CI job, Atlantis, or a Terraform controller) so the change is applied reproducibly and auditable.

GitOps architecture typically includes the following components:

| Component | Purpose | Examples |
| - | - | - |
| Git repositories | Store application and infrastructure manifests as source of truth | `git` (app repos vs infra repos) |
| GitOps controllers | Reconcile Git → cluster state, pull-based sync | Argo CD, Flux v2, Rancher Fleet |
| Artifact registries | Store immutable images/binaries referenced by manifests | Harbor, ECR, GCR, Docker Hub |
| CI/CD orchestration | Build artifacts and optionally update Git manifests | GitHub Actions, Jenkins, GitLab CI |

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/og-mfTVvAAl8u5l1/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/gitops-architecture-repos-controllers-workflows.jpg?fit=max&auto=format&n=og-mfTVvAAl8u5l1&q=85&s=606600c626c39919257e995a59eb451e" alt="A slide titled &#x22;GitOps Architecture: Repositories, Controllers, and Workflows&#x22; showing four panels: Git Repositories, GitOps Controllers, Artifact Registry, and CI/CD Orchestration. Each panel lists examples and brief notes (e.g., Argo CD/Flux v2 for controllers, Harbor/ECR/GCR for registries)." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/gitops-architecture-repos-controllers-workflows.jpg" />
</Frame>

Integration patterns

* CI-only heavy: CI server updates manifests and triggers deployments directly.
* GitOps-first: CI produces artifacts and updates Git; controllers pull from Git and reconcile.
* Hybrid: CI produces immutable artifacts and updates Git; controllers perform the actual cluster sync and policy enforcement.

Typical CI → GitOps flow

1. Developer pushes a feature branch.
2. CI runs tests and builds an immutable artifact.
3. CI merges into main and tags the artifact (immutable SHA).
4. CI updates the deployment manifest in the GitOps repository to reference that artifact SHA.
5. GitOps controller detects the manifest change and reconciles the cluster, optionally performing policy checks, health probes, and progressive promotions.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/og-mfTVvAAl8u5l1/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/gitops-ci-cd-pipeline-infographic.jpg?fit=max&auto=format&n=og-mfTVvAAl8u5l1&q=85&s=318f6f009483750bdec561460a6d0a28" alt="An infographic titled &#x22;GitOps in Action — From Code Commit to Live Deployment.&#x22; It shows a multistep CI/CD pipeline with colored chevrons and labeled stages like Developer Push, CI Pipeline, GitOps Update, Argo CD Sync, Validation, and Promotion." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/gitops-ci-cd-pipeline-infographic.jpg" />
</Frame>

Choosing a controller and platform tooling

* Argo CD: strong UI, app-centric model, good for teams that want a user-friendly dashboard.
* Flux v2: Git-centric, Kubernetes-native design, integrated with Helm/Kustomize.
* Rancher Fleet: multi-cluster large-scale management.

Build servers (Jenkins, GitHub Actions, GitLab CI, etc.) can orchestrate CI tasks, but dedicated GitOps controllers simplify pull-based reconciliation and ongoing cluster drift detection.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/og-mfTVvAAl8u5l1/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/gitops-controllers-argo-flux-fleet.jpg?fit=max&auto=format&n=og-mfTVvAAl8u5l1&q=85&s=f8358c600357a21c4ad9ab12ef23acbd" alt="A presentation slide titled &#x22;GitOps Controllers: Argo CD, Flux, and Platform Integration&#x22; showing three columns for Argo CD, Flux v2, and Rancher Fleet with each logo and short feature bullets (dashboard UI, Helm/Kustomize support, multi-cluster focus, enterprise/large-scale deployments). The slide is © KodeKloud." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/gitops-controllers-argo-flux-fleet.jpg" />
</Frame>

Immutability and artifact promotion

* Build once, promote the exact same artifact across environments to minimize risk.

Example artifact reference:

```text theme={null}
CI Build
pony-spawner:sha-abc123
```

Using the identical SHA in dev, staging, and production ensures tests and releases operate on the same binary.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/K1_NX_PB-6qgXzeI/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/artifact-promotion-same-sha-environments.jpg?fit=max&auto=format&n=K1_NX_PB-6qgXzeI&q=85&s=cdb1eb136c9375555f63049bb6e6bab4" alt="A slide titled &#x22;Artifact Promotion – Same Binary, Different Environments&#x22; showing four colored boxes (CI Build, Dev, Staging, Production) that illustrate promoting the same artifact SHA across dev, staging, and production environments." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/artifact-promotion-same-sha-environments.jpg" />
</Frame>

Progressive delivery strategies
Choose the strategy that matches your risk profile and traffic characteristics.

| Strategy | How it works | Use case / Tradeoffs |
| - | -: | - |
| Canary | Send a small percentage (e.g., 1–5%) to new version, monitor, then increase | Low initial exposure, good for quick validation |
| Linear | Increase traffic by fixed increments (e.g., +10% every X minutes) | Predictable ramp; schedule-based |
| Blue-Green | Deploy parallel environment, switch 100% traffic when ready | Quick full cutover and rollbacks; requires duplicate infra |

Plan percentages and timing against actual traffic volume and SLAs, and always combine rollouts with health checks and automated rollback triggers.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/og-mfTVvAAl8u5l1/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/progressive-delivery-canary-20-50-100.jpg?fit=max&auto=format&n=og-mfTVvAAl8u5l1&q=85&s=504fc74517b1fa1379134b608e1e3165" alt="A slide titled &#x22;Progressive Delivery – Minimizing Risk With Gradual Rollouts&#x22; showing three colored boxes for 20%, 50%, and 100% traffic. The stages are labeled as initial canary deployment, expanded rollout after validation, and full deployment if metrics remain healthy." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/progressive-delivery-canary-20-50-100.jpg" />
</Frame>

Security and policy gates

* PR validation: run pre-merge policy checks (OPA/Rego, Conftest) and static analysis on manifests.
* Admission control: enforce policies at apply/sync time with Gatekeeper or Kyverno.

These gates prevent unsafe or non-compliant manifests from being reconciled into clusters.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/og-mfTVvAAl8u5l1/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/security-gates-admission-control-pr-validation.jpg?fit=max&auto=format&n=og-mfTVvAAl8u5l1&q=85&s=5f3cb25eafd1676ea03311991025ab9d" alt="A slide titled &#x22;Security Gates — Policy Enforcement Before Deployment&#x22; showing two colored blocks: &#x22;Admission Control&#x22; (Gatekeeper validates at cluster apply time) and &#x22;PR Validation&#x22; (OPA policies check manifests before merge). Copyright KodeKloud appears at the bottom." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/security-gates-admission-control-pr-validation.jpg" />
</Frame>

Key CD metrics to monitor

* Deployment frequency — how often you deploy to production.
* Lead time for changes — time from commit to production (hour-level targets are common).
* Change failure rate / rollback rate — target high success rates (e.g., >95% without rollback).
* Time to restore — how quickly you remediate failed deployments.

Infrastructure drift and environment management

* If all changes flow through Git and controllers reconcile state, drift should be rare. Teams can and do operate without manual server logins by using declarative tooling and APIs.
* Version environment manifests and use automated promotion to keep environments consistent, while preserving the ability to apply emergency fixes and environment-specific controls.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/og-mfTVvAAl8u5l1/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/gitops-multiple-environments-deployment-strategy.jpg?fit=max&auto=format&n=og-mfTVvAAl8u5l1&q=85&s=733cc34450618904b1c5ab9154efd2db" alt="A slide titled &#x22;Managing Multiple Environments With GitOps&#x22; showing a central &#x22;Deployment Strategy&#x22; box. Colored nodes connected to it are labeled Environment Separation, Emergency Fixes, Automated Promotion, Production Controls, and Balanced Architecture." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/gitops-multiple-environments-deployment-strategy.jpg" />
</Frame>

Platform deployment — eat your own dog food

* Put platform configuration and manifests in Git; treat the platform like any customer workload.
* Automate platform deployment and testing so the platform is reproducible and versionable.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/K1_NX_PB-6qgXzeI/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/cd-gitops-platform-deployment-pillars.jpg?fit=max&auto=format&n=K1_NX_PB-6qgXzeI&q=85&s=b536b5140b3d07f5c320133c4439b67c" alt="A presentation slide titled &#x22;CD and GitOps – Platform Deployment Foundation&#x22; showing four numbered pillars: 01 Automated Deployment, 02 Git as a Source of Truth, 03 Immutable Promotion, and 04 Progressive Delivery. Each pillar has a short explanatory blurb and the slide is © KodeKloud." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-1-Platform-Engineering-Core-Fundamentals/Continuous-Delivery-and-GitOps-Fundamentals/cd-gitops-platform-deployment-pillars.jpg" />
</Frame>

Final advice for platform engineering and certification prep

* Treat CD and GitOps as foundational: they transform manual, high-risk ops into low-risk automated workflows.
* Design pipelines with immutability, progressive delivery, policy gates, and observability built in.
* Track CD metrics and iterate on rollout strategies to match your organizational risk tolerance.

<Callout icon="lightbulb" color="#1CB2FE">
  Key takeaways: automate repeatable deployments, use Git as the source of truth, promote immutable artifacts, enforce policy gates, and measure CD outcomes (deployment frequency, lead time, change failure rate).
</Callout>

Thank you for reading this lesson on CD and GitOps fundamentals. This concludes Domain 1. Continue with the subsequent materials to continue preparing for the certification.

<CardGroup>
  <Card title="Watch Video" icon="video" cta="Learn more" href="https://learn.kodekloud.com/user/courses/certified-cloud-native-platform-engineering-associate-cnpa/module/2a91f7db-45c5-4944-a2b2-15da9f74f4d5/lesson/1f392462-9699-4f48-961a-7d48d26294d8" />
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.