
- Kubernetes manifests (YAML, Helm charts, Kustomize overlays).
- Environment-specific configuration (dev, staging, production).
- Policies, RBAC configuration, and promotion workflows.
Reconciliation loop (pull-based model)
The reconciliation loop is central to GitOps: a reconciler continuously compares the desired state in Git against the actual cluster state and corrects any drift. This is usually a pull model — an in-cluster controller or agent reads Git and applies changes — which contrasts with traditional push-based CI/CD where pipelines need external cluster access. Benefits of the pull/reconciler model:- Less exposed cluster surface area (no external push access needed).
- Continuous enforcement of declared state and automatic drift correction.
- Clear audit trail through Git history and easier rollbacks.

Argo CD overview
Argo CD is a CNCF‑graduated GitOps continuous delivery tool for Kubernetes. It is Kubernetes-native, declarative, and Git-driven, and it offers a Web UI and CLI, multi-cluster support, and multiple operating modes for different organizational needs.
Argo CD Application resource
An Argo CD Application is the declarative object that maps a repository path to a target Kubernetes cluster and namespace. It declares therepoURL, path to manifests, targetRevision (branch/tag), and destination.
Example minimal Application for the pony-spawner service:
Team roles in a GitOps workflow
Repository layout and environment separation
Common patterns:- Single repo with environment directories:
services/foo/dev,services/foo/prod
- One repo per environment for strict isolation.
- Per-service repositories with shared charts/bases.
- Use shared Kustomize bases, Helm charts, or reusable templates to avoid duplication.
- Enforce RBAC so teams can push to dev but require approvals for production changes.

Deployment manifests are reconciled
Any Kubernetes manifest stored in the repo is compared and applied by Argo CD. Example Deployment manifest reconciled from Git:- Poll the configured Git repository for changes.
- Compare desired state (Git) with actual cluster state.
- Detect drift or differences.
- Sync resources (apply manifests) to remove drift.
- Perform post-sync health checks and report status.


Managing multiple environments
Options to structure environments and promote changes:
You can also run separate Argo CD instances per environment for full isolation or create a single central Argo CD that targets multiple clusters.

Security, governance, and policy enforcement
GitOps improves security and governance by:- Eliminating the need for direct cluster credentials for most developers.
- Providing an auditable history of changes in Git.
- Enabling RBAC at the repository and Argo CD levels.
- Integrating policy gates (pre-commit checks, CI tests, policy-as-code, admission controllers).

Rollbacks and recoverability
Rollbacks with GitOps are straightforward: revert to a known-good commit in Git and let Argo CD re-sync the cluster to that commit. This makes rollbacks auditable and reproducible. Note: application-level concerns such as database migrations still need careful planning and possibly specialized migration tooling.

Platform engineering considerations
GitOps is often provided as a platform service: a central Argo CD instance (or a set of instances) enables self-service deployment while platform teams enforce standards and guardrails. Benefits include multi-cluster support, standardized application templates, and reduced operational ticketing. Agreeing early on repository layouts, RBAC, and promotion workflows reduces friction.
Key takeaways
- Git-driven: Git is the single source of truth for desired system state.
- Pull-based: a reconciler continuously enforces the declared state (Argo CD is a common implementation).
- Declarative: manifests express the desired state rather than imperative commands.
- Continuous reconciliation: drift is detected and corrected automatically.

Value summary
Using GitOps with Argo CD:- Automates and standardizes deployments.
- Improves reliability and observability.
- Makes change history auditable and rollbacks simple.
- Enables teams to deploy independently within platform guardrails.
Remember: Be prepared to explain the difference between push-based CI/CD and pull-based GitOps, how the reconciliation loop works, and why storing the desired state in Git improves auditability and rollback safety.
Links and references
- Argo CD documentation: https://argo-cd.readthedocs.io/
- GitOps concepts: https://www.weave.works/technologies/gitops/
- Kubernetes documentation: https://kubernetes.io/docs/