> ## Documentation Index
> Fetch the complete documentation index at: https://notes.kodekloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Continuous Delivery GitOps

> Overview of GitOps with Argo CD, a Git‑centric pull based continuous delivery approach for Kubernetes covering reconciliation, repository patterns, security, rollbacks, and platform practices.

In this lesson we cover GitOps with Argo CD: the Git-centric, pull-based pattern for continuous delivery that platform engineering teams use to deliver reliable, auditable, and repeatable Kubernetes deployments. You’ll learn core concepts, the Argo CD architecture, repository organization patterns, security and rollback benefits, and how the reconciliation loop maintains the desired cluster state.

GitOps treats a Git repository as the single source of truth for infrastructure, Kubernetes manifests, and deployment configuration. Git provides versioning, an auditable change history, and familiar collaboration workflows for both development and operations teams.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/opiHmBIGEeYSlbhA/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/gitops-single-source-truth-slide.jpg?fit=max&auto=format&n=opiHmBIGEeYSlbhA&q=85&s=87ff466e1f0c783058f232eecd7fcf29" alt="A slide titled &#x22;GitOps – Git as the Single Source of Truth&#x22; showing the GitOps logo and two numbered points: &#x22;Uses Git as the single source of truth&#x22; and &#x22;Drives both development and operations.&#x22;" width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/gitops-single-source-truth-slide.jpg" />
</Frame>

What belongs in Git

* Kubernetes manifests (YAML, Helm charts, Kustomize overlays).
* Environment-specific configuration (dev, staging, production).
* Policies, RBAC configuration, and promotion workflows.

For example, the Sparkle Pony Ranch (SPR) platform objectives are reliable, repeatable deployments across dev/staging/production; full audit trails of who changed what; and low operational friction. These are delivered by storing declarative configuration in Git and letting a reconciler continuously enforce that desired state.

## Reconciliation loop (pull-based model)

The reconciliation loop is central to GitOps: a reconciler continuously compares the desired state in Git against the actual cluster state and corrects any drift. This is usually a pull model — an in-cluster controller or agent reads Git and applies changes — which contrasts with traditional push-based CI/CD where pipelines need external cluster access.

Benefits of the pull/reconciler model:

* Less exposed cluster surface area (no external push access needed).
* Continuous enforcement of declared state and automatic drift correction.
* Clear audit trail through Git history and easier rollbacks.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/opiHmBIGEeYSlbhA/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/gitops-vs-traditional-deployment-models.jpg?fit=max&auto=format&n=opiHmBIGEeYSlbhA&q=85&s=2d6ba229ad0e793de2e9e3cf761552ec" alt="A slide titled &#x22;GitOps vs Traditional Deployment Models&#x22; comparing Traditional CI/CD (push model) on the left with GitOps (pull model) on the right. The bullets note push pipelines require external cluster access and are hard to audit/rollback, while GitOps agents pull state from Git, need no external access, and provide an audit trail with easy rollbacks." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/gitops-vs-traditional-deployment-models.jpg" />
</Frame>

## Argo CD overview

Argo CD is a CNCF‑graduated GitOps continuous delivery tool for Kubernetes. It is Kubernetes-native, declarative, and Git-driven, and it offers a Web UI and CLI, multi-cluster support, and multiple operating modes for different organizational needs.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/opiHmBIGEeYSlbhA/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/argocd-octopus-gitops-continuous-delivery-slide.jpg?fit=max&auto=format&n=opiHmBIGEeYSlbhA&q=85&s=a7d86305f9d26b94e49f06d3ff15b355" alt="A presentation slide for ArgoCD showing the Argo octopus logo and name. It lists key points: CNCF‑graduated GitOps continuous delivery, a Kubernetes‑native GitOps operator, and declarative Git‑based application delivery." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/argocd-octopus-gitops-continuous-delivery-slide.jpg" />
</Frame>

Argo CD core components

| Component | Responsibility |
| - | - |
| API server / Web UI | User and automation interaction (REST API, dashboard) |
| Repository server | Clones and reads Git repositories; prepares manifests |
| Controller | Runs the reconciliation loop and applies changes to clusters |
| Identity/SSO (Dex, OIDC, etc.) | Optional authentication and SSO integration |

## Argo CD Application resource

An Argo CD Application is the declarative object that maps a repository path to a target Kubernetes cluster and namespace. It declares the `repoURL`, path to manifests, `targetRevision` (branch/tag), and destination.

Example minimal Application for the `pony-spawner` service:

```yaml theme={null}
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: pony-spawner
  namespace: argocd
spec:
  source:
    repoURL: https://github.com/spr/pony-services
    path: pony-spawner/manifests
    targetRevision: main
  destination:
    server: https://kubernetes.default.svc
    namespace: production
```

Developers commit code and CI produces artifacts (images, charts). The GitOps repo holds the desired manifests (which typically reference built artifacts). Argo CD watches Git, detects changes, and syncs the cluster to match the declared state. Sync can be manual (safe default) or automatic when teams are confident in automation and monitoring.

## Team roles in a GitOps workflow

| Role | Typical responsibilities |
| - | - |
| Developers | Write application code; update manifests or image tags in Git |
| Platform / GitOps owners | Manage Argo CD, repository layout, RBAC, and platform patterns |
| SRE / Ops | Monitor cluster health, respond to incidents, execute rollbacks if needed |

## Repository layout and environment separation

Common patterns:

* Single repo with environment directories:
  * `services/foo/dev`, `services/foo/prod`
* One repo per environment for strict isolation.
* Per-service repositories with shared charts/bases.
* Use shared Kustomize bases, Helm charts, or reusable templates to avoid duplication.
* Enforce RBAC so teams can push to dev but require approvals for production changes.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/opiHmBIGEeYSlbhA/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/gitops-access-control-benefits.jpg?fit=max&auto=format&n=opiHmBIGEeYSlbhA&q=85&s=40948ac9b3343d5a9cc38ec744da1347" alt="A presentation slide titled &#x22;GitOps Repository Organization&#x22; with a section called &#x22;Access Control Benefits.&#x22; It lists benefits like teams having different permissions per environment, extra approvals for production changes, and clear audit trails for compliance." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/gitops-access-control-benefits.jpg" />
</Frame>

## Deployment manifests are reconciled

Any Kubernetes manifest stored in the repo is compared and applied by Argo CD. Example Deployment manifest reconciled from Git:

```yaml theme={null}
apiVersion: apps/v1
kind: Deployment
metadata:
  name: pony-spawner
spec:
  replicas: 3
  selector:
    matchLabels:
      app: pony-spawner
  template:
    metadata:
      labels:
        app: pony-spawner
    spec:
      containers:
      - name: pony-spawner
        image: registry.spr.com/pony-spawner:v2.1.0
        resources:
          requests:
            cpu: "200m"
            memory: "256Mi"
```

Reconciliation process (high level):

1. Poll the configured Git repository for changes.
2. Compare desired state (Git) with actual cluster state.
3. Detect drift or differences.
4. Sync resources (apply manifests) to remove drift.
5. Perform post-sync health checks and report status.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/opiHmBIGEeYSlbhA/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/argocd-reconcile-poll-compare-sync-health.jpg?fit=max&auto=format&n=opiHmBIGEeYSlbhA&q=85&s=10b29f0024d8a819b81ce86d717e74e7" alt="A slide titled &#x22;How ArgoCD Maintains the Desired State&#x22; showing the &#x22;Reconciliation Process.&#x22; It displays a five-step timeline: Poll Git Repository, Compare States, Detect Drift, Sync Resources, and Health Check." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/argocd-reconcile-poll-compare-sync-health.jpg" />
</Frame>

Argo CD’s UI shows sync status, diff views, and a deployment history — useful for troubleshooting and audits.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/opiHmBIGEeYSlbhA/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/argocd-ui-sync-status-history.jpg?fit=max&auto=format&n=opiHmBIGEeYSlbhA&q=85&s=afa7790249cbdd0323d4c5d27e34ccdf" alt="A presentation slide titled &#x22;ArgoCD User Interface – Features&#x22; showing two UI screenshots labeled &#x22;Sync Status&#x22; and &#x22;History,&#x22; describing real-time deployment state info and complete deployment/rollback history." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/argocd-ui-sync-status-history.jpg" />
</Frame>

## Managing multiple environments

Options to structure environments and promote changes:

| Strategy | Description | Trade-offs |
| - | - | - |
| Separate Applications | One Argo CD Application per environment | Clear separation; more objects to manage |
| Different Git paths | Environment-specific manifest directories in same repo | Easier promotion; risk of accidental cross-env changes |
| Promotion workflow | Move changes through dev → staging → production with CI checks | Safer promotion but requires tooling/process |

You can also run separate Argo CD instances per environment for full isolation or create a single central Argo CD that targets multiple clusters.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/opiHmBIGEeYSlbhA/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/argocd-multiple-environments-strategy.jpg?fit=max&auto=format&n=opiHmBIGEeYSlbhA&q=85&s=9b5eed1c732849b4d5c5d863dd0bb322" alt="A presentation slide titled &#x22;Managing Multiple Environments With ArgoCD&#x22; showing an &#x22;Environment Strategy&#x22; with three colored options: &#x22;Separate Applications&#x22; (one ArgoCD application per environment), &#x22;Different Git Paths&#x22; (environment-specific manifest directories), and &#x22;Promotion Workflow&#x22; (changes flow through environments). The slide is branded © KodeKloud." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/argocd-multiple-environments-strategy.jpg" />
</Frame>

## Security, governance, and policy enforcement

GitOps improves security and governance by:

* Eliminating the need for direct cluster credentials for most developers.
* Providing an auditable history of changes in Git.
* Enabling RBAC at the repository and Argo CD levels.
* Integrating policy gates (pre-commit checks, CI tests, policy-as-code, admission controllers).

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/opiHmBIGEeYSlbhA/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/gitops-argocd-security-benefits.jpg?fit=max&auto=format&n=opiHmBIGEeYSlbhA&q=85&s=2a562b2afc935488f163d2c115934be4" alt="A slide titled &#x22;GitOps With ArgoCD – Security Benefits&#x22; showing four numbered cards. The cards list No Direct Cluster Access, Complete Audit Trail, Role-Based Access, and Policy Enforcement with short explanatory text." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/gitops-argocd-security-benefits.jpg" />
</Frame>

## Rollbacks and recoverability

Rollbacks with GitOps are straightforward: revert to a known-good commit in Git and let Argo CD re-sync the cluster to that commit. This makes rollbacks auditable and reproducible. Note: application-level concerns such as database migrations still need careful planning and possibly specialized migration tooling.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/opiHmBIGEeYSlbhA/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/easy-rollbacks-revert-git-argocd.jpg?fit=max&auto=format&n=opiHmBIGEeYSlbhA&q=85&s=911ad8bd9c34c22b2e3ca28c23f4c4db" alt="A presentation slide titled &#x22;Easy Rollbacks With Git History&#x22; that outlines a four-step rollback process: Identify Issue, Find Last Good State, Revert Git Commit, and ArgoCD Auto-Sync. A gray footer notes &#x22;Phuong can quickly roll back pony spawning issues by reverting Git commits.&#x22;" width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/easy-rollbacks-revert-git-argocd.jpg" />
</Frame>

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/opiHmBIGEeYSlbhA/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/easy-rollbacks-git-history-comparison.jpg?fit=max&auto=format&n=opiHmBIGEeYSlbhA&q=85&s=5de5a2fa18fea26961ecdff2d3157c02" alt="A presentation slide titled &#x22;Easy Rollbacks With Git History&#x22; showing a two-column comparison: a gray panel listing traditional rollback problems (complex procedures, DB migration concerns, configuration/state management, manual coordination) and a blue panel listing GitOps rollback advantages (single Git command, automatic coordination, audit trail, consistent procedures). Copyright KodeKloud appears at the bottom." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/easy-rollbacks-git-history-comparison.jpg" />
</Frame>

## Platform engineering considerations

GitOps is often provided as a platform service: a central Argo CD instance (or a set of instances) enables self-service deployment while platform teams enforce standards and guardrails. Benefits include multi-cluster support, standardized application templates, and reduced operational ticketing. Agreeing early on repository layouts, RBAC, and promotion workflows reduces friction.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/opiHmBIGEeYSlbhA/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/gitops-core-platform-selfservice-benefits.jpg?fit=max&auto=format&n=opiHmBIGEeYSlbhA&q=85&s=08b5399aeefffd00de8c1386fc48fcbf" alt="A presentation slide titled &#x22;GitOps as a Core Platform Service&#x22; with the heading &#x22;Self‑Service Benefits.&#x22; It shows two numbered cards: &#x22;Teams can deploy independently&#x22; and &#x22;Platform team maintains centralized control.&#x22;" width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/gitops-core-platform-selfservice-benefits.jpg" />
</Frame>

## Key takeaways

* Git-driven: Git is the single source of truth for desired system state.
* Pull-based: a reconciler continuously enforces the declared state (Argo CD is a common implementation).
* Declarative: manifests express the desired state rather than imperative commands.
* Continuous reconciliation: drift is detected and corrected automatically.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/opiHmBIGEeYSlbhA/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/gitops-key-takeaways-pull-declarative-reconciliation.jpg?fit=max&auto=format&n=opiHmBIGEeYSlbhA&q=85&s=d718c0a155c94e4a93a7d71060390473" alt="A presentation slide titled &#x22;Key Takeaways: GitOps – Modern Deployment for Platform Engineering&#x22; showing four colorful cards labeled 01–04 with the principles: Git‑Driven, Pull‑Based, Declarative, and Continuous Reconciliation. The cards note ideas like ArgoCD pulling desired state from Git and ensuring actual state matches Git declarations." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-3-Continuous-Delivery-Platform-Engineering/Continuous-Delivery-GitOps/gitops-key-takeaways-pull-declarative-reconciliation.jpg" />
</Frame>

## Value summary

Using GitOps with Argo CD:

* Automates and standardizes deployments.
* Improves reliability and observability.
* Makes change history auditable and rollbacks simple.
* Enables teams to deploy independently within platform guardrails.

Thanks for reading.

<Callout icon="lightbulb" color="#1CB2FE">
  Remember: Be prepared to explain the difference between push-based CI/CD and pull-based GitOps, how the reconciliation loop works, and why storing the desired state in Git improves auditability and rollback safety.
</Callout>

## Links and references

* Argo CD documentation: [https://argo-cd.readthedocs.io/](https://argo-cd.readthedocs.io/)
* GitOps concepts: [https://www.weave.works/technologies/gitops/](https://www.weave.works/technologies/gitops/)
* Kubernetes documentation: [https://kubernetes.io/docs/](https://kubernetes.io/docs/)

<CardGroup>
  <Card title="Watch Video" icon="video" cta="Learn more" href="https://learn.kodekloud.com/user/courses/certified-cloud-native-platform-engineering-associate-cnpa/module/b1af4eef-35d2-47b1-8964-1e80b1f1a739/lesson/ba4a16dc-1634-4d85-a2ac-5390695cc463" />
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.