ADVERTISEMENT

GitOps Workflow with ArgoCD: Continuous Delivery on Kubernetes Explained

📁 GitOps & Kubernetes CD
⏱️ 14 min read • Updated: Sep 2026

GitOps Workflow with ArgoCD: Continuous Delivery for Kubernetes Infrastructure

GitOps Continuous Delivery Workflow with ArgoCD Git Repository Sync and Kubernetes Cluster Automation
GitOps Summary • Direct Answer

GitOps is a cloud-native operational framework where a Git repository serves as the single source of truth for desired infrastructure and application state. Using ArgoCD (a declarative Continuous Delivery controller running inside Kubernetes), the cluster continuously reconciles live running workloads against Git manifests: any unauthorized manual changes (configuration drift) are automatically detected and reverted (self-healing), while code commits trigger automated, auditable zero-downtime releases.

In traditional CI/CD workflows, external build pipelines (like GitHub Actions runners) are granted administrative cluster credentials to execute kubectl apply commands directly against the cluster. This "Push-based" deployment model creates dangerous security liabilities: if your CI runner is breached, an attacker gains root access to your entire production cloud infrastructure.

GitOps replaces this with an in-cluster "Pull-based" continuous delivery model using ArgoCD. Building upon our foundational guide on Kubernetes Architecture (Pods, Services & Deployments) and cloud automation (Terraform Infrastructure as Code Guide), GitOps represents the pinnacle of modern cloud deployment reliability.

[ Developer Commit ] ➔➔ [ Git Repository (Single Source of Truth) ]
                                ▲
                                │ (Continuous Polling & Reconciliation)
[ Kubernetes Cluster ] ➔➔ [ ArgoCD Controller Running Inside Cluster ]
                                ▼
[ Live State Compared to Desired State ] ➔➔ [ Automated Sync & Self-Healing ]

01. The Four Core Principles of GitOps

  • 1. Declarative Descriptions: The entire cluster state (Deployments, Services, Ingress, ConfigMaps) is declared in version-controlled YAML files, Helm charts, or Kustomize overlays.
  • 2. Versioned & Immutable State in Git: Git commit logs provide a tamper-proof audit trail of exactly who approved and deployed every single change, fully aligning with Zero-Trust Cloud Security Architecture.
  • 3. Pull-Based Automated Synchronization: Software agents running inside the cluster pull updates from Git. The cluster never exposes inbound ports or API keys to external CI runners.
  • 4. Continuous Drift Detection & Self-Healing: If an unauthorized engineer manually changes a replica count using kubectl edit, ArgoCD instantly detects the drift and overwrites the change back to the Git source of truth within seconds.

02. Installing ArgoCD in Your Kubernetes Cluster

Installing ArgoCD inside your cluster requires just two commands:

# 1. Create the dedicated argocd namespace
kubectl create namespace argocd

# 2. Apply the official ArgoCD manifests
kubectl apply -n argocd -f https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml

# 3. Verify that all controller pods are running
kubectl get pods -n argocd

To access the intuitive ArgoCD web UI dashboard locally, port-forward the server:

kubectl port-forward svc/argocd-server -n argocd 8080:443

03. Defining an ArgoCD Application Manifest (Application CRD)

In GitOps, you define your applications declaratively as Kubernetes Custom Resource Definitions (CRDs). Here is a production-grade Application manifest that syncs your production microservices repository:

# argocd-production-app.yaml
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: api-service-production
  namespace: argocd
  finalizers:
    - resources-finalizer.argocd.argoproj.io
spec:
  project: default
  source:
    repoURL: 'https://github.com/waseemkaluwal/cloud-infrastructure-k8s.git'
    targetRevision: main
    path: k8s/production
  destination:
    server: 'https://kubernetes.default.svc'
    namespace: production
  syncPolicy:
    automated:
      prune: true     # Automatically deletes resources removed from Git
      selfHeal: true  # Automatically reverts manual cluster drift
    syncOptions:
      - CreateNamespace=true

04. The Perfect Union: GitHub Actions (CI) + ArgoCD (CD)

Many developers ask: "Does GitOps replace GitHub Actions?" No! They work together seamlessly:

  • GitHub Actions handles CI: Lints code, runs unit tests, compiles Docker images, runs vulnerability scans, pushes images to container registries, and commits the new image tag (e.g., v1.4.2) to the GitOps config repository (GitHub Actions CI/CD Pipeline Guide).
  • ArgoCD handles CD: Detects the new commit in the GitOps repo, initiates a rolling update in Kubernetes, monitors pod health checks, and reports live sync status.
Instant Disaster Recovery with GitOps

If an entire AWS availability zone or region collapses, you can provision a fresh Kubernetes cluster with Terraform (Terraform IaC Guide), install ArgoCD, and point it to your Git repository. ArgoCD recreates all 50 microservices and networking configurations automatically in under 5 minutes!

GitOps Pull vs Traditional Push CI/CD Matrix

Operational Dimension Traditional Push Deployment (CI/CD) GitOps Pull Model (ArgoCD)
Deployment Initiator External CI runner pushes manifests to cluster Internal cluster agent monitors Git repository
Cluster Security Credentials Shared admin kubeconfig exposed in CI secrets Zero cluster credentials leave the Kubernetes network
Configuration Drift Handling Undetected until next automated deployment push Instant automated drift detection and self-healing
Disaster Recovery & Rollback Re-running complex multi-step build pipelines Single git revert triggers instantaneous rollbacks
📖 Authoritative Documentation & Technical References

05. Frequently Asked Questions (FAQ)

Q: What is the difference between ArgoCD and Flux?
Both are CNCF graduated GitOps operators. ArgoCD features a rich web UI dashboard, fine-grained SSO/RBAC controls, and multi-cluster management. Flux is a collection of modular controllers configured purely via command-line and Kubernetes manifests.
Q: How do you handle secrets in GitOps without exposing passwords in Git?
Never commit plaintext secrets! Use tools like Sealed Secrets (Bitnami), HashiCorp Vault, or External Secrets Operator (which securely injects secrets from AWS Secrets Manager or AWS KMS into Kubernetes pods at runtime).
Q: What is the App of Apps pattern in ArgoCD?
The App of Apps pattern is an architectural design where a single parent ArgoCD Application manifest points to a Git directory containing definitions for all your child applications (monitoring, ingress, databases, API services), allowing an entire cluster ecosystem to be bootstrapped from a single file.

06. Conclusion & Next Steps

Transitioning your Kubernetes cluster management to a GitOps workflow with ArgoCD establishes a single, immutable source of truth for your entire application infrastructure. By pulling configurations directly from Git, detecting configuration drift automatically, and shielding cluster credentials from external CI runners, GitOps delivers enterprise-grade security and frictionless team collaboration.

To level up your GitOps maturity, incorporate automated canary and blue/green deployments using Argo Rollouts, and secure sensitive manifest values using HashiCorp Vault or Sealed Secrets.

Implementing declarative GitOps continuous delivery workflows with ArgoCD for multi-cluster environments? Discover live GitOps delivery pipelines in the Waseem Kaluwal Portfolio, or book a specialized session through GitOps Consultation.

Topic Cluster

Related Cloud & DevOps Engineering Guides

Supercharge your infrastructure and deployment workflow with these companion production tutorials:

CI/CD & Automation Read Guide →
CI/CD Pipeline with GitHub Actions and Docker: Complete Production Guide
Automate linting, multi-stage Docker builds, and zero-downtime SSH deployments with GitHub Actions.
Kubernetes & K8s Read Guide →
Kubernetes Architecture Explained: Master Pods, Services, Deployments, and Ingress
Master Kubernetes core architecture: control planes, worker nodes, ingress controllers, and cluster scaling.
DevSecOps Security Read Guide →
DevSecOps Pipeline Security: Automating Secret Scanning, SAST, and Container Vulnerability Checks
Shift security left by integrating Gitleaks, Semgrep SAST, and Trivy vulnerability scans into CI/CD pipelines.
Cloud Observability Read Guide →
Prometheus & Grafana: End-to-End Production Monitoring and Observability on AWS
Build real-time observability with Prometheus metric scraping, Alertmanager thresholds, and Grafana dashboards.
Waseem Kaluwal - Web Developer, Python & AI Expert, SEO Specialist, AWS DevOps

Written by Waseem Kaluwal

Software Engineer, Full-Stack Website Developer, Social Media Influencer, Python & AI Expert, Technical SEO Strategist, and AWS DevOps Specialist. Tech YouTuber, Photographer, and Global Freelancer dedicated to engineering high-performance digital platforms and intelligent automation systems.

No comments:

Post a Comment

ADVERTISEMENT