All skills
wshobson avatar

/gitops-workflow

@5684887
by Seth Hobsonwshobson/agents40k stars
4,281

Implement GitOps workflows with ArgoCD and Flux for automated, declarative Kubernetes deployments with continuous reconciliation. Use when implementing GitOps practices, automating Kubernetes deployments, or setting up declarative infrastructure management.

Use this Skill: https://skilld.dev/gh/wshobson/agents/gitops-workflow

This session only. Nothing lands on disk.

SKILL.md

β‰ˆ69 tokens always: the name and description. β‰ˆ1.4k when used: this file. β‰ˆ1.4k more on demand in 2 files.

GitOps Workflow

Complete guide to implementing GitOps workflows with ArgoCD and Flux for automated Kubernetes deployments.

Purpose

Implement declarative, Git-based continuous delivery for Kubernetes using ArgoCD or Flux CD, following OpenGitOps principles.

When to Use This Skill

  • Set up GitOps for Kubernetes clusters
  • Automate application deployments from Git
  • Implement progressive delivery strategies
  • Manage multi-cluster deployments
  • Configure automated sync policies
  • Set up secret management in GitOps

OpenGitOps Principles

  1. Declarative - Entire system described declaratively
  2. Versioned and Immutable - Desired state stored in Git
  3. Pulled Automatically - Software agents pull desired state
  4. Continuously Reconciled - Agents reconcile actual vs desired state

ArgoCD Setup

1. Installation

# Create namespace
kubectl create namespace argocd

# Install ArgoCD
kubectl apply -n argocd -f https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml

# Get admin password
kubectl -n argocd get secret argocd-initial-admin-secret -o jsonpath="{.data.password}" | base64 -d

Reference: See references/argocd-setup.md for detailed setup

2. Repository Structure

gitops-repo/
β”œβ”€β”€ apps/
β”‚   β”œβ”€β”€ production/
β”‚   β”‚   β”œβ”€β”€ app1/
β”‚   β”‚   β”‚   β”œβ”€β”€ kustomization.yaml
β”‚   β”‚   β”‚   └── deployment.yaml
β”‚   β”‚   └── app2/
β”‚   └── staging/
β”œβ”€β”€ infrastructure/
β”‚   β”œβ”€β”€ ingress-nginx/
β”‚   β”œβ”€β”€ cert-manager/
β”‚   └── monitoring/
└── argocd/
    β”œβ”€β”€ applications/
    └── projects/

3. Create Application

# argocd/applications/my-app.yaml
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: my-app
  namespace: argocd
spec:
  project: default
  source:
    repoURL: https://github.com/org/gitops-repo
    targetRevision: main
    path: apps/production/my-app
  destination:
    server: https://kubernetes.default.svc
    namespace: production
  syncPolicy:
    automated:
      prune: true
      selfHeal: true
    syncOptions:
      - CreateNamespace=true

4. App of Apps Pattern

apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: applications
  namespace: argocd
spec:
  project: default
  source:
    repoURL: https://github.com/org/gitops-repo
    targetRevision: main
    path: argocd/applications
  destination:
    server: https://kubernetes.default.svc
    namespace: argocd
  syncPolicy:
    automated: {}

Flux CD Setup

1. Installation

# Install Flux CLI
curl -s https://fluxcd.io/install.sh | sudo bash

# Bootstrap Flux
flux bootstrap github \
  --owner=org \
  --repository=gitops-repo \
  --branch=main \
  --path=clusters/production \
  --personal

2. Create GitRepository

apiVersion: source.toolkit.fluxcd.io/v1
kind: GitRepository
metadata:
  name: my-app
  namespace: flux-system
spec:
  interval: 1m
  url: https://github.com/org/my-app
  ref:
    branch: main

3. Create Kustomization

apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
  name: my-app
  namespace: flux-system
spec:
  interval: 5m
  path: ./deploy
  prune: true
  sourceRef:
    kind: GitRepository
    name: my-app

Sync Policies

Auto-Sync Configuration

ArgoCD:

syncPolicy:
  automated:
    prune: true # Delete resources not in Git
    selfHeal: true # Reconcile manual changes
    allowEmpty: false
  retry:
    limit: 5
    backoff:
      duration: 5s
      factor: 2
      maxDuration: 3m

Flux:

spec:
  interval: 1m
  prune: true
  wait: true
  timeout: 5m

Reference: See references/sync-policies.md

Progressive Delivery

Canary Deployment with ArgoCD Rollouts

apiVersion: argoproj.io/v1alpha1
kind: Rollout
metadata:
  name: my-app
spec:
  replicas: 5
  strategy:
    canary:
      steps:
        - setWeight: 20
        - pause: { duration: 1m }
        - setWeight: 50
        - pause: { duration: 2m }
        - setWeight: 100

Blue-Green Deployment

strategy:
  blueGreen:
    activeService: my-app
    previewService: my-app-preview
    autoPromotionEnabled: false

Secret Management

External Secrets Operator

apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
  name: db-credentials
spec:
  refreshInterval: 1h
  secretStoreRef:
    name: aws-secrets-manager
    kind: SecretStore
  target:
    name: db-credentials
  data:
    - secretKey: password
      remoteRef:
        key: prod/db/password

Sealed Secrets

# Encrypt secret
kubeseal --format yaml < secret.yaml > sealed-secret.yaml

# Commit sealed-secret.yaml to Git

Best Practices

  1. Use separate repos or branches for different environments
  2. Implement RBAC for Git repositories
  3. Enable notifications for sync failures
  4. Use health checks for custom resources
  5. Implement approval gates for production
  6. Keep secrets out of Git (use External Secrets)
  7. Use App of Apps pattern for organization
  8. Tag releases for easy rollback
  9. Monitor sync status with alerts
  10. Test changes in staging first

Troubleshooting

Sync failures:

argocd app get my-app
argocd app sync my-app --prune

Out of sync status:

argocd app diff my-app
argocd app sync my-app --force

Related Skills

  • k8s-manifest-generator - For creating manifests
  • helm-chart-scaffolding - For packaging applications

Source: SKILL.md on GitHub

1 warning16d5 checks Β· Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides standard installation and configuration guides for ArgoCD and Flux CD. It includes remote downloads and privileged commands that are part of the official, documented setup processes for these well-known industry tools.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW Β· No issues

  • Runlayer7mo

    2/3 files flagged

  • ZeroLeaks5mo

    2 findings Β· Score: 80/100

Signed by skilld at 5684887. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 8 months ago
  • kubernetes
  • gitops
  • argocd
  • flux
  • cd
  • declarative
  • deployment
  • kustomization
  • multi-cluster

README badge

README badge for wshobson/agents/gitops-workflow

Implements GitOps workflows for Kubernetes using ArgoCD or Flux CD, with declarative application deployments that continuously reconcile desired state from Git. Covers repository structure, auto-sync policies, progressive delivery strategies like canary deployments, and secret management with External Secrets Operator or Sealed Secrets.

Generated from the current SKILL.md.

Does this skill cover both ArgoCD and Flux, or do I have to pick one?
The skill covers both ArgoCD and Flux CD. You choose which tool fits your GitOps workflow; the skill shows setup and configuration for each.
Can I use this skill for multi-cluster deployments?
Yes. The skill includes guidance for multi-cluster deployments and uses the App of Apps pattern to manage applications across clusters.
How does secret management work in this GitOps workflow?
The skill covers External Secrets Operator and Sealed Secrets to keep secrets out of Git while maintaining declarative infrastructure.
Does this skill support progressive delivery strategies like canary or blue-green deployments?
Yes. The skill includes examples of canary deployments using ArgoCD Rollouts and blue-green deployment configurations.
What happens if there's a sync failure or drift between Git and the cluster?
The skill covers troubleshooting commands (argocd app get, argocd app diff) and auto-sync policies with retry logic to handle failures and reconcile drift.

Generated from the current SKILL.md. These answers refresh after source changes.