GitOps Principles & Practice cheat sheet
43 commands from every lesson of GitOps Principles & Practice, on one page.
See the loop in action (Argo CD / Flux)
argocd app get orders-api | Desired (Git) vs live state, sync and health status |
argocd app diff orders-api | Exactly what differs between Git and the cluster |
flux get kustomizations -A | Flux: which Git paths are applied, and their status |
flux reconcile kustomization apps --with-source | Flux: pull and apply now instead of waiting |
git log --oneline -- environments/prod/ | Every change ever made to production, with author and reason |
Render and check locally
kustomize build apps/orders-api/envs/prod | Exactly what Kustomize will produce for prod |
helm template orders-api charts/orders-api -f envs/prod/values.yaml | Render a chart with prod values |
diff <(kustomize build envs/staging) <(kustomize build envs/prod) | What differs between two environments |
kubeconform -strict -summary rendered/ | Validate rendered manifests against Kubernetes schemas |
Promote by hand (it's just Git)
yq -i '.image.digest = "sha256:..."' apps/orders-api/envs/staging/values.yaml | Set the new digest for staging |
cd apps/orders-api/envs/prod && kustomize edit set image ghcr.io/acme/orders-api@sha256:... | Set the image in a Kustomize overlay |
git switch -c promote/orders-api-prod && git commit -am "orders-api: promote 1.4.0 to prod" | Promotion as a reviewable branch |
gh pr create --title "orders-api 1.4.0 -> prod" --body "Soaked 24h in staging, SLOs green" | Open the promotion PR |
Roll back
git revert <promotion-commit> | Undo a promotion; the agent redeploys the previous version |
git log --oneline -- apps/orders-api/envs/prod/ | Every version prod has run |
Sealed Secrets
kubectl create secret generic db --from-literal=password=... --dry-run=client -o yaml > db.yaml | A normal Secret, never committed |
kubeseal --format yaml < db.yaml > db-sealed.yaml | Encrypt it for this cluster; commit db-sealed.yaml |
SOPS
age-keygen -o key.txt | Create an age key pair (keep the private key out of Git) |
sops --encrypt --age <public-key> --encrypted-regex '^(data|stringData)$' secret.yaml > secret.enc.yaml | Encrypt only the values |
sops --decrypt secret.enc.yaml | Decrypt to check (needs the key) |
External Secrets Operator
kubectl get externalsecrets -A | Which secrets are synced, and their status |
kubectl describe externalsecret db -n shop | Why a sync fails (permissions, missing key) |
Drift and sync
argocd app diff orders-api | Live vs Git, object by object |
argocd app sync orders-api --prune | Apply Git and delete objects removed from Git |
argocd app set orders-api --self-heal | Automatically revert manual changes |
flux diff kustomization apps --path ./apps | Flux: what would change |
During an incident
argocd app set orders-api --sync-policy none | Pause automated sync for one app (Argo CD) |
flux suspend kustomization apps | Pause reconciliation (Flux) |
flux resume kustomization apps | Resume, which re-applies Git |
git revert <sha> && git push | Roll back the change in Git |
Flux
flux check --pre | Is the cluster ready for Flux? |
flux bootstrap github --owner=acme --repository=gitops-config --path=clusters/dev-eu-1 | Install Flux and commit its own config to Git |
flux get all -A | Sources, kustomizations and Helm releases with status |
flux logs --level=error | Controller errors |
Argo CD
argocd app create orders-api --repo <url> --path apps/orders-api/envs/dev --dest-server https://kubernetes.default.svc --dest-namespace shop | Create an application |
argocd app list | Applications with sync and health status |
argocd app sync orders-api | Sync now |
Argo Rollouts
kubectl argo rollouts get rollout orders-api -n shop --watch | Live view of steps, weights and analysis |
kubectl argo rollouts promote orders-api -n shop | Move past a manual pause |
kubectl argo rollouts abort orders-api -n shop | Stop and return all traffic to the stable version |
kubectl argo rollouts dashboard | Local web dashboard |
Flagger
kubectl get canaries -A | Canary status and current weight |
kubectl describe canary orders-api -n shop | Analysis results and events |