GitOps Principles & Practice
GitOps is more than a tool: it's an operating model where the desired state of every environment lives in Git and an agent in the cluster keeps reality matching it. Learn the principles, design the repositories, promote changes between environments, handle secrets, work with drift and rollbacks, choose between Flux and Argo CD, and add progressive delivery.
What you'll be able to do
- Explain the four GitOps principles and why pull-based delivery is safer for clusters
- Design application and environment repositories that scale
- Promote releases from dev to prod through Git, automatically and reviewably
- Keep secrets out of Git while still delivering them through GitOps
- Handle drift, rollbacks and disaster recovery the GitOps way
- Choose between Flux and Argo CD, and add canary releases
Before you start
Git for Engineers (Level 1–2), Kubernetes Administration (Level 1).
How it works
Each lesson: plain-language idea → how it really works → hands-on. Each section ends with a cheat sheet & self-check.
Curriculum
Lessons marked “Read” are ready; the rest are on the way.
Level 1 — The model
- 01What GitOps isThe four principles, push vs pull, the reconcile loop, and what changes for teamsRead →
- 02Repository designApp repo vs config repo, directory layouts, Helm vs Kustomize, rendered manifestsRead →
- 03Promotion between environmentsImage updates, pull-request promotion, automation and guard-railsRead →
- 📋Cheat sheet & self-checkEvery command from this section on one page, then 9 questions to check yourself.Open →
Level 2 — Running it
- 04Secrets in GitOpsSealed Secrets, SOPS and External Secrets: what goes in Git and what never doesRead →
- 05Drift, rollback and recoverySelf-heal, pruning, git revert, and rebuilding a cluster from GitRead →
- 06Flux and Argo CDTwo implementations of the same idea: how they differ and how to chooseRead →
- 07Progressive deliveryCanary and blue-green with Argo Rollouts or Flagger, driven by metricsRead →
- 📋Cheat sheet & self-checkEvery command from this section on one page, then 12 questions to check yourself.Open →
Real-world scenarios
Work through each one: symptom → misleading signal → evidence → root cause → prevention.
The fix vanished ten minutes later. Explain why, and get it into Git properly.
Stop the spread, roll back, and add promotion gates.
Rebuild everything from Git in another region, and find what wasn't in Git.
This site is a public version of my personal engineering knowledge hub. It intentionally excludes confidential company information and internal operational details.