GitOps Principles & Practice›Level 2 · Cheat sheet & self-check

Level 2 — Running it · wrap-up

Cheat sheet & self-check

Every command from this section on one page.

04 · Secrets in GitOps

Sealed Secrets

kubectl create secret generic db --from-literal=password=... --dry-run=client -o yaml > db.yamlA normal Secret, never committed
kubeseal --format yaml < db.yaml > db-sealed.yamlEncrypt it for this cluster; commit db-sealed.yaml

SOPS

age-keygen -o key.txtCreate an age key pair (keep the private key out of Git)
sops --encrypt --age <public-key> --encrypted-regex '^(data|stringData)$' secret.yaml > secret.enc.yamlEncrypt only the values
sops --decrypt secret.enc.yamlDecrypt to check (needs the key)

External Secrets Operator

kubectl get externalsecrets -AWhich secrets are synced, and their status
kubectl describe externalsecret db -n shopWhy a sync fails (permissions, missing key)

05 · Drift, rollback and recovery

Drift and sync

argocd app diff orders-apiLive vs Git, object by object
argocd app sync orders-api --pruneApply Git and delete objects removed from Git
argocd app set orders-api --self-healAutomatically revert manual changes
flux diff kustomization apps --path ./appsFlux: what would change

During an incident

argocd app set orders-api --sync-policy nonePause automated sync for one app (Argo CD)
flux suspend kustomization appsPause reconciliation (Flux)
flux resume kustomization appsResume, which re-applies Git
git revert <sha> && git pushRoll back the change in Git

06 · Flux and Argo CD

Flux

flux check --preIs the cluster ready for Flux?
flux bootstrap github --owner=acme --repository=gitops-config --path=clusters/dev-eu-1Install Flux and commit its own config to Git
flux get all -ASources, kustomizations and Helm releases with status
flux logs --level=errorController errors

Argo CD

argocd app create orders-api --repo <url> --path apps/orders-api/envs/dev --dest-server https://kubernetes.default.svc --dest-namespace shopCreate an application
argocd app listApplications with sync and health status
argocd app sync orders-apiSync now

07 · Progressive delivery

Argo Rollouts

kubectl argo rollouts get rollout orders-api -n shop --watchLive view of steps, weights and analysis
kubectl argo rollouts promote orders-api -n shopMove past a manual pause
kubectl argo rollouts abort orders-api -n shopStop and return all traffic to the stable version
kubectl argo rollouts dashboardLocal web dashboard

Flagger

kubectl get canaries -ACanary status and current weight
kubectl describe canary orders-api -n shopAnalysis results and events