Level 2 — Running it · wrap-up
Cheat sheet & self-check
Every command from this section on one page.
Sealed Secrets
kubectl create secret generic db --from-literal=password=... --dry-run=client -o yaml > db.yaml | A normal Secret, never committed |
kubeseal --format yaml < db.yaml > db-sealed.yaml | Encrypt it for this cluster; commit db-sealed.yaml |
SOPS
age-keygen -o key.txt | Create an age key pair (keep the private key out of Git) |
sops --encrypt --age <public-key> --encrypted-regex '^(data|stringData)$' secret.yaml > secret.enc.yaml | Encrypt only the values |
sops --decrypt secret.enc.yaml | Decrypt to check (needs the key) |
External Secrets Operator
kubectl get externalsecrets -A | Which secrets are synced, and their status |
kubectl describe externalsecret db -n shop | Why a sync fails (permissions, missing key) |
Drift and sync
argocd app diff orders-api | Live vs Git, object by object |
argocd app sync orders-api --prune | Apply Git and delete objects removed from Git |
argocd app set orders-api --self-heal | Automatically revert manual changes |
flux diff kustomization apps --path ./apps | Flux: what would change |
During an incident
argocd app set orders-api --sync-policy none | Pause automated sync for one app (Argo CD) |
flux suspend kustomization apps | Pause reconciliation (Flux) |
flux resume kustomization apps | Resume, which re-applies Git |
git revert <sha> && git push | Roll back the change in Git |
Flux
flux check --pre | Is the cluster ready for Flux? |
flux bootstrap github --owner=acme --repository=gitops-config --path=clusters/dev-eu-1 | Install Flux and commit its own config to Git |
flux get all -A | Sources, kustomizations and Helm releases with status |
flux logs --level=error | Controller errors |
Argo CD
argocd app create orders-api --repo <url> --path apps/orders-api/envs/dev --dest-server https://kubernetes.default.svc --dest-namespace shop | Create an application |
argocd app list | Applications with sync and health status |
argocd app sync orders-api | Sync now |
Argo Rollouts
kubectl argo rollouts get rollout orders-api -n shop --watch | Live view of steps, weights and analysis |
kubectl argo rollouts promote orders-api -n shop | Move past a manual pause |
kubectl argo rollouts abort orders-api -n shop | Stop and return all traffic to the stable version |
kubectl argo rollouts dashboard | Local web dashboard |
Flagger
kubectl get canaries -A | Canary status and current weight |
kubectl describe canary orders-api -n shop | Analysis results and events |