惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
L
Lohrmann on Cybersecurity
罗磊的独立博客
V
V2EX
人人都是产品经理
人人都是产品经理
腾讯CDC
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
aimingoo的专栏
aimingoo的专栏
D
Docker
云风的 BLOG
云风的 BLOG
B
Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Microsoft Azure Blog
Microsoft Azure Blog
C
Check Point Blog
IT之家
IT之家
S
Secure Thoughts
S
Security @ Cisco Blogs
博客园 - 聂微东
阮一峰的网络日志
阮一峰的网络日志
G
Google Developers Blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
TaoSecurity Blog
TaoSecurity Blog
博客园_首页
雷峰网
雷峰网
博客园 - 三生石上(FineUI控件)
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
H
Heimdal Security Blog
Last Week in AI
Last Week in AI
Engineering at Meta
Engineering at Meta
D
DataBreaches.Net
J
Java Code Geeks
PCI Perspectives
PCI Perspectives
GbyAI
GbyAI
Help Net Security
Help Net Security
W
WeLiveSecurity
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
S
Schneier on Security
H
Hackread – Cybersecurity News, Data Breaches, AI and More
F
Full Disclosure
A
About on SuperTechFans
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
Recorded Future
Recorded Future
C
CXSECURITY Database RSS Feed - CXSecurity.com
NISL@THU
NISL@THU
Hacker News: Ask HN
Hacker News: Ask HN
The Cloudflare Blog
Latest news
Latest news
The Last Watchdog
The Last Watchdog
Attack and Defense Labs
Attack and Defense Labs
T
The Blog of Author Tim Ferriss

Sealos Blog

Build a Full-Stack App with Claude Code + InsForge — Zero Backend Code | Sealos Blog InsForge vs Supabase: Which Backend for AI-Powered Development? | Sealos Blog Kubernetes NodePort Exhaustion: SSH Gateway Solution | Sealos Blog Claude Code Metrics Dashboard: Grafana Setup (2026) | Sealos Blog What Is RustFS? Apache 2.0 MinIO Alternative (2026) | Sealos Blog Claude Code Mobile: iPhone, Android & SSH (2026) | Sealos Blog Eaglercraft Server Hosting: Fast Setup (2026) | Sealos Blog An Honest Review: Migrating a Complex Microservice App from Heroku to Sealos | Sealos Blog The Ultimate Guide to Kubernetes Audit Logging for Security and Compliance | Sealos Blog Cost Optimization Shootout: Sealos Autonomous FinOps vs. Kubecost Manual Reports | Sealos Blog For CTOs: How to Cut Your Cloud Bill by 50% Without Sacrificing Performance | Sealos Blog Building Resilient Systems: A Deep Dive into Sealos High-Availability and Auto-Failover | Sealos Blog Building a Scalable Event-Driven Architecture with Sealos Managed Kafka | Sealos Blog Beyond kubectl apply: 5 GitOps Best Practices for Production-Ready CI/CD on Sealos | Sealos Blog Advanced RAG Pipelines: Why Your Choice of Vector Database (like Milvus) Matters | Sealos Blog Advanced MLOps: How to Monitor and Evaluate LLM Applications in Production | Sealos Blog A Developer's Guide to Kubernetes RBAC: Securing Your Cluster the Easy Way with Sealos | Sealos Blog A CISO's Guide to Cloud Development: Securing the CI/CD Pipeline with Sealos DevBox | Sealos Blog What is Kubernetes Multi-Tenancy? A Guide for Platform Engineers | Sealos Blog What is Infrastructure from Code (IfC)? The Next Step After Infrastructure as Code (IaC) | Sealos Blog What is eBPF? The Future of Kubernetes Networking and Security | Sealos Blog What is an "AI-Native" Platform? (And Why You Need One for MLOps) | Sealos Blog What is an Agentic Workflow? Building the Next Generation of AI Apps | Sealos Blog What is a Kubernetes Chargeback Model (And How Does it Save You Money?) | Sealos Blog What is a "Headless" Development Environment? (And How it Works with VS Code) | Sealos Blog What is a Graph-Based Vector Database? (And When to Use It Over Milvus) | Sealos Blog What is a "Cloud Operating System"? The Next Evolution of PaaS Explained | Sealos Blog The Real Cost of EKS: How Sealos Delivers a Simpler, Cheaper Kubernetes Experience | Sealos Blog The 3 Types of Kubernetes Autoscaling (HPA, VPA, CA) and How Sealos Manages Them for You | Sealos Blog Sealos vs Vercel: Why a Cloud OS Beats a Frontend Platform for Full-Stack Apps | Sealos Blog Sealos vs. Render vs. Fly.io: A 2025 Guide to the Best Heroku Alternatives | Sealos Blog Sealos vs. OpenShift: Kubernetes for Developers vs. Kubernetes for Ops Teams | Sealos Blog Sealos vs. Netlify: When to Choose a Full Kubernetes Platform over a Static Site Hoster | Sealos Blog Sealos vs. DigitalOcean App Platform: A Head-to-Head Comparison on Cost, Features, and Scalability | Sealos Blog Sealos vs. AWS Elastic Beanstalk: The Modern PaaS for Developers Who Hate YAML | Sealos Blog Sealos DevBox vs. AWS Cloud9: Why Your CDE Should Be Platform-Agnostic | Sealos Blog For Developers: Stop Wasting Time on DevOps. A 10-Minute Guide to Shipping Faster with DevBox. | Sealos Blog Deploying n8n with Docker: From Local Setups to a Radically Simple Cloud Alternative | Sealos Blog The Impact of Prompt Bloat: How the Sealos AI Proxy Can Cache Queries and Cut LLM Costs | Sealos Blog The FinOps Playbook: How to Implement Kubernetes Chargebacks and Showbacks with Sealos | Sealos Blog Smoke Testing for ML Pipelines: Catching Data and Model Errors Before They Hit Production | Sealos Blog Optimizing PostgreSQL Performance: A Guide to Sealos Managed Database Tuning | Sealos Blog Managing Kubernetes Multi-Tenancy: How Sealos Enforces Resource Quotas and Network Policies | Sealos Blog From Days to Minutes: How to Standardize Developer Environments for Your Entire Engineering Org | Sealos Blog For Platform Engineers: How to Build a Golden Path IDP (Internal Developer Platform) with Sealos | Sealos Blog For FinOps Managers: The 5 Leakiest Buckets in Your Kubernetes Budget (And How to Plug Them) | Sealos Blog For Educators & IT Admins: How to Provide a Secure, Scalable Cloud Lab for 1000+ Students on a Budget | Sealos Blog What is a Vector Database? A Beginner's Guide to Milvus, Pinecone, and More | Sealos Blog Why Your Microservices Architecture is Failing (And How a Cloud OS Can Fix It) | Sealos Blog The Power of Autoscaling: A Deep Dive into HPA, VPA, and Cluster Autoscaler | Sealos Blog The Total Economic Impact of Cloud Development Environments (CDEs) | Sealos Blog The Illustrated Guide to the Kubernetes Control Plane | Sealos Blog The MLOps Lifecycle Explained: From Data Prep to Model Deployment | Sealos Blog Beyond Vercel's AI Cloud: The Case for an AI-Native Operating System | Sealos Blog The Architecture of a Modern AI Application: A 2025 Blueprint | Sealos Blog GitHub Codespaces is Great, But Your Workflow is Incomplete. Here's Why. | Sealos Blog The Best Heroku Alternatives in 2025 for Scalability and Cost | Sealos Blog CAST AI vs. Kubecost vs. Sealos: Choosing the Right K8s Cost Management Tool | Sealos Blog DevBox vs. Gitpod vs. Replit: An Unbiased Comparison for 2025 | Sealos Blog Unlocking Hidden Savings: A Guide to Using Spot Instances Safely in Kubernetes | Sealos Blog Can a CDE Really Replace Your MacBook Pro? A Performance Benchmark | Sealos Blog The End of "Works on My Machine": Achieving 100% Reproducible Builds with DevBox | Sealos Blog The Ultimate Guide to GPU Provisioning and Management in Kubernetes | Sealos Blog Rightsizing Kubernetes Workloads: How to Stop Wasting Money on CPU and Memory Requests | Sealos Blog The 2025 Guide to Kubernetes Cost Optimization: 10 Strategies to Cut Your Bill in Half | Sealos Blog FinOps for Startups: How to Build a Cost-Conscious Culture from Day One | Sealos Blog How to Onboard a New Developer in Under 5 Minutes with Sealos DevBox | Sealos Blog Calculating Kubernetes Costs: A Breakdown of EKS, GKE, and AKS Pricing Models | Sealos Blog Case Study: How We Reduced Our Kubernetes Bill by 87% with Sealos | Sealos Blog Are You Overpaying for Managed Kubernetes? The True Cost of Vendor Lock-in | Sealos Blog Beyond Monitoring: How Sealos Autonomously Optimizes Your Cloud Spend | Sealos Blog A Practical Guide to Kubernetes Security: Hardening Your Cluster in 2025 | Sealos Blog A Secure-by-Design Development Workflow with Isolated Cloud Environments | Sealos Blog Setting Up a Collaborative Python Data Science Environment with DevBox | Sealos Blog Using the Sealos AI Proxy to Manage and Cache LLM API Calls | Sealos Blog Migration Guide: Moving Your Node.js & Postgres App from Heroku to Sealos in Under an Hour | Sealos Blog Serving Machine Learning Models at Scale: A Guide to Inference Optimization | Sealos Blog Headless Development with Sealos: Using Your Local VS Code with a Powerful Cloud Backend | Sealos Blog How to Build and Deploy a RAG Pipeline with Llama 3 and Milvus on Sealos | Sealos Blog From Localhost to Production in 15 Minutes: A Full-Stack CDE Workflow with Sealos DevBox | Sealos Blog GitOps on Autopilot: Implementing a CI/CD Pipeline with Sealos and GitHub Actions | Sealos Blog Fine-Tuning Open-Source LLMs on a Budget with Sealos | Sealos Blog From Docker Compose to Kubernetes: A Simple Migration Path with Sealos | Sealos Blog Building an AI Agentic Workflow with LangChain and Sealos | Sealos Blog What is Helm for Kubernetes? The Ultimate Package Manager Explained | Sealos Blog What is a Custom Resource Definition (CRD) in Kubernetes? | Sealos Blog What is a Kubernetes StatefulSet? A Practical Guide | Sealos Blog What is a Kubernetes Ingress Controller? A Guide to Smart Traffic Routing | Sealos Blog What is a Kubernetes Operator? Automating Complex Applications | Sealos Blog What is a Kubernetes Service? A Simple Guide for Developers | Sealos Blog Streamlining Your CI/CD Pipeline with a DevBox Build Environment | Sealos Blog Why Standardized Development Environments Are Key to Team Velocity | Sealos Blog What Is GitHub Codespace? | Sealos Blog DevBox Install? Skip It Entirely. Get a Ready-to-Code Environment in One Click with Sealos DevBox. | Sealos Blog How to Set Up a DevBox: The Ultimate Guide to 1-Click Cloud Development | Sealos Blog Empowering Indie Devs and Startup Teams: How Sealos DevBox Accelerates Agile Development | Sealos Blog From Chaos to Consistency: How Sealos DevBox Transforms Enterprise Development Workflows | Sealos Blog From Campus Labs to Cloud Freedom: How Sealos DevBox Supercharges Student Development | Sealos Blog How Sealos DevBox Cut Container Commit Time from 15 Minutes to 1 Second | Sealos Blog DevBox vs Codespaces: Which Remote Dev Environment Fits You Best? | Sealos Blog
What is GitOps? A Beginner's Guide to "Push-to-Deploy" Workflows | Sealos Blog
Sealos · 2025-10-18 · via Sealos Blog

Ever pushed a change to production and held your breath, hoping nothing breaks? Or spent hours debugging an issue only to find the staging environment was subtly different from production? You're not alone. Managing modern, cloud-native infrastructure is complex. Environments drift, manual deployments are error-prone, and tracking who changed what, when, and why can feel like a detective story.

What if there was a better way? What if you could manage your entire infrastructure with the same rigor, transparency, and collaboration you use for your application code? What if a simple git push could securely and reliably update your applications and infrastructure?

This is the promise of GitOps. It’s a powerful operational framework that takes the best practices from DevOps—like version control, collaboration, and CI/CD automation—and applies them directly to infrastructure management. By making Git the single source of truth for your entire system, GitOps provides a clear, auditable, and automated path from code to cluster.

This guide will demystify GitOps. We'll explore what it is, why it's transforming modern operations, how it works, and how you can get started on your journey to a more stable, secure, and efficient "push-to-deploy" workflow.

At its heart, GitOps is a paradigm for managing infrastructure and applications where the desired state of the entire system is declaratively defined and version-controlled in a Git repository.

Let's break that down:

  • Declarative: Instead of writing scripts that say how to achieve a state (imperative), you create configuration files (like Kubernetes YAML) that describe what the final state should look like. For example, "I want three replicas of my web server running version 1.2."
  • Version-Controlled in Git: These declarative files live in a Git repository. This makes Git the single source of truth. The state defined in the main branch is the state that should be live in production.
  • Automated Reconciliation: A software agent constantly compares the live state of your infrastructure (e.g., your Kubernetes cluster) with the desired state in the Git repository. If there's a difference (a "drift"), the agent automatically updates the live environment to match the repository.

Think of it like a thermostat. You declaratively set the desired temperature (the state in Git). The thermostat (the GitOps agent) constantly monitors the room's actual temperature (the live system state) and automatically turns the heat or AC on or off to match your desired setting. You don't tell it how to heat the room; you just declare the result you want.

The concept of GitOps was first formalized by Weaveworks, who outlined four key principles that define a true GitOps workflow.

1. The Entire System is Described Declaratively

As mentioned, all resources—infrastructure, networking, monitoring, and applications—are defined in a declarative format. For Kubernetes users, this typically means YAML manifests. For infrastructure, it could be Terraform or CloudFormation files. This approach is crucial because it provides an unambiguous description of the system that both humans and machines can understand.

2. The Canonical Desired System State is Versioned in Git

Git is the ultimate source of truth. If you want to deploy a new application, scale a service, or change a configuration, you don't SSH into a server or use a manual dashboard. You make a change to the configuration file and submit a pull request. This leverages Git's powerful features for operations:

  • Audit Trail: A complete history of every change, who made it, and why.
  • Rollbacks: A bad deployment can be reverted with a single git revert command.
  • Collaboration: Pull requests enable peer review and discussion for infrastructure changes, just like application code.

3. Approved Changes are Automatically Applied to the System

Once changes are approved and merged into the target branch (e.g., main), they are automatically applied to the live environment. This is handled by a software agent that syncs the state from the Git repository to the cluster. This automated process removes the need for manual kubectl apply commands or direct cluster credentials in your CI pipeline, reducing the risk of human error.

4. Software Agents Ensure Correctness and Alert on Divergence

A GitOps agent continuously runs inside your environment, acting as a control loop. Its job is twofold:

  • Ensure Correctness: It constantly compares the live system state against the desired state in Git.
  • Alert on Divergence: If the live state ever drifts from the Git state (e.g., due to a manual, out-of-band change), the agent can either automatically correct it (self-healing) or alert the team to the discrepancy. This closes the loop and guarantees that your Git repository is a true reflection of your running infrastructure.

Let's walk through a typical GitOps workflow for a developer wanting to deploy a new version of an application.

  1. Code Change: A developer makes a change to the application code and pushes it to the application code repository.
  2. Continuous Integration (CI): This push triggers a CI pipeline (e.g., using Jenkins, GitLab CI, or GitHub Actions). The pipeline runs tests, builds a new container image, and pushes it to a container registry (like Docker Hub or Harbor). The image is tagged with a unique identifier, often the Git commit hash.
  3. Configuration Update: Here's the key GitOps step. The CI pipeline (or a dedicated tool) automatically creates a commit in a separate configuration repository. This commit updates the Kubernetes manifest file, changing the image tag to point to the new container image built in the previous step.
  4. Pull Request and Merge: The change is submitted as a pull request to the configuration repository. The operations team or senior developers review the proposed change (e.g., deploying image v1.2.1 to production), approve it, and merge it into the main branch.
  5. GitOps Agent Detection: A GitOps agent (like Argo CD or Flux), running inside the Kubernetes cluster, is configured to watch the configuration repository. It detects that the main branch has been updated.
  6. Reconciliation: The agent compares the new manifests in Git with the resources currently running in the cluster. It sees that the running deployment is using the old image tag, while the Git repository specifies the new one.
  7. Deployment: The agent "pulls" the change and applies it to the cluster, triggering a rolling update of the application to the new version. The live state now matches the desired state in Git.

This entire process, from merging the pull request to the live deployment, happens automatically, securely, and with a full audit trail.

There are two primary models for how changes get from Git to the cluster. The pull-based model is generally considered the more secure and robust approach.

Pull-Based GitOps (Agent-driven)

This is the model described in the workflow above and is considered the canonical approach.

  • How it works: An operator (agent) runs inside the Kubernetes cluster. It periodically "pulls" from the Git repository to check for new commits. If it finds any, it applies the changes to the cluster from within.
  • Pros:
    • High Security: Cluster credentials are not exposed outside the cluster boundary. The agent only needs read-only access to the Git repository.
    • Drift Detection: Because the agent lives in the cluster, it can constantly monitor for any differences between the desired and actual states.
    • Scalability: Each cluster manages its own state, making it easy to manage many clusters from a central set of configuration repositories.

Push-Based GitOps (CI-driven)

This is an older model that is simpler to set up but has significant drawbacks.

  • How it works: The CI/CD pipeline (e.g., Jenkins) is responsible for pushing changes directly to the Kubernetes cluster after a change is merged in Git.
  • Cons:
    • Lower Security: The CI system needs direct administrative access to the Kubernetes cluster. This exposes powerful credentials outside the cluster, widening the attack surface.
    • No Drift Detection: The CI pipeline only acts when a change is pushed. It has no awareness of the cluster's state at other times and cannot detect or correct manual changes.
FeaturePull-Based Model (Recommended)Push-Based Model
TriggerAgent inside the cluster pulls changes.CI pipeline outside the cluster pushes changes.
SecurityHigh. Cluster credentials remain within the cluster.Lower. CI system requires admin access to the cluster.
Drift DetectionYes. The agent constantly compares live vs. desired state.No. The pipeline is unaware of out-of-band changes.
ScalabilityExcellent for managing multiple clusters.Can become complex and fragile at scale.
Key ToolsArgo CD, Flux CDJenkins, GitLab CI (with custom scripts)

Adopting GitOps isn't just about following a trend; it delivers tangible business and technical advantages.

Increased Developer Velocity

By automating the deployment pipeline, developers can release features faster and more independently. The "push-to-deploy" workflow means that once their code is tested and their configuration PR is merged, their work is done. They don't need to learn kubectl or wait for an operations team to perform a manual deployment.

Enhanced Security and Compliance

GitOps creates an unbreakable audit log. Every change to the production environment is tied to a Git commit, which is tied to a pull request and an author. This makes security audits and compliance checks straightforward. Furthermore, by limiting direct cluster access and using the pull-based model, you dramatically reduce the risk of unauthorized changes.

Improved Reliability and Stability

  • Mean Time to Recovery (MTTR): When a bad deployment occurs, recovery is as fast and simple as git revert. This rolls the system back to the last known good state, and the GitOps agent handles the rest.
  • Disaster Recovery: If a cluster is completely lost, you can bring up a new one and simply point your GitOps agent at the configuration repository. The agent will rebuild the entire environment from scratch based on the declarative manifests.

Greater Transparency and Collaboration

With the entire system state visible in Git, everyone on the team—developers, operations, and security—can see what's running, what has changed, and what's planned. Using pull requests for infrastructure changes fosters a culture of review and collaboration, catching potential issues before they reach production.

The GitOps ecosystem has matured rapidly, with two main projects leading the way in the Cloud Native Computing Foundation (CNCF).

  • Argo CD: A declarative, GitOps continuous delivery tool for Kubernetes. It is known for its powerful web UI, which provides a fantastic real-time visualization of application status and the differences between the live and desired states. It's very application-centric and easy for teams to adopt.
  • Flux CD: A toolkit for keeping Kubernetes clusters in sync with sources of configuration (like Git repositories) and automating updates to configuration when there is new code to deploy. Flux is known for its modular, "do one thing well" approach and deep integration into the Kubernetes ecosystem.

Simplifying the Foundation for GitOps with Sealos

Before you can even start with GitOps, you need a stable, running Kubernetes cluster. Setting up and managing Kubernetes can be a significant hurdle, involving complex networking, certificate management, and node provisioning.

This is where a platform like Sealos can be invaluable. Sealos is a cloud operating system that radically simplifies the deployment and management of high-availability Kubernetes clusters, whether on-premise or in the cloud.

With Sealos, you can get a production-ready Kubernetes cluster running in minutes. This provides the perfect, solid foundation on top of which you can layer your GitOps tools. Instead of wrestling with kubeadm or complex installation scripts, you can use Sealos to handle the cluster lifecycle, allowing your team to focus on what matters: implementing a robust GitOps workflow with tools like Argo CD or Flux.

Ready to dip your toes in the water? Here’s a high-level roadmap to get started.

  1. Prerequisites:

    • A Kubernetes cluster. (As mentioned, using a tool like Sealos can make this the easiest step).
    • A Git repository for your application code.
    • A separate Git repository for your Kubernetes configuration manifests.
    • A container registry to store your application images.
  2. Choose and Install a GitOps Tool: Select an agent like Argo CD or Flux. Follow their official documentation to install the agent into your Kubernetes cluster. This is typically a one-time setup.

  3. Structure Your Repositories: Create a new Git repository for your configuration. Inside, create a directory for your first application.

  4. Create Your First Application Manifest: Add a Kubernetes manifest file (e.g., deployment.yaml) to your configuration repository. This file will declaratively define your application.

  5. Connect the Agent to Your Repo: Configure your GitOps agent (e.g., via the Argo CD UI or a Flux Kustomization object) to watch your configuration repository and the specific path where your application manifest lives.

  6. Watch the Magic: As soon as you configure the agent, it will pull the manifest from Git and deploy your Nginx application to the cluster. You can use kubectl get deployments to see it running.

  7. Make a Change: Now, for the real test. Edit the deployment.yaml file in your Git repository. Change replicas: 2 to replicas: 3. Commit and push the change to your main branch.

Within a few moments, without any manual intervention, you will see your GitOps agent detect the change and scale your deployment. You'll now have three Nginx pods running in your cluster. You have just completed your first GitOps loop!

GitOps is more than just a buzzword; it represents a fundamental shift towards a more automated, reliable, and secure model for managing cloud-native systems. By establishing Git as the single source of truth, you unlock powerful workflows that increase developer velocity, strengthen security, and dramatically improve system stability.

The journey starts with understanding the core principles: a declarative system state, versioned in Git, with changes automatically applied and reconciled by software agents. By embracing this model, you can finally tame the complexity of modern infrastructure, eliminate configuration drift, and empower your teams to build and deploy with confidence. The "push-to-deploy" future is here, and it's version-controlled.