gitops-workflow
wshobson/agents
Implement GitOps workflows with ArgoCD and Flux for automated, declarative Kubernetes deployments.
What is gitops-workflow?
This skill guides you through setting up GitOps practices using ArgoCD or Flux CD to manage Kubernetes deployments declaratively from Git repositories. Use it when automating application deployments, implementing continuous reconciliation, or managing multi-cluster infrastructure following OpenGitOps principles.
- Install and configure ArgoCD or Flux CD for Git-based continuous delivery
- Define declarative application manifests and sync policies for automated reconciliation
- Implement progressive delivery strategies including canary and blue-green deployments
- Manage secrets securely in GitOps workflows using External Secrets or Sealed Secrets
- Set up App of Apps pattern for organizing and managing multiple applications
- Configure auto-sync policies with pruning and self-healing capabilities
How to install gitops-workflow
npx skills add https://github.com/wshobson/agents --skill gitops-workflow- Kubernetes cluster (1.19+) with kubectl access
- Git repository for storing manifests and configurations
- ArgoCD or Flux CLI installed locally
How to use gitops-workflow
- 1.Create a Git repository with your desired cluster state organized by environment and application
- 2.Install ArgoCD (kubectl apply) or Flux (flux bootstrap) on your Kubernetes cluster
- 3.Define Application resources (ArgoCD) or GitRepository/Kustomization resources (Flux) pointing to your Git repo
- 4.Configure sync policies with automated pruning and self-healing enabled
- 5.Set up secret management using External Secrets Operator or Sealed Secrets
- 6.Monitor sync status and configure notifications for deployment failures
- 7.Test progressive delivery strategies (canary/blue-green) in staging before production
Use cases
- Automate Kubernetes application deployments triggered by Git commits
- Set up multi-environment deployments (staging, production) with separate Git branches
- Implement canary rollouts with automated traffic shifting and pause gates
- Manage infrastructure as code with continuous reconciliation between Git and cluster state
- Enable disaster recovery by storing entire cluster configuration in version control
- Platform engineers implementing continuous delivery infrastructure
- DevOps teams managing multi-cluster Kubernetes environments
- SREs automating infrastructure management and deployments
- Development teams adopting declarative deployment practices
gitops-workflow FAQ
ArgoCD uses a pull-based model with a centralized controller and provides a web UI for application management. Flux CD is more lightweight and uses GitOps Toolkit components for modular functionality. Both follow OpenGitOps principles; choose based on your operational preferences and cluster size.
Use External Secrets Operator to fetch secrets from AWS Secrets Manager, HashiCorp Vault, or other backends, or use Sealed Secrets to encrypt secrets in Git that only your cluster can decrypt.
With self-healing enabled, ArgoCD or Flux will automatically reconcile the cluster back to the Git-declared state within the sync interval (typically 1-5 minutes).
Yes, both ArgoCD and Flux support multi-cluster deployments. Use separate Git paths or repositories per cluster, or use ArgoCD's multi-cluster features to manage applications across clusters from a central control plane.
Rollback by reverting the commit in Git that caused the issue, or by checking out a previous tag/commit. The GitOps controller will automatically reconcile the cluster to the previous state.
Full instructions (SKILL.md)
Source of truth, from wshobson/agents.
name: gitops-workflow description: Implement GitOps workflows with ArgoCD and Flux for automated, declarative Kubernetes deployments with continuous reconciliation. Use when implementing GitOps practices, automating Kubernetes deployments, or setting up declarative infrastructure management.
GitOps Workflow
Complete guide to implementing GitOps workflows with ArgoCD and Flux for automated Kubernetes deployments.
Purpose
Implement declarative, Git-based continuous delivery for Kubernetes using ArgoCD or Flux CD, following OpenGitOps principles.
When to Use This Skill
- Set up GitOps for Kubernetes clusters
- Automate application deployments from Git
- Implement progressive delivery strategies
- Manage multi-cluster deployments
- Configure automated sync policies
- Set up secret management in GitOps
OpenGitOps Principles
- Declarative - Entire system described declaratively
- Versioned and Immutable - Desired state stored in Git
- Pulled Automatically - Software agents pull desired state
- Continuously Reconciled - Agents reconcile actual vs desired state
ArgoCD Setup
1. Installation
# Create namespace
kubectl create namespace argocd
# Install ArgoCD
kubectl apply -n argocd -f https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml
# Get admin password
kubectl -n argocd get secret argocd-initial-admin-secret -o jsonpath="{.data.password}" | base64 -d
Reference: See references/argocd-setup.md for detailed setup
2. Repository Structure
gitops-repo/
├── apps/
│ ├── production/
│ │ ├── app1/
│ │ │ ├── kustomization.yaml
│ │ │ └── deployment.yaml
│ │ └── app2/
│ └── staging/
├── infrastructure/
│ ├── ingress-nginx/
│ ├── cert-manager/
│ └── monitoring/
└── argocd/
├── applications/
└── projects/
3. Create Application
# argocd/applications/my-app.yaml
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: my-app
namespace: argocd
spec:
project: default
source:
repoURL: https://github.com/org/gitops-repo
targetRevision: main
path: apps/production/my-app
destination:
server: https://kubernetes.default.svc
namespace: production
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true
4. App of Apps Pattern
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: applications
namespace: argocd
spec:
project: default
source:
repoURL: https://github.com/org/gitops-repo
targetRevision: main
path: argocd/applications
destination:
server: https://kubernetes.default.svc
namespace: argocd
syncPolicy:
automated: {}
Flux CD Setup
1. Installation
# Install Flux CLI
curl -s https://fluxcd.io/install.sh | sudo bash
# Bootstrap Flux
flux bootstrap github \
--owner=org \
--repository=gitops-repo \
--branch=main \
--path=clusters/production \
--personal
2. Create GitRepository
apiVersion: source.toolkit.fluxcd.io/v1
kind: GitRepository
metadata:
name: my-app
namespace: flux-system
spec:
interval: 1m
url: https://github.com/org/my-app
ref:
branch: main
3. Create Kustomization
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: my-app
namespace: flux-system
spec:
interval: 5m
path: ./deploy
prune: true
sourceRef:
kind: GitRepository
name: my-app
Sync Policies
Auto-Sync Configuration
ArgoCD:
syncPolicy:
automated:
prune: true # Delete resources not in Git
selfHeal: true # Reconcile manual changes
allowEmpty: false
retry:
limit: 5
backoff:
duration: 5s
factor: 2
maxDuration: 3m
Flux:
spec:
interval: 1m
prune: true
wait: true
timeout: 5m
Reference: See references/sync-policies.md
Progressive Delivery
Canary Deployment with ArgoCD Rollouts
apiVersion: argoproj.io/v1alpha1
kind: Rollout
metadata:
name: my-app
spec:
replicas: 5
strategy:
canary:
steps:
- setWeight: 20
- pause: { duration: 1m }
- setWeight: 50
- pause: { duration: 2m }
- setWeight: 100
Blue-Green Deployment
strategy:
blueGreen:
activeService: my-app
previewService: my-app-preview
autoPromotionEnabled: false
Secret Management
External Secrets Operator
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: db-credentials
spec:
refreshInterval: 1h
secretStoreRef:
name: aws-secrets-manager
kind: SecretStore
target:
name: db-credentials
data:
- secretKey: password
remoteRef:
key: prod/db/password
Sealed Secrets
# Encrypt secret
kubeseal --format yaml < secret.yaml > sealed-secret.yaml
# Commit sealed-secret.yaml to Git
Best Practices
- Use separate repos or branches for different environments
- Implement RBAC for Git repositories
- Enable notifications for sync failures
- Use health checks for custom resources
- Implement approval gates for production
- Keep secrets out of Git (use External Secrets)
- Use App of Apps pattern for organization
- Tag releases for easy rollback
- Monitor sync status with alerts
- Test changes in staging first
Troubleshooting
Sync failures:
argocd app get my-app
argocd app sync my-app --prune
Out of sync status:
argocd app diff my-app
argocd app sync my-app --force
Related Skills
k8s-manifest-generator- For creating manifestshelm-chart-scaffolding- For packaging applications
Related skills
More from wshobson/agents and the wider catalog.

go-concurrency-patterns
Master Go concurrency with goroutines, channels, sync primitives, and context management.

godot-gdscript-patterns
Master Godot 4 GDScript patterns: signals, scenes, state machines, and optimization for game development.

grafana-dashboards
Create and manage production Grafana dashboards for real-time system and application metric visualization.

grpo-rlvr-training
Train reasoning models with GRPO and reinforcement learning from verifiable rewards when task success is algorithmically checkable.

hads
Human-AI Document Standard for technical docs readable by both humans and AI models.

helm-chart-scaffolding
Design, organize, and manage Helm charts for templating and packaging Kubernetes applications.