ArgoCD
ArgoCD is a Kubernetes controller that keeps a cluster in step with manifests in Git. The GCP Web App Blueprint runs one ArgoCD instance in each stage's GKE cluster, and it is the only path by which the application's release reaches the cluster: no code pipeline deploys to the cluster directly.
What it does
An Application points at a path and revision of a Git repository and a destination namespace. ArgoCD renders the manifests there, compares them with the cluster and reports the Application as synced or out of sync. A sync applies the difference. With automated sync, ArgoCD syncs on every change; prune deletes resources removed from Git and self-heal reverts changes made in the cluster by hand. Without automated sync, a person starts each sync.
How BuiltForProd uses it
The argocd unit installs the argo-cd chart 10.9.6 on the tainted system pool and creates one Application, blueprint-app:
| Setting | Value |
|---|---|
| Source | acme-gcp-blueprint-webapp-gitops, branch main, path blueprint-app/helm |
| Values files | values.yaml, values-<stage>.yaml, ../envs/<stage>/values.yaml |
| Destination | Namespace blueprint-app, server-side apply |
Sync (argocd_auto_sync) | Automated with prune and self-heal in dev and staging; manual in prod |
HA (argocd_ha) | Off in dev; on in staging and prod: two replicas per component, a PDB each, and redis-ha, which needs three system nodes |
Promotion. The code pipeline never pushes to the GitOps repository: it opens a pull request that changes the image tag in envs/<stage>/values.yaml through a GitHub App token. Dev and staging pull requests auto-merge and sync automatically. For prod, promote-prod.yml runs behind the prod Environment's reviewers, a person merges the pull request, and a person starts the sync in ArgoCD. See GitHub Actions.
Repository access. ArgoCD clones the GitOps repository as the acme-runner GitHub App. Its credentials are Secret Manager secrets in acme-core-auto whose values are entered by hand; the stage deployer reads them and the unit stores them in the repository secret in the argocd namespace.
Secrets for the application. The unit also creates the ClusterSecretStore gcp-sm over Secret Manager of the stage project, used by the External Secrets Operator. The Application ignores the fields the External Secrets webhook fills in, so ArgoCD does not report a permanent difference.
Access. The UI and API are internal only, at argocd.<stage>.internal.company.com, behind a regional internal load balancer built by a GKE Gateway of class gke-l7-rilb, with a certificate from the internal CA of cert-manager. TLS ends at the Gateway. It is reachable from the networks of the Shared VPC host, such as the runners and the IAP bastions, and through kubectl port-forward.
Terms you will see
| Term | Meaning |
|---|---|
| Application | The ArgoCD object that ties a Git path to a namespace. |
| Automated sync | ArgoCD applies every change in Git without a person. |
| Self-heal | ArgoCD reverts changes made directly in the cluster. |
| Deploy pull request | The pull request a code workflow opens to change one stage's image tag. |
gcp-sm | The ClusterSecretStore over the stage project's Secret Manager. |
Where to read more
- GCP Web App Blueprint overview for the delivery chain.
- Helm for the chart ArgoCD renders.
- GitOps for the model behind it.