Skip to main content

ArgoCD

ArgoCD is a Kubernetes controller that keeps a cluster in step with manifests in Git. The GCP Web App Blueprint runs one ArgoCD instance in each stage's GKE cluster, and it is the only path by which the application's release reaches the cluster: no code pipeline deploys to the cluster directly.

What it does​

An Application points at a path and revision of a Git repository and a destination namespace. ArgoCD renders the manifests there, compares them with the cluster and reports the Application as synced or out of sync. A sync applies the difference. With automated sync, ArgoCD syncs on every change; prune deletes resources removed from Git and self-heal reverts changes made in the cluster by hand. Without automated sync, a person starts each sync.

How BuiltForProd uses it​

The argocd unit installs the argo-cd chart 10.9.6 on the tainted system pool and creates one Application, blueprint-app:

SettingValue
Sourceacme-gcp-blueprint-webapp-gitops, branch main, path blueprint-app/helm
Values filesvalues.yaml, values-<stage>.yaml, ../envs/<stage>/values.yaml
DestinationNamespace blueprint-app, server-side apply
Sync (argocd_auto_sync)Automated with prune and self-heal in dev and staging; manual in prod
HA (argocd_ha)Off in dev; on in staging and prod: two replicas per component, a PDB each, and redis-ha, which needs three system nodes

Promotion. The code pipeline never pushes to the GitOps repository: it opens a pull request that changes the image tag in envs/<stage>/values.yaml through a GitHub App token. Dev and staging pull requests auto-merge and sync automatically. For prod, promote-prod.yml runs behind the prod Environment's reviewers, a person merges the pull request, and a person starts the sync in ArgoCD. See GitHub Actions.

Repository access. ArgoCD clones the GitOps repository as the acme-runner GitHub App. Its credentials are Secret Manager secrets in acme-core-auto whose values are entered by hand; the stage deployer reads them and the unit stores them in the repository secret in the argocd namespace.

Secrets for the application. The unit also creates the ClusterSecretStore gcp-sm over Secret Manager of the stage project, used by the External Secrets Operator. The Application ignores the fields the External Secrets webhook fills in, so ArgoCD does not report a permanent difference.

Access. The UI and API are internal only, at argocd.<stage>.internal.company.com, behind a regional internal load balancer built by a GKE Gateway of class gke-l7-rilb, with a certificate from the internal CA of cert-manager. TLS ends at the Gateway. It is reachable from the networks of the Shared VPC host, such as the runners and the IAP bastions, and through kubectl port-forward.

Terms you will see​

TermMeaning
ApplicationThe ArgoCD object that ties a Git path to a namespace.
Automated syncArgoCD applies every change in Git without a person.
Self-healArgoCD reverts changes made directly in the cluster.
Deploy pull requestThe pull request a code workflow opens to change one stage's image tag.
gcp-smThe ClusterSecretStore over the stage project's Secret Manager.

Where to read more​