Operate OpsKnight through GitOps
Promote Kustomize overlays safely with explicit migration ordering, secret ownership, drift control, validation, and rollback.
Prerequisites
Use a controller that supports ordered synchronization or hooks, a protected secret controller, server-side validation, policy checks, and auditable environment promotion.
Prepare GitOps ownership
Define owners for namespace/resources, Secrets, database migration Job, workloads, ingress/policy, and monitoring. Prevent multiple controllers from writing the same field. Remove placeholder Secrets and keep plaintext credentials outside Git.
Separate the one-shot migration from continuously reconciled Deployments. Use the controller's supported hook/sync-wave semantics or an external release job so migration succeeds before workload revision changes.
Deploy a revision
- Render the exact overlay in CI.
- Run server-side dry-run and policy checks.
- Review resource/image/topology diff.
- Reconcile Secret dependencies.
- Run and verify one-shot migration.
- Sync workload resources.
- Wait for role rollouts and execute acceptance.
Verify promotion
Confirm controller health/no unexpected drift, migration success, exact image, exclusive topology, readiness, role/queue progress, public routing, and synthetic incident lifecycle. Record the Git revision and evidence.
Operate it in production
Alert on reconciliation failure, unexpected prune, drift, hook failure, and unhealthy workloads. Pause automated promotion when migration or acceptance fails. Avoid live edits; encode durable fixes in the overlay.
Troubleshooting
Deployments sync before migration: correct wave/hook ownership and stop promotion; do not rely on retry timing.
Secret controller is late: add explicit health/dependency gating and keep workloads blocked until keys exist.
Controller prunes migration evidence: export logs/status to the release record before cleanup.
Rollback commit is unsafe after migration: use schema-compatible rollback rules; Git reversal cannot reverse database state.
Change or undo a revision
Follow Rollback. Revert manifests only when the prior image is compatible with the migrated schema; otherwise execute controlled data recovery. Record and fix the promotion-gate gap.
Next steps
Last updated for v2.0.0
Edit this page on GitHub