Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Billy Yuen, Alexander Matyushentsev, Todd Ekenstam, Jesse Suen

Rating No ratings yet

GitOps and Kubernetes introduces a radical idea—managing your infrastructure with the same Git pull requests you use to manage your codebase. In this in-depth tutorial, you’ll learn to operate infrastructures based on powerful-but-complex technologies such as Kubernetes with the same Git version control tools most developers use daily. With these GitOps techniques and best practices, you’ll accelerate application development without compromising on security, easily roll back infrastructure changes, and seamlessly introduce new team members to your automation process. About the Technology With GitOps you use the Git version control system to organize and manage your infrastructure just like any other codebase. It’s an excellent model for applications deployed as containers and pods on Kubernetes. About the book GitOps and Kubernetes teaches you how to use Git and the GitOps methodology to manage a Kubernetes cluster. The book interleaves theory with practice, presenting core Ops concepts alongside easy-to-implement techniques so you can put GitOps into action. Learn to develop pipelines that trace changes, roll back mistakes, and audit container deployment. What's inside • Managing secrets the GitOps way • Controlling access with Git, Kubernetes, and Pipeline • Branching, namespaces, and configuration About the reader For developers and operations engineers familiar with continuous delivery, Git, and Kubernetes. About the authors Billy Yuen, Alexander Matyushentsev, Todd Ekenstam, and Jesse Suen are principal engineers at Intuit. They are widely recognized for their work in GitOps for Kubernetes.

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A hands-on guide to running Kubernetes the GitOps way: store desired state in Git, let an operator reconcile the cluster, and ship changes through pull requests. Best for developers and ops engineers who already know continuous delivery, Git, and Kubernetes basics and want a concrete migration path. 【Book Arc】 - **Opening (~0%–10%)**: Frames the core problem — infrastructure changes are manual, unauditable, and hard to roll back — and introduces GitOps as the fix: desired state lives in Git, changes flow through branches, reviews, and merges. - **Early (~10%–30%)**: Builds the Kubernetes foundation the rest of the book depends on: declarative vs. imperative object management, idempotency, controller architecture and delegation, plus a first simple GitOps operator you implement yourself. - **Early–Middle (~30%–45%)**: Moves from single deployments to environments — using Namespaces as boundaries, designing QA/E2E/stage/prod separation, and choosing a branching and repo organization strategy. - **Middle (~45%–60%)**: Compares configuration management tools (Helm, Kustomize, Jsonnet), weighing Helm's chart ecosystem against its templating readability and non-declarative `--set` pitfalls. - **Late (~60%–85%)**: Turns to the operational hard parts: managing secrets the GitOps way, controlling access across Git, Kubernetes, and pipelines, and building pipelines that trace, audit, and roll back changes. - **Ending (~85%–100%)**: Consolidates the practice with the named tooling (Argo CD, Jenkins X, Flux) and the workflow of promoting, verifying, and reverting deployments. (Excerpts do not cover the closing chapters in detail.) 【Key Takeaways】 - **Git is the single source of truth for desired state** (Opening): instead of changing systems via UI or CLI, engineers edit configuration files; any gap between Git and the live system signals undeployed change. - **Declarative beats imperative because it is idempotent** (Early): pressing "channel 3" always lands on channel 3, whereas imperative "channel up" depends on where you started — this is why Kubernetes pairs naturally with GitOps. - **Controllers are the reconciliation engine** (Early): each controller watches one resource type and drives actual state toward desired state, delegating work to other controllers (Deployment → ReplicaSet → Pod). - **Never reuse image tags like `latest`** (Early): if the manifest doesn't change, Kubernetes won't redeploy; use a unique version such as a commit SHA so every build is a detectable change. - **Namespaces define environment boundaries** (Middle): QA, E2E, stage, and prod can be separated by namespace, but the authors recommend splitting preprod and prod across two clusters to protect production. - **Helm is powerful but not automatically declarative** (Middle): its chart repository is a major strength, yet Go templating hurts readability and `--set` values escape version control, undermining reproducibility. - **Secrets and access control are first-class GitOps concerns** (Late): managing secrets, and scoping permissions across Git, Kubernetes, and pipelines, must be designed rather than bolted on. - **The ops role shifts to automation** (Opening): engineers move from performing deployments to maintaining GitOps automation and reviewing changes — the same pull-request skills developers already have. 【Reading Tips】 - Read chapters 1–2 carefully even if you know Kubernetes: the declarative/idempotency and controller-delegation explanations are the conceptual spine for every later tool. - Skim the tool comparison (Helm/Kustomize/Jsonnet) if you have already chosen a configuration tool; deep-read the trade-off discussion if you are still deciding. - Do the hands-on exercises — the local minikube cluster, the sample NGINX Pod, and the simple Bash operator — rather than only reading listings; they make reconciliation behavior concrete. - Treat the environment and branching chapters as design guidance, not recipes: adapt the two-cluster preprod/prod split to your own compliance and blast-radius needs. - Keep the companion repository (github.com/gitopsbook/resources) open while reading so you can run manifests instead of transcribing them. 【Coverage Limits】 This guide is synthesized from stratified excerpts covering roughly the first half of the book plus chapter-level signposting; the detailed treatment of Argo CD, Jenkins X, and Flux, and the secrets/access-control chapters, is only partially represented here.
Page 7
Suen M A N N I N G contents preface xi acknowledgments xii about this book xiii about the authors xviii about the cover illustration xx PART 1 BACKGROUND ......
View in text
Excerpt 2
icy: Always is specific to a particular kind of object. In volumes: The Volume that is the Pod example, spec includes a list of - name: data used to share da...
View in text
Excerpt 3
is running and waiting for the ConfigMap. Let’s create one. Refer to listing 2.4 for the manifest of the ConfigMap. We create the ConfigMap using the kubectl...
View in text
Excerpt 4
n that Helm templates suffer from a readability problem. We don’t doubt that this will be addressed with Helm 3’s support for Lua, but until then, well, we h...
View in text
Excerpt 5
ise when different modules are interacting with each other. During unit testing, external calls are typically “mocked” to eliminate dependencies issues and r...
View in text
Excerpt 6
ReplicaSet is declarative, all three Pods should be green. Deployment basics 119Deployment ensures that only a certain number of Pods are down while they are...
View in text
Excerpt 7
ass, which will always return 0 (healthy), and an Analysis- Template fail, which will always return 1 (unhealthy). In addition, Argo Rollouts internally main...
View in text
Excerpt 8
ure you’ve completed the basic GitOps operator tutorial. As you might remember, we have configured a CronJob along with a ServiceAccount and the ClusterRoleB...
View in text
Tags
AI categories
DevOpsCloud NativeGo
ISBN: 1617297976
Publish Year: 2021
Language: English
Pages: 344
File Format: PDF
File Size: 12.6 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…