Argo CD 126 reads BookNest's desired state from a separate public config repository, github.com/binarybehemoth/booknest-gitops (https://github.com/binarybehemoth/booknest-gitops), holding the Kustomize 547,809 base and production overlay of Kustomize Overlays, so deploying needs no code build and is a separate permission:
mkdir ../booknest-gitops && cd ../booknest-gitops && git init -q -b main
mkdir base && cp ../booknest/k8s/kustomization.yaml \
$(yq '.resources[] | "../booknest/k8s/" + .' ../booknest/k8s/kustomization.yaml) base/
cp -r ../booknest/overlays/production .
sed -i 's|../../k8s|../base|' production/kustomization.yaml
git add . && git commit -qm "BookNest production, from the Kustomize overlay"
gh repo create binarybehemoth/booknest-gitops --public --source . --push \
--description "BookNest's Kubernetes manifests, deployed by Argo CD" 2>&1 | grep -v '^To 'https://github.com/binarybehemoth/booknest-gitops * [new branch] HEAD -> main branch 'main' set up to track 'origin/main'.
An Application joins a source (repository, revision, path) to a destination (cluster, namespace):
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata: { name: booknest, namespace: argocd }
spec:
project: default
source:
repoURL: https://github.com/binarybehemoth/booknest-gitops.git
targetRevision: main
path: production
destination: { server: https://kubernetes.default.svc, namespace: booknest }
syncPolicy:
automated: { prune: true, selfHeal: true } # apply, prune, undo driftkubectl apply -f booknest-app.yaml
git add booknest-app.yaml && git commit -qm "Add the Argo CD Application" && git push -q
until kubectl -n argocd get app booknest | grep -q 'Synced.*Healthy'; do sleep 3; done
kubectl -n argocd get app booknestapplication.argoproj.io/booknest created NAME SYNC STATUS HEALTH STATUS booknest Synced Healthy
Sync status compares Git 1,932 with the cluster; health judges live objects (a Deployment is Progressing until its rollout ends; custom kinds use Lua checks). Without automated, Argo CD only reports OutOfSync. The running objects were adopted, not recreated: Argo CD 3 marks what it manages with an argocd.argoproj.io/tracking-id annotation and ignores the rest, such as the db-credentials Secret.
