GitOps Principles

GitOps Principles and the Pull-Based Model

The CNCF's OpenGitOps project defines GitOps by four principles (version 1.0.0):

The third principle breaks with a classic pipeline. In a push model, CI (Jenkins 8,793 in Jenkins) holds cluster credentials and applies changes, and nothing notices later hand edits. In the pull model, the controller needs only read access to Git and CI only write access to Git; the loop of The Reconciliation Loop runs one level up, with the repository's HEAD as the spec.