The CNCF's OpenGitOps project defines GitOps by four principles (version 1.0.0):
Declarative: the desired state is expressed as data, such as manifests.
Versioned and immutable: that state is stored with its complete history, in practice in Git 1,932 .
Pulled automatically: software agents fetch the desired state from the source themselves.
Continuously reconciled: the agents correct any difference in the live state.
The third principle breaks with a classic pipeline. In a push model, CI (Jenkins 8,793 in Jenkins) holds cluster credentials and applies changes, and nothing notices later hand edits. In the pull model, the controller needs only read access to Git and CI only write access to Git; the loop of The Reconciliation Loop runs one level up, with the repository's HEAD as the spec.