GitOps cuts Jenkins's pipeline in two. Jenkins 8,793 still tests, builds, scans and pushes the image, but its last step writes the new tag into the config repository instead of deploying, so it needs a Git 1,932 credential rather than the cluster token of Jenkins Deploy Access:
stage('Promote to production') {
steps {
withCredentials([gitUsernamePassword(credentialsId: 'booknest-gitops-token')]) {
sh """
git clone -q https://github.com/binarybehemoth/booknest-gitops.git gitops && cd gitops
yq -i '.images[0].newTag = "${env.IMAGE_TAG}"' production/kustomization.yaml
git commit -qam "Deploy BookNest API ${env.IMAGE_TAG} (build ${env.BUILD_NUMBER})"
git push -q origin main
"""
}
}
}For production, open a pull request instead, so a person approves and GitHub's branch protection applies. Argo CD 126 Image Updater and Flux 213,041 's image automation controllers can even commit new tags themselves.