Portal | Level: L2: Operations | Topics: GitOps | Domain: DevOps & Tooling
Lab Runtime 07 — GitOps Sync and Drift¶
Objective¶
Demonstrate GitOps sync and drift reconciliation using ArgoCD concepts. This lab introduces configuration drift by manually modifying a running deployment outside of Helm/Git, then reconciles the drift by re-applying the declared Helm state (simulating an ArgoCD sync).
Prerequisites¶
make deploy-allhas been run and the grokdevops app is deployed and healthy- Helm 3 installed
- kubectl configured for the target cluster
- ArgoCD installed (optional -- the lab simulates ArgoCD sync behavior via Helm)
Steps¶
- Break: Run
./break.shto introduce drift by manually scaling the deployment and injecting a rogue environment variable, bypassing Helm/Git. - Observe: Compare the live state to the declared Helm values. In a real GitOps setup, ArgoCD would flag this as "OutOfSync".
- Fix: Run
./fix.shto reconcile drift by performing a Helm upgrade with the declared values (simulating an ArgoCD sync). - Verify: Run
./verify.shto confirm replica count and environment variables match the declared state. - Teardown: Run
./teardown.shto ensure clean Helm state.
Expected Observations¶
kubectl get deployment grokdevops -n grokdevopsshows a replica count that differs from the Helm-declared value (e.g., manually scaled to 5 when Helm says 2).kubectl get deployment grokdevops -n grokdevops -o jsonpath='{.spec.template.spec.containers[0].env}'shows a rogue environment variable not present in the Helm values file.helm get values grokdevops -n grokdevopsdoes not include the manual changes, confirming drift between desired state (Helm/Git) and actual state (cluster).
Wrong Turns¶
- Accepting drift as normal — Drift means the cluster no longer matches the declared source of truth. This leads to unreproducible deployments, mystery behavior, and broken disaster recovery.
- Using
kubectlto "fix" the drift — Applying more manualkubectlpatches creates additional drift. The correct approach is to reconcile via Helm (or ArgoCD sync) so the declared state wins. - Blaming ArgoCD or the GitOps tool — ArgoCD correctly detects and reports drift. The problem is the manual change, not the tool that flags it. The fix is to re-sync from the declared state.
Minimal Explanation¶
Helm stores the rendered manifests of each release revision in a
Kubernetes Secret. When you use kubectl to directly modify a resource
(e.g., scaling replicas or adding env vars), those changes exist only
in the live cluster state (etcd) and are not recorded in Helm's stored
manifests or in Git. This creates divergence: the desired state in Git
says one thing, the cluster says another. GitOps controllers like ArgoCD
continuously compare the two and flag differences as "OutOfSync." The
fix is to re-apply the declared state via helm upgrade (or ArgoCD
sync), which overwrites the manual changes with what Git declares.
Transfer Pattern¶
- Emergency hotfixes in production: An engineer uses
kubectlto patch a production issue at 2 AM. The fix works but is never committed to Git, so the next deploy reverts it. - Team members using kubectl directly: In organizations without strict GitOps enforcement, developers
kubectl applychanges that bypass the release pipeline, creating invisible drift.
See Also¶
training/library/guides/gitops-example.mdtraining/interview-scenarios/07-config-drift-detected.md
Solution (spoilers)¶
See training/library/solutions/labs/lab-runtime-07.md for hints and explanation.
Teardown¶
Or reset the entire environment:
Wiki Navigation¶
Prerequisites¶
- Kubernetes Exercises (Quest Ladder) (CLI) (Exercise Set, L1)
Related Content¶
- Argo Flashcards (CLI) (flashcard_deck, L1) — GitOps
- GitOps (Topic Pack, L1) — GitOps
- GitOps & ArgoCD Drills (Drill, L2) — GitOps
- Gitops Flashcards (CLI) (flashcard_deck, L1) — GitOps
- Interview: Config Drift Detected (Scenario, L2) — GitOps
- Interview: GitOps Drift Detected (Scenario, L2) — GitOps
- Runbook: ArgoCD Out of Sync (Runbook, L2) — GitOps
- Runbook: Deploy Rollback (Runbook, L1) — GitOps
- Skillcheck: GitOps (Assessment, L2) — GitOps
- Track: Helm & Release Ops (Reference, L1) — GitOps