A self-contained GitOps example for deploying a small API to Kubernetes with Helm, Argo CD and Terraform-managed Kind.
- GitHub Actions runs application tests and Helm validation.
- The workflow builds and publishes the immutable commit image to GHCR.
- Argo CD watches the Helm source and reconciles the desired state.
- Kubernetes performs rolling updates and horizontal autoscaling.
terraform -chdir=terraform init
terraform -chdir=terraform apply
helm lint helm/demo-api
helm template demo-api helm/demo-api
kubectl apply -f argocd/application.yamlReplace every OWNER placeholder with your GitHub username or organization. In a real repository, use an image updater or a separate environment repository to commit the tested image digest instead of deploying latest.
GitOps reconciliation, Helm templating, Argo CD automated sync/self-heal, Terraform infrastructure, rolling updates, HPA, security contexts and CI validation.
Terraform (Kind) -> Argo CD (Git source of truth) -> Helm chart -> Rolling update + HPA
terraform/main.tf— provisions the Kind-managed cluster and network.helm/demo-api/— chart with Deployment, Service, Ingress, HPA andsecurityContext.argocd/application.yaml— Argo CD app pointing at the Helm source.
GitOps works only if Git is the single source of truth and drift is impossible: Argo CD's self-heal continuously reconciles back to the committed manifests, so a manually changed pod is reverted. Pairing that with :<sha> image tags means every applied revision is reproducible and auditable, and an Ingress + HPA in the same chart keeps the app usable and elastic without extra repos.
terraform -chdir=terraform init
terraform -chdir=terraform apply
helm lint helm/demo-api
helm template demo-api helm/demo-api
kubectl apply -f argocd/application.yaml
# watch reconciliation:
kubectl get argocd app -w