Skip to main content
TruStacks

Solutions · GitOps delivery

Deployment you can read in a pull request.

TruStacks proposes the Helm chart and ArgoCD Application for each service as a pull request against your platform repository. Nothing deploys until a person on your team merges it, and then your own GitOps controller syncs what was merged. The agents hold no production credentials and never touch the cluster: git is the only door, and your people hold it.

The path to production

Four steps, and only one of them is an agent.

  1. Step 1

    The crew proposes

    A Helm chart and an ArgoCD Application, written into your platform repository as a pull request. The agents never touch a cluster.

  2. Step 2

    Policy decides

    The proposal is checked against the constitution before the pull request opens. A denial is recorded with its rule, and nothing opens.

  3. Step 3

    A person merges

    Your reviewer reads the blast radius and the rollback in the pull request body, and merges or doesn't. There is no autonomous merge path.

  4. Step 4

    Your controller syncs

    Your own GitOps controller deploys what was merged, with your credentials, on your infrastructure. Production syncs wait for a person, by rule.

Checked before you see it

Production does not sync itself.

The constitution checks delivery manifests the same way it checks pipelines. A proposal that would let a production Application sync automatically is denied before anyone is asked to review it.

  • proposal.has_helm_chart

    The proposal includes at least one Chart.yaml under the gitops/ service root.

  • proposal.has_argocd_application

    The proposal includes an ArgoCD Application manifest for the service and its target cluster.

  • practice.argocd_prod_requires_manual_sync

    ArgoCD Applications targeting prod must opt out of automated sync.

Today, and where it is headed

ArgoCD today. Flux, and more than Kubernetes, next.

Today the crew writes Helm charts and ArgoCD Applications. You can declare Flux in your environment profile now, and the crew takes it into account, but it does not write Flux configuration yet. The direction is wider than either: the governed pull request does not care what applies the change, so the same propose, decide, approve path is where non-Kubernetes delivery targets are headed too.

Keep your controller. Lose the hand-written manifests.

Hosted Beta signup is open, capped at 100 teams. Create your workspace at app.trustacks.com, and the hosted quickstart walks you to your first governed pull request.