Solutions · GitOps delivery
Deployment you can read in a pull request.
TruStacks proposes the Helm chart and ArgoCD Application for each service as a pull request against your platform repository. Nothing deploys until a person on your team merges it, and then your own GitOps controller syncs what was merged. The agents hold no production credentials and never touch the cluster: git is the only door, and your people hold it.
The path to production
Four steps, and only one of them is an agent.
Step 1
The crew proposes
A Helm chart and an ArgoCD Application, written into your platform repository as a pull request. The agents never touch a cluster.
Step 2
Policy decides
The proposal is checked against the constitution before the pull request opens. A denial is recorded with its rule, and nothing opens.
Step 3
A person merges
Your reviewer reads the blast radius and the rollback in the pull request body, and merges or doesn't. There is no autonomous merge path.
Step 4
Your controller syncs
Your own GitOps controller deploys what was merged, with your credentials, on your infrastructure. Production syncs wait for a person, by rule.
Checked before you see it
Production does not sync itself.
The constitution checks delivery manifests the same way it checks pipelines. A proposal that would let a production Application sync automatically is denied before anyone is asked to review it.
proposal.has_helm_chartThe proposal includes at least one Chart.yaml under the gitops/ service root.
proposal.has_argocd_applicationThe proposal includes an ArgoCD Application manifest for the service and its target cluster.
practice.argocd_prod_requires_manual_syncArgoCD Applications targeting prod must opt out of automated sync.
Today, and where it is headed
ArgoCD today. Flux, and more than Kubernetes, next.
Today the crew writes Helm charts and ArgoCD Applications. You can declare Flux in your environment profile now, and the crew takes it into account, but it does not write Flux configuration yet. The direction is wider than either: the governed pull request does not care what applies the change, so the same propose, decide, approve path is where non-Kubernetes delivery targets are headed too.
Keep your controller. Lose the hand-written manifests.
Hosted Beta signup is open, capped at 100 teams. Create your workspace at app.trustacks.com, and the hosted quickstart walks you to your first governed pull request.