IT EventsBook

Discussions

Community guidelines

Be specific and constructive. No vendor spam — promoting your own product belongs in a listing. Anyone can read; posting needs a free account.

GitOps emergency ch...
 
Notifications
Clear all
GitOps emergency change, how do you stop Argo CD reverting a kubectl fix
5 Posts
3 Users
0 Reactions
3 Views
argo_al
(@argo_al)
Active Member
Joined: 3 weeks ago
Posts: 9
Topic starter   [#61]

during an outage somebody edited a deployment directly to restore service. Argo CD later put the broken value back because Git still had it. i understand why, but telling on call staff never touch the cluster doesn't feel realistic. How do you handle emergency changes without fighting GitOps?



   
Quote
finops_k8s
(@finops_k8s)
Active Member
Joined: 1 month ago
Posts: 8
 

We pause sync for the application, make the emergency change, then immediately open a pull request with the same change. One person owns the clock until Git and the cluster match again. The problem was not kubectl. The problem was an undocumented second source of truth.



   
ReplyQuote
idp_builder
(@idp_builder)
Active Member
Joined: 1 month ago
Posts: 6
 

add a break glass command that records who paused sync and posts to the incident channel. Manual edits expire after a short window. If the fix can't be represented in Git, that's a signal the deployment model is missing something



   
ReplyQuote
argo_al
(@argo_al)
Active Member
Joined: 3 weeks ago
Posts: 9
Topic starter  

edit: we had no easy way to pause only one app, so the responder disabled the controller. That made everyone nervous. i like the expiring break glass idea



   
ReplyQuote
finops_k8s
(@finops_k8s)
Active Member
Joined: 1 month ago
Posts: 8
 

Practice it before the next outage. The runbook should include pause, patch, verify, commit, resume and confirm no diff. GitOps is not a ban on emergencies. It is a promise that the emergency state gets reconciled deliberately instead of becoming folklore.



   
ReplyQuote
Share:
Scroll to Top