Production-grade GitOps proof of concept on OpenShift 4.15 using ArgoCD (Red Hat OpenShift GitOps).
ocp-gitops-poc/
├── .github/workflows/ # CI/CD pipeline definitions
│ ├── ci.yaml # Build, test, push to ghcr.io, update staging
│ └── promote.yaml # Promote image tag to production (manual trigger)
├── apps/ # Application manifests (GitOps)
│ ├── app-of-apps/ # App-of-Apps pattern (root ArgoCD app)
│ │ ├── app-of-apps.yaml # Root Application
│ │ ├── project.yaml # AppProject
│ │ ├── sample-app-staging.yaml
│ │ ├── sample-app-production.yaml
│ │ └── kustomization.yaml
│ └── sample-app/ # Sample app Kustomize manifests
│ ├── base/ # Base: Deployment, Service, ConfigMap, Route
│ └── overlays/
│ ├── staging/ # Staging overlay (1 replica, auto-updated by CI)
│ └── production/ # Production overlay (2 replicas, manual promote)
├── argocd/ # ArgoCD bootstrap manifests
│ ├── base/ # Operator subscription + ArgoCD CR
│ ├── components/
│ │ ├── pdb/ # PodDisruptionBudgets
│ │ └── servicemonitor/ # ServiceMonitors for observability
│ └── overlays/
│ └── cluster/ # Cluster-specific overlay
├── sample-app/ # Application source code
│ ├── src/
│ │ ├── app.py # Flask application
│ │ └── requirements.txt
│ ├── tests/
│ │ ├── test_app.py
│ │ └── requirements-test.txt
│ ├── Dockerfile # Multi-stage build
│ └── .dockerignore
├── platform/multi-tenancy/ # Namespace isolation & self-service onboarding
│ ├── base/ # stage/, prod/ — namespace, quota, limits, netpol, RBAC
│ ├── templates/ # Helm chart + Terraform module (project templates)
│ ├── openshift/ # Native oc new-project self-service template
│ └── onboarding/ # ONBOARDING.md — 3 self-service paths
└── docs/ # Documentation
├── step-by-step-guide.md # Full deployment walkthrough
├── ci-pipeline-fix-rca.md # CI pipeline RCA (Quay.io -> ghcr.io fix)
├── session-context.md # Cluster state & access details
├── requirements.md
├── phase1-cluster-assessment.md
├── multi-tenancy-hld.md # Multi-tenancy HLD (architecture, isolation model)
├── multi-tenancy-lld.md # Multi-tenancy LLD (manifest-level detail)
├── multi-tenancy-timeline.md # 7-day timeline + resource requirements
└── multi-tenancy-validation.md # Pre/post-deployment validation checklist
- OpenShift 4.15+ cluster
ocCLI authenticated- GitHub account (ghcr.io uses built-in GITHUB_TOKEN - no external registry account needed)
oc apply -k argocd/overlays/clusteroc apply -f apps/app-of-apps/app-of-apps.yaml -n openshift-gitopsURL: https://openshift-gitops-server-openshift-gitops.apps.lab.ocp.local
User: admin
Staging: https://sample-app-sample-app-staging.apps.lab.ocp.local
Production: https://sample-app-sample-app-production.apps.lab.ocp.local
Code Push --> GitHub Actions CI --> ghcr.io Image --> Manifest Update --> ArgoCD Sync --> Pod Rollout
- CI: GitHub Actions builds container image, runs tests, pushes to ghcr.io with commit SHA tag
- CD: ArgoCD watches this Git repo and auto-syncs to OpenShift
- Image Tags: Each overlay uses kustomize
images.newTagwith the commit SHA (not:latest), ensuring ArgoCD detects changes and triggers pod rollouts automatically - Promotion: CI auto-updates staging tag; manual
workflow_dispatchpromotes to production - Pattern: App-of-Apps for multi-environment management
| Environment | Namespace | Replicas | Sync Policy | Image Update |
|---|---|---|---|---|
| Staging | sample-app-staging | 1 | Automated (prune + self-heal) | Auto (CI commits new tag) |
| Production | sample-app-production | 2 | Automated (prune + self-heal) | Manual (promote workflow) |
- Registry: ghcr.io (GitHub Container Registry)
- Image:
ghcr.io/esarath/sample-app - Tags: Commit SHA (e.g.,
e132cfe) +latest - Auth: Built-in
GITHUB_TOKEN(no external secrets needed) - Build: Multi-stage (python:3.12-slim), non-root user (UID 1001), Gunicorn with 2 workers
Triggers on push to main with changes in sample-app/**:
- test - Install deps, run pytest
- build-and-push - Build Docker image, push to ghcr.io with SHA tag + latest
- update-manifests - Update staging
kustomization.yaml(bothnewTagandAPP_VERSION)
Manual trigger (workflow_dispatch) with image tag input:
- Updates production
kustomization.yaml(bothnewTagandAPP_VERSION)
Namespace isolation and self-service onboarding built on top of the same
GitOps pipeline: stage and prod namespaces with ResourceQuota,
LimitRange, default-deny NetworkPolicy, and scoped RBAC, onboardable via
a Helm chart, a Terraform module, or OpenShift's native oc new-project
template. See docs/multi-tenancy-hld.md for
architecture and platform/multi-tenancy/onboarding/ONBOARDING.md
for the onboarding procedure.
- Step-by-Step Deployment Guide - Full walkthrough from repo creation to end-to-end testing
- CI Pipeline RCA - Root cause analysis of CI failures (Quay.io to ghcr.io migration)
- Cluster Assessment - Phase 1 cluster health checks
- Session Context - Cluster topology, access details, and current state
- Multi-Tenancy HLD / LLD / Timeline / Validation