Operations
GitOps
53 / 69

Git becomes the source of truth and no human or pipeline needs standing kubectl access.

Git repositoryreviewed pull requestsArgo CD or Fluxruns in the cluster, pullsCluster statereconciled to match GitPod Identity roleonly to read ECR or a private repoImage registrycontroller or CI promotes digests

Fits the ownership split

AWS keeps the control plane healthy; GitOps keeps workloads and config correct. Drift is corrected automatically.

Safer access model

No CI secret with cluster-admin. The in-cluster controller pulls with a scoped role; humans use access entries with read or limited rights.

Terraform vs GitOps

Terraform for the cluster and AWS resources; GitOps for what runs inside. Keep the boundary clear to avoid two tools fighting.