ACK One GitOps sample application
This topic describes a sample application deployed using ACK One GitOps.
Directory structure of the deployment repository
A complete CI/CD pipeline involves two main types of repositories: a business code repository and a deployment repository. Because this guide requires you to modify repository configurations, you must fork the following repositories to your own account.
-
Business code repositories: The echo-server project and the echo-web-server project.
-
Deployment repository: Stores the YAML files for the applications that you want to deploy to your clusters. For more information, see the Alibaba Cloud GitOps Demo project (example branch). The main directory structure is as follows. This guide provides examples for development, staging, and production environments, covering a complete development workflow. It includes both Helm and Kustomize methods. Choose a deployment method based on your requirements.
manifests ├── helm │ ├── echo-server │ │ ├── .argocd-source-app-helm-dev.yaml │ │ ├── .argocd-source-app-helm-production.yaml │ │ ├── .argocd-source-app-helm-staging.yaml │ │ ├── Chart.yaml │ │ ├── templates │ │ │ ├── NOTES.txt │ │ │ ├── _helpers.tpl │ │ │ ├── deployment-echo-server.yaml │ │ │ ├── deployment-echo-web-server.yaml │ │ │ ├── external-secret.yaml │ │ │ ├── hpa.yaml │ │ │ ├── ingress.yaml │ │ │ ├── rollout.yaml │ │ │ ├── service-echo-server.yaml │ │ │ ├── service-echo-web-server.yaml │ │ │ ├── serviceaccount.yaml │ │ │ └── tests │ │ │ └── test-connection.yaml │ │ ├── values-dev.yaml │ │ ├── values-production.yaml │ │ ├── values-staging.yaml │ │ └── values.yaml │ └── web-demo │ ├── Chart.yaml │ ├── templates │ │ ├── deployment.yaml │ │ └── service.yaml │ └── values.yaml └── kustomize ├── base │ ├── deployment.yaml │ ├── kustomization.yaml │ └── service.yaml └── overlay ├── dev │ ├── .argocd-source-app-kust-dev.yaml │ ├── deployment.yaml │ └── kustomization.yaml ├── production │ ├── .argocd-source-app-kust-production.yaml │ ├── deployment.yaml │ └── kustomization.yaml └── staging ├── .argocd-source-app-kust-staging.yaml ├── deployment.yaml └── kustomization.yamlThe echo-server project in this deployment repository is managed by Helm and demonstrates capabilities such as multi-environment or multi-cluster deployments, multiple Deployments, multi-cluster secret management, and Rollouts.
Multi-environment or multi-cluster deployment
The following sections describe the configurations for applications managed by Helm and Kustomize.
-
Applications managed by Helm
You can use different
values.yamlfiles for environment-specific deployments, such asvalues-dev.yaml,values-staging.yaml, andvalues-production.yamlfrom the directory structure.-
For example, if you want to disable Rollout-based rolling updates in the Dev environment but enable them in the Staging and Production environments, you can configure these settings in the respective
values.yamlfiles. -
In each
values-****.yamlfile, change the image repository information to match your Container Registry Enterprise Edition (ACR EE) instance. This guide uses an ACR EE instance nameddemo-testand a namespace namedcidemo. Configure these settings based on your actual environment.image: echoServer: repository: demo-test-registry.cn-hangzhou.cr.aliyuncs.com/cidemo/echo-server tag: "v1.0" echoWebServer: repository: demo-test-registry.cn-hangzhou.cr.aliyuncs.com/cidemo/echo-web-server tag: "v1.0" pullPolicy: IfNotPresent
-
-
Applications managed by Kustomize
For applications managed by Kustomize, resource modifications are made using a base and overlay approach. To create environment-specific configurations, you can use different directories within the
overlaydirectory.
After an application image is updated, Image Updater automatically writes the latest image information back to the .argocd-source-app-helm-xxx.yaml and .argocd-source-app-kust-xxx.yaml files in the Git repository. The content is similar to the following example. For more information about Application configurations, see Build a CI/CD pipeline by using ACK One GitOps and ACR.
helm:
parameters:
- name: image.echoServer.repository
value: demo-test-registry.cn-hangzhou.cr.aliyuncs.com/cidemo/echo-server
forcestring: true
- name: image.echoServer.tag
value: v2.1
forcestring: true
- name: image.echoWebServer.repository
value: demo-test-registry.cn-hangzhou.cr.aliyuncs.com/cidemo/echo-web-server
forcestring: true
- name: image.echoWebServer.tag
value: v1.0
forcestring: true
Distribute environment-specific credentials
If you need to use different configurations and credentials, such as database usernames and passwords, across multiple clusters, you can use Secrets Manager to encrypt and manage them. After that, you can import Alibaba Cloud KMS credentials for your application in each cluster. For more information about how to use Secrets Manager, see Quick start for Secrets Manager.
To use this feature, you must add a corresponding YAML file (external-secret.yaml) to the deployment repository. When the application is deployed, this file creates an ExternalSecret resource, which triggers the retrieval of credentials from KMS. The corresponding Secret is then mounted in deployment-echo-server.yaml.
In this guide, the values-****.yaml files for each environment require different settings. For example, you can disable the secretManager capability in the development environment. Modify the configuration based on your requirements.
Canary release
In staging and production environments, you typically need to perform progressive releases using the Rollout capability. To do this, add a corresponding YAML file, rollout.yaml, to the deployment repository. This file deploys a Rollout resource to trigger a canary release or a rolling update. For more information about canary releases, see Perform a canary release by using ACK One GitOps and Argo Rollouts and Use Kruise Rollout to implement a canary release (Canary & A/B Testing).
Application manifests
The following sections provide sample Application YAML manifests for deploying with Helm and Kustomize in development, staging, and production environments. Modify the argocd-image-updater.argoproj.io/image-list and repoURL settings based on your actual environment.
Helm
The following manifests are for the Helm application in each environment.
-
Development environment
-
Staging environment
-
Production environment
Kustomize
The following manifests are for the Kustomize application in each environment.
-
Development environment
-
Staging environment
-
Production environment